Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,980cataloged exploits
36,899CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,476Referência 23,400GitHub PoC 15,250VulnCheck XDB 8,959Nuclei 4,393Metasploit 3,502✓ verified onlyrecentpopularrisk
79,980 exploits
GitHub PoC
Automated exploit for Krayin CRM ≤ 2.2.x.
An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x a
48RISK
open ↗GitHub PoC
Exploit for CVE-2025-55182
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open ↗VulnCheck XDB
remote-with-credentials
Apache Solr: Enabling BasicAuth using bin/solr CLI configures additional insecure users
56RISK
open ↗GitHub PoC★ 2
Reproducer for CVE-2026-40047: Apache Camel camel-docling CLI argument injection / path traversal
Apache Camel: Camel-Docling: Insufficient validation of custom CLI arguments enables argument injection and path traversal in DoclingProducer
48RISK
open ↗GitHub PoC
eunho87/CVE-2021-42013
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open ↗GitHub PoC★ 12
Apache Solr instances that may be affected by CVE-2026-44825, related to Velocity Template Remote Code Execution (RCE) conditions.
Apache Solr: Enabling BasicAuth using bin/solr CLI configures additional insecure users
56RISK
open ↗GitHub PoC
CVE-2026-33017 - Langflow < 1.9.0 Unauthenticated RCE PoC
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISK
open ↗GitHub PoC
Reproducer for CVE-2026-40453: Apache Camel case-variant Camel header injection (incomplete fix of CVE-2025-27636)
Apache Camel JMS, Apache Camel CoAP, Apache Camel Google PubSub: Incomplete fix for CVE-2025-27636 in non-HTTP HeaderFilterStrategies (camel-jms, camel-sjms, camel-coap, camel-google-pubsub) allows case-variant header injection
48RISK
open ↗GitHub PoC★ 3
CVE-2026-19874
Konami's Metal Gear Online 3 contains a heap-based buffer overflow
48RISK
open ↗VulnCheck XDB
initial-access
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISK
open ↗GitHub PoC
Tracking Januscape (CVE-2026-53359), the KVM/x86 guest-to-host escape
KVM: x86: Fix shadow paging use-after-free due to unexpected role
41RISK
open ↗GitHub PoC
Automated exploit for Krayin CRM ≤ 2.2.x.
An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x a
48RISK
open ↗Exploit-DB
Langflow 1.9.0 - RCE
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISK
open ↗Exploit-DB
Atarim WordPress Plugin 4.2.2 - Sensitive Information Exposure
WordPress Atarim plugin <= 4.2.1 - Sensitive Data Exposure vulnerability
56RISK
open ↗Exploit-DB
Joomla Page Builder CK 3.5.10 - Arbitrary File Upload
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0
75RISK
open ↗GitHub PoC★ 7
CVE-2026-43499
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open ↗VulnCheck XDB
initial-access
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open ↗GitHub PoC
CVE-2026-43499 - Draft
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open ↗GitHub PoC★ 1
CVE-2026-49777 - WooCommerce Product Slider Pro Malicious Software Implantation RCE - PoC & Analysis | CVSS 10.0 CRITICAL | AMN SECURITY
WordPress Product Slider Pro for WooCommerce plugin < 3.5.4 - Backdoor vulnerability
63RISK
open ↗GitHub PoC★ 1
CVE-2026-8206 - Kirki WordPress Plugin Unauthenticated Account Takeover - PoC & Analysis | CVSS 9.8 CRITICAL | AMN SECURITY
Kirki 6.0.0 - 6.0.6 - Unauthenticated Privilege Escalation via 'handle_forgot_password'
48RISK
open ↗GitHub PoC★ 1
CVE-2026-0257 - Palo Alto PAN-OS GlobalProtect Auth Override Cookie Forgery - PoC & Analysis | CVSS 9.1 CRITICAL CISA KEV | AMN SECURITY
PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
100RISK
open ↗GitHub PoC
aykhan32/CVE-2026-51788
An issue in cleverange_auth v.0.1.10 allows a remote attacker to cause a denial of service via the account_verification
41RISK
open ↗VulnCheck XDB
initial-access
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open ↗VulnCheck XDB
initial-access
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open ↗VulnCheck XDB
initial-access
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
75RISK
open ↗GitHub PoC★ 1
CVE-2026-45659 - Microsoft SharePoint Deserialization RCE - PoC & Analysis | CVSS 8.8 | AMN SECURITY
Microsoft SharePoint Remote Code Execution Vulnerability
93RISK
open ↗GitHub PoC
CVE-2026-14191 - Draft
WinRAR / UnRAR RAR5 recovery-volume (.rev) out-of-bounds heap write in RecVolumes5::ReadHeader
41RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.