Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
71,836 exploits
GitHub PoC14
CVE-2026-43284
CVE-2026-43284HIGH08 May 2026
xfrm: esp: avoid in-place decrypt on shared skb frags
78RISK
open
VulnCheck XDB
initial-access
CVE-2026-5718HIGH08 May 2026
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.7 - Unauthenticated Arbitrary File Upload via Non-ASCII Filename Blacklist Bypass
56RISK
open
GitHub PoC12
A proof-of-concept demonstrating how a default, unprivileged Kubernetes Pod can achieve node-level code execution on Amazon EKS by exploiting the Dirty Frag (CVE-2026-43284) Linux kernel page-cache corruption vulnerability through shared container image layers.
CVE-2026-43284HIGH08 May 2026
xfrm: esp: avoid in-place decrypt on shared skb frags
78RISK
open
GitHub PoC
EspoCRM 9.3.3 - Authenticated SSRF via Alternative IPv4 Notation
CVE-2026-33534MEDIUM08 May 2026
EspoCRM has authenticated SSRF via internal-host validation bypass using alternative IPv4 notation
48RISK
open
GitHub PoC
Linux Kernel Local Privilege Escalation
CVE-2026-31431HIGHunder attack08 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
GitHub PoC
Sidjaz/CrushFTP-CVE-2024-4040-Proof-of-Concept
CVE-2024-4040CRITICALunder attack08 May 2026
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISK
open
GitHub PoC
Xmyronn/CVE-2026-10243-AUTH
CVE-2026-10243MEDIUM08 May 2026
code-projects Smart Parking System Admin Endpoint missing authentication
33RISK
open
VulnCheck XDB
local
CVE-2026-31431HIGHunder attack08 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
GitHub PoC
Kernel LPE PoC & Mitigation Toolkit - ROSN-LR5-Full (CVE-2026-31431)
CVE-2026-31431HIGHunder attack08 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
VulnCheck XDB
local
CVE-2026-43284HIGH08 May 2026
xfrm: esp: avoid in-place decrypt on shared skb frags
78RISK
open
VulnCheck XDB
local
CVE-2026-31431HIGHunder attack08 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
GitHub PoC
Full exploit chain lab and Suricata IDS detection for CVE-2022-30190 (Follina) - MSDT RCE
CVE-2022-30190HIGHunder attackransomware08 May 2026
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
CTT-Enhanced Apache mod_auth_digest Timing Attack — CVE-2026-33006 Remote Digest Authentication Bypass → 33-Layer Temporal Timing Attack Original vulnerability: Apache HTTP Server 2.4.66 (mod_auth_digest timing leak) CTVSS (Original): 4.8 (Medium) CTT-Enhanced CVSS: 7.5 (High) — Network, low complexity, temporal wedge evasion
CVE-2026-33006MEDIUM08 May 2026
Apache HTTP Server: mod_auth_digest timing attack
13RISK
open
GitHub PoC
branixsolutions/Security-CVE-2026-41940-cPanel-WHM-WP2
CVE-2026-41940CRITICALunder attackransomware08 May 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISK
open
GitHub PoC
Desc "Fix Redis CVE ultil 20260508-10h51 GMT+7"
CVE-2026-25589HIGH08 May 2026
RedisBloom RESTORE invalid memory access may allow remote code execution
21RISK
open
GitHub PoC
A Rust honeypot that simulates a vulnerable cPanel/WHM instance for CVE-2026-41940
CVE-2026-41940CRITICALunder attackransomware08 May 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISK
open
Exploit-DB
Ghost CMS 6.19.0 - SQLi
CVE-2026-26980CRITICAL07 May 2026
Ghost has a SQL Injection in its Content API
75RISK
open
VulnCheck XDB
local
CVE-2026-31431HIGHunder attack07 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-10149CRITICALunder attack07 May 2026
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISK
open
VulnCheck XDB
local
CVE-2026-31431HIGHunder attack07 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
GitHub PoC171
Next.js v16.2.4 Security PoC Collection (CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-44576, CVE-2026-44582, CVE-2026-44572)
CVE-2026-23870HIGH07 May 2026
A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpo
41RISK
open
GitHub PoC33
CVE-2026-23631 (DarkReplica) Redis Exploit
CVE-2026-23631MEDIUM07 May 2026
redis-server Lua use-after-free may allow remote code execution
33RISK
open
VulnCheck XDB
initial-access
CVE-2026-41940CRITICALunder attackransomware07 May 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISK
open
Exploit-DB
ThingsBoard IoT Platform 4.2.0 - Server-Side Request Forgery (SSRF)
CVE-2025-34282MEDIUM07 May 2026
ThingsBoard < v4.2.1 SVG Image SSRF
33RISK
open
VulnCheck XDB
initial-access
CVE-2025-6440CRITICAL07 May 2026
WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload
60RISK
open
VulnCheck XDB
info-leak
CVE-2026-7482HIGH07 May 2026
Ollama heap out-of-bounds read in GGUF tensor parsing leaks server process memory to unauthenticated remote attackers
21RISK
open
Exploit-DB
Bludit CMS 3.18.4 - RCE
CVE-2026-25099HIGH07 May 2026
Remote Code Execution via Unrestricted File Upload in Bludit
41RISK
open
GitHub PoC2
Math.js Expression Parser RCE
CVE-2026-40897HIGH07 May 2026
Math.js: Unsafe object property setter in mathjs
41RISK
open
GitHub PoC
Advisory: CVE-2026-38361 multiple DoS vulnerabilities (CWE-400/CWE-670) in dash-uploader (Python/PyPI)
CVE-2026-38361HIGH07 May 2026
Multiple unauthenticated denial-of-service (DoS) issues in fohrloop dash-uploader v0.1.0 through v0.7.0a2. The chunked-u
36RISK
open
GitHub PoC2
Advisory: CVE-2026-38360 path traversal (CWE-22) in dash-uploader (Python/PyPI)
CVE-2026-38360CRITICAL07 May 2026
Directory Traversal vulnerability in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execut
43RISK
open
previouspage 72 / 2,395next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.