Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,794cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
14,946 exploits
GitHub PoC1
renzi25031469/CVE-2026-19478
CVE-2026-19478CRITICAL19 Aug 2026
Improper Control of Generation of Code ('Code Injection') in GitLab
63RISK
open
GitHub PoC
fork and edits from https://github.com/aniqfakhrul/CVE-2026-54121
CVE-2026-54121HIGH19 Aug 2026
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RISK
open
GitHub PoC
open-flaw/CVE-2026-56848
CVE-2026-56848HIGH19 Aug 2026
A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_m
41RISK
open
GitHub PoC1
Ring0-level process killer leveraging CVE-2026-0828 (BYOVD). Designed to demonstrate kernel-level process termination via a vulnerable signed driver, highlighting the security risks of Bring Your Own Vulnerable Driver attacks and the importance of driver trust, monitoring, and endpoint protection.
CVE-2026-0828HIGH19 Aug 2026
Kernel driver vulnerability in Safetica Endpoint Client
41RISK
open
GitHub PoC1
0xdeadroot/SCTPhantom-CVE-2026-64564
CVE-2026-64564CRITICAL19 Aug 2026
sctp: don't free the ASCONF's own transport in DEL-IP processing
48RISK
open
GitHub PoC
Forminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration
CVE-2026-15748CRITICAL19 Aug 2026
Forminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration
48RISK
open
GitHub PoC
TranDongA3/POC-CVE-2026-63030-CVE-2026-60137-
CVE-2026-63030CRITICALunder attack19 Aug 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
GitHub PoC1
halo cms plugin 1-request rce from a url, PoC + exploit chain
CVE-2026-67919CRITICAL19 Aug 2026
An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the PluginEndpoint.java, installFromUri m
48RISK
open
GitHub PoC
CVE-2026-47858
CVE-2026-47858HIGH19 Aug 2026
live information startup mode is vulnerable for remote code execution
41RISK
open
GitHub PoC
zavisco/CVE-2026-64849.yaml
CVE-2026-64849CRITICALunder attack19 Aug 2026
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
98RISK
open
GitHub PoC531
A cPanel and WHM authentication bypassing tool
CVE-2026-41940CRITICALunder attackransomware19 Aug 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISK
open
GitHub PoC
fastjson jsontype利用
CVE-2026-16723CRITICAL19 Aug 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
53RISK
open
GitHub PoC
CVE-2026-73072 - Draft or TODO
CVE-2026-73072HIGH19 Aug 2026
Vim: Heap Buffer Overflow when Loading a Spell File
41RISK
open
GitHub PoC
andreamammano89-maker/CVE-2021-42013_821311
CVE-2021-42013CRITICALunder attackransomware19 Aug 2026
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
GitHub PoC
CVE-2026-19501 poc
CVE-2026-19501HIGH18 Aug 2026
CVE-2026-19501
41RISK
open
GitHub PoC
CVE-2026-43499 (GhostLock) — Linux kernel futex PI rt_mutex UAF ARM32 privilege escalation research targeting Huawei Watch 4 Pro (kernel 5.4.210)
CVE-2026-43499HIGH18 Aug 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC
kaleth4/CVE-2026-64638
CVE-2026-64638HIGH18 Aug 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
68RISK
open
GitHub PoC1
CVE-2026-19500 poc
CVE-2026-19500HIGH18 Aug 2026
SureForms contains an uncontrolled resource consumption vulnerability
41RISK
open
GitHub PoC
Technical analysis and clean Java Thread Echo PoC for Oracle WebLogic Server vulnerability chain.
CVE-2020-14882CRITICALunder attack18 Aug 2026
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC3
CVE-2026-15748 - Unauthenticated RCE exploit for WordPress Forminator plugin (≤1.56.1). Automated detection, deep crawl, nonce extraction, and safe upload test. For authorized testing only.
CVE-2026-15748CRITICAL18 Aug 2026
Forminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration
48RISK
open
GitHub PoC1
Windows Defender 0day vulnerability CVE-2026-69414 ShieldBreak
CVE-2026-69414HIGH18 Aug 2026
Microsoft Defender Elevation of Privilege Vulnerability
41RISK
open
GitHub PoC
TP-Link Archer BE800 V1 — Parental Control LAN RCE
CVE-2026-9254HIGH18 Aug 2026
Command Injection Vulnerability in Parent Control of Multiple TP-Link Archer Devices
41RISK
open
GitHub PoC2
CVE-2026-14669 - PostgreSQL to_char() timezone abbreviation heap buffer overflow PoC; for authorized security testing
CVE-2026-14669HIGH18 Aug 2026
PostgreSQL to_char heap buffer overflow executes arbitrary code
41RISK
open
GitHub PoC
IhsSpotlight/HeartBleed-CVE-2014-0160--SCRIPTS-python3
CVE-2014-0160HIGHunder attack18 Aug 2026
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
GitHub PoC1
PoC for CVE-2026-44848: Portainer missing authorization on Docker plugin endpoints -> host RCE (GHSA-rrmm-9v76-h3p4). Stdlib-only Python.
CVE-2026-44848CRITICAL18 Aug 2026
Portainer: Missing authorization on Docker plugin endpoints allows host RCE
48RISK
open
GitHub PoC3
CVE-2026-65400
CVE-2026-65400CRITICALunder attack18 Aug 2026
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS
78RISK
open
GitHub PoC
0xROI/CVE-2026-77113
CVE-2026-77113MEDIUM18 Aug 2026
Path Traversal Vulnerability in apport-unpack
33RISK
open
GitHub PoC10
Reproducible A/B lab + safe PoC for GitLab CVE-2026-19478 / CVE-2026-19650 (GraphQL @gl_introduced)
CVE-2026-19478CRITICAL18 Aug 2026
Improper Control of Generation of Code ('Code Injection') in GitLab
63RISK
open
GitHub PoC11
CVE-2026-19478 PoC . Unauthenticated remote code-injection in GitLab's GraphQL layer
CVE-2026-19478CRITICAL18 Aug 2026
Improper Control of Generation of Code ('Code Injection') in GitLab
63RISK
open
GitHub PoC
codeb0ssx/CVE-2026-64849-PoC
CVE-2026-64849CRITICALunder attack18 Aug 2026
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
98RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.