Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,980cataloged exploits
36,899CVEs with public exploitation
24,695lab-tested
79,980 exploits
GitHub PoC
zero-trace7/CVE-2026-50229
CVE-2026-50229MEDIUM08 Jul 2026
Apache Tomcat: XSS in number guess example
48RISK
open
GitHub PoC
Automated exploit for Krayin CRM ≤ 2.2.x.
CVE-2026-38526CRITICAL08 Jul 2026
An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x a
48RISK
open
GitHub PoC
Exploit for CVE-2025-55182
CVE-2025-55182CRITICALunder attackransomware08 Jul 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2026-44825HIGH08 Jul 2026
Apache Solr: Enabling BasicAuth using bin/solr CLI configures additional insecure users
56RISK
open
GitHub PoC2
Reproducer for CVE-2026-40047: Apache Camel camel-docling CLI argument injection / path traversal
CVE-2026-40047CRITICAL08 Jul 2026
Apache Camel: Camel-Docling: Insufficient validation of custom CLI arguments enables argument injection and path traversal in DoclingProducer
48RISK
open
GitHub PoC
eunho87/CVE-2021-42013
CVE-2021-42013CRITICALunder attackransomware08 Jul 2026
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
GitHub PoC12
Apache Solr instances that may be affected by CVE-2026-44825, related to Velocity Template Remote Code Execution (RCE) conditions.
CVE-2026-44825HIGH08 Jul 2026
Apache Solr: Enabling BasicAuth using bin/solr CLI configures additional insecure users
56RISK
open
GitHub PoC
CVE-2026-33017 - Langflow < 1.9.0 Unauthenticated RCE PoC
CVE-2026-33017CRITICALunder attack08 Jul 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISK
open
GitHub PoC
Reproducer for CVE-2026-40453: Apache Camel case-variant Camel header injection (incomplete fix of CVE-2025-27636)
CVE-2026-40453CRITICAL08 Jul 2026
Apache Camel JMS, Apache Camel CoAP, Apache Camel Google PubSub: Incomplete fix for CVE-2025-27636 in non-HTTP HeaderFilterStrategies (camel-jms, camel-sjms, camel-coap, camel-google-pubsub) allows case-variant header injection
48RISK
open
GitHub PoC3
CVE-2026-19874
CVE-2026-19874CRITICAL08 Jul 2026
Konami's Metal Gear Online 3 contains a heap-based buffer overflow
48RISK
open
VulnCheck XDB
initial-access
CVE-2026-33017CRITICALunder attack08 Jul 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-24706CRITICALunder attack08 Jul 2026
Remote Code Execution Vulnerability in Packaging
100RISK
open
GitHub PoC
Tracking Januscape (CVE-2026-53359), the KVM/x86 guest-to-host escape
CVE-2026-53359HIGH08 Jul 2026
KVM: x86: Fix shadow paging use-after-free due to unexpected role
41RISK
open
GitHub PoC
junghyeonkum/CVE-2022-24706
CVE-2022-24706CRITICALunder attack08 Jul 2026
Remote Code Execution Vulnerability in Packaging
100RISK
open
GitHub PoC
Automated exploit for Krayin CRM ≤ 2.2.x.
CVE-2026-38526CRITICAL08 Jul 2026
An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x a
48RISK
open
Exploit-DB
Langflow 1.9.0 - RCE
CVE-2026-33017CRITICALunder attackwebappsmultiple08 Jul 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISK
open
Exploit-DB
Atarim WordPress Plugin 4.2.2 - Sensitive Information Exposure
CVE-2025-60188HIGHwebappsmultiple08 Jul 2026
WordPress Atarim plugin <= 4.2.1 - Sensitive Data Exposure vulnerability
56RISK
open
Exploit-DB
Joomla Page Builder CK 3.5.10 - Arbitrary File Upload
CVE-2026-56290CRITICALwebappsmultiple08 Jul 2026
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0
75RISK
open
GitHub PoC7
CVE-2026-43499
CVE-2026-43499HIGH08 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware08 Jul 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
CVE-2026-43499 - Draft
CVE-2026-43499HIGH08 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC1
CVE-2026-49777 - WooCommerce Product Slider Pro Malicious Software Implantation RCE - PoC & Analysis | CVSS 10.0 CRITICAL | AMN SECURITY
CVE-2026-49777CRITICAL08 Jul 2026
WordPress Product Slider Pro for WooCommerce plugin < 3.5.4 - Backdoor vulnerability
63RISK
open
GitHub PoC1
CVE-2026-8206 - Kirki WordPress Plugin Unauthenticated Account Takeover - PoC & Analysis | CVSS 9.8 CRITICAL | AMN SECURITY
CVE-2026-8206CRITICAL08 Jul 2026
Kirki 6.0.0 - 6.0.6 - Unauthenticated Privilege Escalation via 'handle_forgot_password'
48RISK
open
GitHub PoC1
CVE-2026-0257 - Palo Alto PAN-OS GlobalProtect Auth Override Cookie Forgery - PoC & Analysis | CVSS 9.1 CRITICAL CISA KEV | AMN SECURITY
CVE-2026-0257HIGHunder attackransomware08 Jul 2026
PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
100RISK
open
GitHub PoC
aykhan32/CVE-2026-51788
CVE-2026-51788HIGH08 Jul 2026
An issue in cleverange_auth v.0.1.10 allows a remote attacker to cause a denial of service via the account_verification
41RISK
open
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALunder attack07 Jul 2026
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-36401CRITICALunder attack07 Jul 2026
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-48282CRITICAL07 Jul 2026
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
75RISK
open
GitHub PoC1
CVE-2026-45659 - Microsoft SharePoint Deserialization RCE - PoC & Analysis | CVSS 8.8 | AMN SECURITY
CVE-2026-45659HIGHunder attackransomware07 Jul 2026
Microsoft SharePoint Remote Code Execution Vulnerability
93RISK
open
GitHub PoC
CVE-2026-14191 - Draft
CVE-2026-14191HIGH07 Jul 2026
WinRAR / UnRAR RAR5 recovery-volume (.rev) out-of-bounds heap write in RecVolumes5::ReadHeader
41RISK
open
previouspage 71 / 2,666next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.