Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,980cataloged exploits
36,899CVEs with public exploitation
24,695lab-tested
79,980 exploits
GitHub PoC
nvicloud/CVE-2026-12948
CVE-2026-12948MEDIUM10 Jul 2026
Stored Cross-Site Scripting (XSS)
33RISK
open
GitHub PoC
unpredictable21/halo-2.25.4-backup-write-CVE-2026-67920
CVE-2026-67920HIGH10 Jul 2026
An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the run.halo.app.migration.impl.Migration
41RISK
open
VulnCheck XDB
initial-access
CVE-2022-26134CRITICALunder attackransomware10 Jul 2026
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL10 Jul 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware10 Jul 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
Reproducer for CVE-2026-40860 — Apache Camel camel-jms/sjms/amqp JMS ObjectMessage unsafe deserialization (RCE)
CVE-2026-40860CRITICAL10 Jul 2026
Apache Camel: Unsafe Deserialization of JMS ObjectMessage in camel-jms, camel-sjms, camel-sjms2 and camel-amqp
48RISK
open
GitHub PoC
oPanel DNS-Based Cross-Site Scripting (XSS) & Session Hijacking
CVE-2026-50980MEDIUM10 Jul 2026
Cross-Site Scripting (XSS) vulnerability in the DNS lookup/management component of oPanel before v1.20.25 allows remote
33RISK
open
Metasploit300
Wordpress Planyo Online Reservation System Arbitrary File Read (CVE-2026-3576)
CVE-2026-3576HIGH10 Jul 2026
Planyo online reservation system <= 3.0 - Unauthenticated Server-Side Request Forgery via 'ulap_url' Parameter
61RISK
open
GitHub PoC
oPanel Authanticated Remote Code Execution via 'advenced/curl' Component
CVE-2026-50979HIGH10 Jul 2026
A command injection vulnerability in the 'advanced/curl' component of Osbil Technology oPanel v1.19.50 and earlier allow
41RISK
open
GitHub PoC
Exploitability PoC for CVE-2026-9558 (SSTI Mautic Theme)
CVE-2026-9558CRITICAL10 Jul 2026
A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twi
48RISK
open
GitHub PoC
sudoand3rs0n/CVE-2025-5548
CVE-2025-5548MEDIUM10 Jul 2026
FreeFloat FTP Server NOOP Command buffer overflow
38RISK
open
GitHub PoC
Reproducer for CVE-2026-40859 — Apache Camel camel-netty-http / camel-vertx-http producer-side unsafe deserialization of HTTP response bodies (RCE)
CVE-2026-40859HIGH10 Jul 2026
Apache Camel: Camel-Vertx-Http: Unsafe Java deserialization of HTTP response bodies via a raw ObjectInputStream when transferException is enabled
41RISK
open
GitHub PoC
Exploit for CVE-2022-26134
CVE-2022-26134CRITICALunder attackransomware10 Jul 2026
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC
0x77FSec/CVE-2026-23744
CVE-2026-23744CRITICAL10 Jul 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISK
open
GitHub PoC
Initial upload
CVE-2026-12352MEDIUM10 Jul 2026
Incorrect Authorization
33RISK
open
GitHub PoC
CVE-2025-60787 motionEye authenticated command injection RCE PoC
CVE-2025-60787HIGH10 Jul 2026
MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name
61RISK
open
VulnCheck XDB
client-side
CVE-2024-47176MEDIUM10 Jul 2026
cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
60RISK
open
GitHub PoC
CVE-2026-51833 Advisory
CVE-2026-51833HIGH10 Jul 2026
Xenforo 2.3.8 is vulnerable to SSRF. Attackers that have administrator privileges or are able to add/save RSS feeds can
41RISK
open
GitHub PoC1
CVE-2026-53571 `server.fs.deny` bypass on Windows alternate paths PoC.
CVE-2026-53571HIGH09 Jul 2026
Vite: `server.fs.deny` bypass on Windows alternate paths
41RISK
open
GitHub PoC
Public disclosure for CVE-2026-52100 (CSRF) & CVE-2026-52101 (SSRF) in linx-server. MITRE assigned the CVEs; this repo provides a public reference and helps affected users understand the risk.
CVE-2026-52100HIGH09 Jul 2026
Cross Site Request Forgery vulnerability in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to e
41RISK
open
GitHub PoC1
lieehrdiansyah12/CVE-2026-43503
CVE-2026-43503HIGH09 Jul 2026
net: skbuff: propagate shared-frag marker through frag-transfer helpers
41RISK
open
GitHub PoC
endusdksla/xwiki-cve-2025-24893
CVE-2025-24893CRITICALunder attack09 Jul 2026
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
GitHub PoC1
CVE-2026-50181 / GHSA-fg23-3346-88f5: Langroid path traversal advisory landing page
CVE-2026-50181HIGH09 Jul 2026
Langroid: Path traversal in the file tools allows read/write outside configured current directory
41RISK
open
GitHub PoC1
Tracking GhostLock (CVE-2026-43499), the rtmutex/futex stack use-after-free
CVE-2026-43499HIGH09 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC1
CVE-2026-4257 - Contact Form by Supsystic <= 1.7.36 # SSTI to RCE
CVE-2026-4257CRITICAL09 Jul 2026
Contact Form by Supsystic <= 1.7.36 - Unauthenticated Server-Side Template Injection via Prefill Functionality
75RISK
open
GitHub PoC1
0x00phantom-hat/CVE-2026-12400-Exploit
CVE-2026-12400MEDIUM09 Jul 2026
FlowForms <= 1.1.1 - Authenticated (Contributor+) Insecure Direct Object Reference to Arbitrary Form Modification via REST API '/flowforms/v1/forms/{id}' Endpoints
33RISK
open
GitHub PoC
unpredictable21/halo-2.25.4-CVE-2026-67919
CVE-2026-67919CRITICAL09 Jul 2026
An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the PluginEndpoint.java, installFromUri m
48RISK
open
GitHub PoC9
tc3650/CVE-2026-43499-armv7
CVE-2026-43499HIGH09 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC
包括能执行的命令探测和一键getshell(需要服务器部署服务)
CVE-2026-8037CRITICALunder attack09 Jul 2026
OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF
100RISK
open
GitHub PoC1
CVE-2026-50131 / GHSA-xw9q-2mv6-9fr8: Fedify incomplete SSRF mitigation advisory landing page
CVE-2026-50131HIGH09 Jul 2026
Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 ranges
41RISK
open
previouspage 69 / 2,666next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.