Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,980cataloged exploits
36,899CVEs with public exploitation
24,695lab-tested
79,980 exploits
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware11 Jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
Wazuh + Suricata SOC lab detecting real exploits (CVE-2011-2523) and brute-force attacks, with custom detection rules for gaps in default IDS signatures.
CVE-2011-252311 Jul 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL11 Jul 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISK
open
GitHub PoC1
Dahua CVE-2026-29115
CVE-2026-29115MEDIUM11 Jul 2026
A vulnerability has been found in some Dahua products could allow an authenticated remote attacker to send a specially c
33RISK
open
VulnCheck XDB
initial-access
CVE-2019-1003030CRITICALunder attack11 Jul 2026
A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/
100RISK
open
GitHub PoC2
Balbooa Forms (com_baforms) < 2.4.1 — Unauthenticated File Upload to RCE via form.uploadAttachmentFile | CVSS 9.8 | CISA KEV
CVE-2026-56291CRITICALunder attack11 Jul 2026
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1
98RISK
open
GitHub PoC1
Dahua CVE-2026-29116
CVE-2026-29116HIGH11 Jul 2026
A vulnerability has been found in some Dahua products could allow an unauthenticated remote attacker to send a specially
41RISK
open
GitHub PoC4
CVE-2026-46331 act_pedit page-cache corruption exploit, with Alpine PIE fix
CVE-2026-46331HIGH11 Jul 2026
net/sched: fix pedit partial COW leading to page cache corruption
41RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2021-2564611 Jul 2026
Authenticated users can override system configurations in their requests which allows them to execute arbitrary code.
60RISK
open
GitHub PoC1
RustDesk < 1.4.9 - Missing Session-Scope Enforcement Allows Out-of-Scope Control Message Injection
CVE-2026-57850HIGH11 Jul 2026
RustDesk Missing Session Scope Enforcement Allows Out-of-Scope Control Message Injection
41RISK
open
GitHub PoC
Instant Appointment <= 1.2 — Unauthenticated Arbitrary File Upload to RCE via add_service_front AJAX | CVSS 9.8
CVE-2026-15282CRITICAL11 Jul 2026
Instant Appointment <= 1.2 - Unauthenticated Arbitrary File Upload
48RISK
open
VulnCheck XDB
initial-access
CVE-2026-56291CRITICALunder attack11 Jul 2026
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1
98RISK
open
VulnCheck XDB
local
CVE-2016-5195HIGHunder attack11 Jul 2026
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
VulnCheck XDB
initial-access
CVE-2022-2907811 Jul 2026
The ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[
50RISK
open
VulnCheck XDB
initial-access
CVE-2019-15107CRITICALunder attackransomware11 Jul 2026
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
GitHub PoC
[AI-assisted] Root method for Lenovo IdeaTab A1000G (MT8317, kernel 3.4.0, Android 4.1) via CVE-2016-5195 (Dirty COW)
CVE-2016-5195HIGHunder attack11 Jul 2026
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
GitHub PoC
Cybersecurity Capstone Project completed during the NCSC Nashama CyberCamp 11, delivered in collaboration with IT Security C&T. The project demonstrates vulnerability assessment, exploitation, mitigation, and SIEM detection for Oracle WebLogic (CVE-2017-10271) and Apache Druid (CVE-2021-25646).
CVE-2017-10271HIGHunder attackransomware11 Jul 2026
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open
GitHub PoC
Exploitability PoC for CVE-2026-9558 (SSTI Mautic Theme)
CVE-2026-9558CRITICAL10 Jul 2026
A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twi
48RISK
open
GitHub PoC
CVE-2025-60787 motionEye authenticated command injection RCE PoC
CVE-2025-60787HIGH10 Jul 2026
MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name
61RISK
open
GitHub PoC
Exploit for CVE-2022-26134
CVE-2022-26134CRITICALunder attackransomware10 Jul 2026
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC
caspy123/CVE-2026-43499
CVE-2026-43499HIGH10 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC2
A Proof of Concept (PoC) exploit for CVE-2026-46331
CVE-2026-46331HIGH10 Jul 2026
net/sched: fix pedit partial COW leading to page cache corruption
41RISK
open
GitHub PoC
0x77FSec/CVE-2026-23744
CVE-2026-23744CRITICAL10 Jul 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISK
open
GitHub PoC
CVE-2026-54390 — JTL Shop Smarty SSTI RCE | Pre-Auth Template Injection via fetch('string:' . ) | 5.2.0-5.7.1
CVE-2026-54390CRITICAL10 Jul 2026
JTL Shop < 5.7.2 Server-Side Template Injection via Smarty Renderer
48RISK
open
GitHub PoC
Dr-D25/CVE-2026-49049
CVE-2026-49049HIGH10 Jul 2026
Joomla Extension - joomshaper.com - Unauthenticated access to Helix3 template ajax handler
56RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-8110HIGHunder attack10 Jul 2026
File overwrite in file update API in Gogs
100RISK
open
GitHub PoC
Reproducer for CVE-2026-40860 — Apache Camel camel-jms/sjms/amqp JMS ObjectMessage unsafe deserialization (RCE)
CVE-2026-40860CRITICAL10 Jul 2026
Apache Camel: Unsafe Deserialization of JMS ObjectMessage in camel-jms, camel-sjms, camel-sjms2 and camel-amqp
48RISK
open
GitHub PoC
oPanel Authanticated Remote Code Execution via 'advenced/curl' Component
CVE-2026-50979HIGH10 Jul 2026
A command injection vulnerability in the 'advanced/curl' component of Osbil Technology oPanel v1.19.50 and earlier allow
41RISK
open
GitHub PoC
Reproducer for CVE-2026-40859 — Apache Camel camel-netty-http / camel-vertx-http producer-side unsafe deserialization of HTTP response bodies (RCE)
CVE-2026-40859HIGH10 Jul 2026
Apache Camel: Camel-Vertx-Http: Unsafe Java deserialization of HTTP response bodies via a raw ObjectInputStream when transferException is enabled
41RISK
open
GitHub PoC1
Reproducer for CVE-2026-40858 — Apache Camel camel-infinispan remote aggregation repository unsafe deserialization (RCE)
CVE-2026-40858HIGH10 Jul 2026
Apache Camel: Camel-Infinispan: Unsafe Deserialization in Remote Aggregation Repository
41RISK
open
previouspage 68 / 2,666next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.