Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,980cataloged exploits
36,899CVEs with public exploitation
24,695lab-tested
79,980 exploits
GitHub PoC
HTB_Nexus Penetration Test Report – Comprehensive security assessment documenting credential leakage from Gitea, CVE-2026-38526 exploitation in Krayin CRM, and privilege escalation via Gitea template sync directory traversal. Mapped to MITRE ATT&CK and NSA D3FEND frameworks with actionable remediation roadmap and full evidence appendix.
CVE-2026-38526CRITICAL06 Jul 2026
An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x a
48RISK
open
GitHub PoC7
jaf0rk/CVE-2026-14382
CVE-2026-14382CRITICAL06 Jul 2026
Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to
48RISK
open
VulnCheck XDB
initial-access
CVE-2026-0920CRITICAL06 Jul 2026
LA-Studio Element Kit for Elementor <= 1.5.6.3 - Unauthenticated Privilege Escalation via Backdoor to Administrative User Creation via lakit_bkrole parameter
48RISK
open
GitHub PoC1
Exploitability PoC for CVE-2026-49352 (9router Hardcoded JWT Secret Authentication Bypass)
CVE-2026-49352CRITICAL06 Jul 2026
9Router: Hardcoded Default fallback JWT Secret Allows Authentication Bypass
48RISK
open
GitHub PoC
Exploit for Authenticated Remote Code Execution (RCE) in Krayin CRM v2.2.x (CVE-2026-38526)
CVE-2026-38526CRITICAL06 Jul 2026
An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x a
48RISK
open
GitHub PoC
Next.js / RSC - Unauthenticated RCE (React2Shell) (CVE-2025-55182)
CVE-2025-55182CRITICALunder attackransomware06 Jul 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-23550CRITICAL05 Jul 2026
WordPress Modular DS plugin <= 2.5.1 - Privilege Escalation vulnerability
68RISK
open
GitHub PoC4
Pre-auth path traversal to arbitrary file delete in Avada (Fusion) Builder <= 3.15.3 leading to RCE (CVSS 9.1)
CVE-2026-8713CRITICAL05 Jul 2026
Avada (Fusion) Builder <= 3.15.3 - Unauthenticated Arbitrary File Deletion via Form Entry Value
63RISK
open
GitHub PoC1
Offline jQuery CVE-2020-11023 remediation kit for legacy Spring/JSP - Node.js built-ins only (no npm, no internet)
CVE-2020-11023MEDIUMunder attack05 Jul 2026
Potential XSS vulnerability in jQuery
85RISK
open
GitHub PoC
Pre-auth Local File Inclusion in WP User Manager <= 2.9.17 via path traversal in tab parameter (CVSS 7.5)
CVE-2026-9290HIGH05 Jul 2026
WP User Manager <= 2.9.17 - Unauthenticated Path Traversal to Local File Inclusion via 'tab' Query Parameter
56RISK
open
VulnCheck XDB
initial-access
CVE-2026-48939CRITICALunder attack05 Jul 2026
Joomla Extension - icagenda.com - Remote Code Execution in iCaganda extension for Joomla < 4.0.8/3.9.15
98RISK
open
GitHub PoC
MESLIMOHAMEDM22005188/path-traversal-CVE-2026-14628
CVE-2026-14628MEDIUM05 Jul 2026
NousResearch hermes-agent Live Webhook Endpoint base.py extract_media path traversal
33RISK
open
GitHub PoC
 CVE-2026-49049 - Unauthenticated File Deletion, Arbitrary Write & XSS Injection for Helix3 Joomla Extension
CVE-2026-49049HIGH05 Jul 2026
Joomla Extension - joomshaper.com - Unauthenticated access to Helix3 template ajax handler
56RISK
open
VulnCheck XDB
initial-access
CVE-2026-20896CRITICAL05 Jul 2026
Gitea Docker image trusts spoofable reverse-proxy headers by default
63RISK
open
GitHub PoC6
Public PoC and detector for CVE-2026-20896 ("Gitea Docker: One Header, Any User")
CVE-2026-20896CRITICAL05 Jul 2026
Gitea Docker image trusts spoofable reverse-proxy headers by default
63RISK
open
VulnCheck XDB
initial-access
CVE-2026-48908CRITICAL05 Jul 2026
Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2
68RISK
open
GitHub PoC1
CVE-2018-10933 - libssh Authentication Bypass
CVE-2018-10933CRITICAL05 Jul 2026
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISK
open
GitHub PoC2
Product Video Gallery for Woocommerce <= 1.5.1.8 - Authenticated Stored Cross-Site Scripting Proof of Concept
CVE-2026-10104MEDIUM05 Jul 2026
Product Video Gallery for Woocommerce <= 1.5.1.8 - Authenticated (Shop Manager+) Stored Cross-Site Scripting via custom_thumbnail Parameter
33RISK
open
GitHub PoC
Eliot-code/CVE-2026-22874-PoC
CVE-2026-22874CRITICAL05 Jul 2026
Gitea webhook and migration allow-list filtering permits SSRF
48RISK
open
VulnCheck XDB
denial-of-service
CVE-2026-8713CRITICAL05 Jul 2026
Avada (Fusion) Builder <= 3.15.3 - Unauthenticated Arbitrary File Deletion via Form Entry Value
63RISK
open
GitHub PoC2
Pre-auth arbitrary file upload RCE exploit for iCagenda Joomla extension < 4.0.8 (CVSS 10.0)
CVE-2026-48939CRITICALunder attack05 Jul 2026
Joomla Extension - icagenda.com - Remote Code Execution in iCaganda extension for Joomla < 4.0.8/3.9.15
98RISK
open
GitHub PoC
Research and hands-on PoC of Spectre Variant 2 (CVE-2017-5715), a hardware side-channel vulnerability exploiting CPU speculative execution and branch prediction. Includes lab setup, vulnerability identification, exploit walkthrough, cache-timing analysis, demo video, and mitigation strategies.
CVE-2017-5715MEDIUM05 Jul 2026
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized discl
55RISK
open
GitHub PoC1
QNAP password reset URL injection writeup + PoC.
CVE-2025-59382LOW05 Jul 2026
QTS, QuTS hero, QuTScloud, QVP (QVR Pro appliances)
28RISK
open
GitHub PoC6
Epson Printer RAW Protocol Exploit Framework
CVE-2026-39047HIGH05 Jul 2026
Buffer Overflow vulnerability in EPSON L14150 FL27PB allows a remote attacker to execute arbitrary code via the RAW Prin
21RISK
open
GitHub PoC
This repository contains a professional bug bounty report demonstrating the successful exploitation of a Blind SSRF vulnerability that reached an internal CGI endpoint vulnerable to Shellshock (CVE-2014-6271). Remote command execution was confirmed using an out-of-band (OAST) DNS callback, showcasing the complete attack chain, technical analysis.
CVE-2014-6271CRITICALunder attack05 Jul 2026
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC
Proof of Concept (PoC) for CVE-2026-49975 – HTTP/2 server memory exhaustion attack leveraging HPACK amplification and connection retention (HTTP/2 Slowloris).
CVE-2026-49975HIGH05 Jul 2026
Apache HTTP Server: mod_http2 denial of service
53RISK
open
GitHub PoC
bayu06802/CVE-2026-48908
CVE-2026-48908CRITICAL05 Jul 2026
Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2
68RISK
open
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALunder attack05 Jul 2026
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC5
Apache ActiveMQ Classic RCE research: CVE-2026-34197 / CVE-2026-42588 bypass chain + hardened-6.2.6 audit findings + Crowdfense comparison
CVE-2026-34197HIGHunder attack04 Jul 2026
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans
100RISK
open
GitHub PoC
Technical troubleshooting repository for fixing infinite rendering vulnerability loops and resource exhaustion threats under CVE-2026-23869 cleanly.
CVE-2026-23869HIGH04 Jul 2026
A denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-
41RISK
open
previouspage 74 / 2,666next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.