Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,775cataloged exploits
36,767CVEs with public exploitation
24,695lab-tested
79,775 exploits
GitHub PoC
Balboa form Command Injection POC
CVE-2026-67363HIGH30 Aug 2026
Joomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4.3.2
41RISK
open
GitHub PoC1
PoC CVE-2026-18741
CVE-2026-18741MEDIUM30 Aug 2026
Worksuite SaaS version prior to 6.0.14 Stored XSS via Asset Management Location and Description Fields
33RISK
open
VulnCheck XDB
initial-access
CVE-2026-48611CRITICAL30 Aug 2026
Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or
63RISK
open
GitHub PoC
Read-only CLI to check whether a WordPress site is exposed to WP2Shell (CVE-2026-63030 / CVE-2026-60137)
CVE-2026-63030CRITICALunder attack30 Aug 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
GitHub PoC
🫖 Contract-correlated discovery and authorized validation tool for Gitea CVE-2026-60004
CVE-2026-60004CRITICALunder attack30 Aug 2026
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
100RISK
open
GitHub PoC1
FastGPT Community Edition NoSQL Injection PoC (CVE-2026-79483)
CVE-2026-79483MEDIUM30 Aug 2026
FastGPT Community Edition 4.10.0 through 4.14.0 are vulnerable to a NoSQL injection in the POST /api/core/chat/getHistor
33RISK
open
GitHub PoC
joaovicdev/EXPLOIT-CVE-2026-56121
CVE-2026-56121CRITICAL30 Aug 2026
Feast < 0.63.0 Unauthenticated RCE via ApplyFeatureView gRPC Deserialization
48RISK
open
GitHub PoC2
Offensive Research & Exploit Development. Vulnerability research, PoC development, and offensive tooling for financial infrastructure.
CVE-2026-78903LOW30 Aug 2026
Incomplete cleanup in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromise
28RISK
open
VulnCheck XDB
initial-access
CVE-2026-82222CRITICAL30 Aug 2026
WordPress GiveWP plugin <= 4.16.7.1 - Remote Code Execution (RCE) vulnerability
48RISK
open
GitHub PoC
CVE-2026-12513 Vulnerability Advisory & PoC — Discovered by Huynh Kien Minh (MinhHK).
CVE-2026-12513MEDIUM30 Aug 2026
Shared Files < 1.7.68 - Unauthenticated Arbitrary File Deletion via Path Traversal
33RISK
open
GitHub PoC16
Authorized Docker lab and clean PoC for validating CVE-2026-82222 RCE in GiveWP 4.16.5.1 and the 4.16.7.2 fix.
CVE-2026-82222CRITICAL30 Aug 2026
WordPress GiveWP plugin <= 4.16.7.1 - Remote Code Execution (RCE) vulnerability
48RISK
open
VulnCheck XDB
initial-access
CVE-2026-42945CRITICAL30 Aug 2026
NGINX ngx_http_rewrite_module vulnerability
60RISK
open
GitHub PoC
Drupalgeddon2 CVE-2018-7600 vulnerable Drupal 7 lab
CVE-2018-7600CRITICALunder attackransomware30 Aug 2026
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
GitHub PoC4
CBDC Infrastructure Vulnerability Research. CVE-2026-78904: Infinite mint and redemption bypass in central bank digital currency APIs.
CVE-2026-78904CRITICAL30 Aug 2026
Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitra
48RISK
open
GitHub PoC
CVE-2026-82286 — gpt-crawler <=1.5.1 unauthenticated arbitrary file write via outputFileName (POST /crawl). PoC + self-contained Docker lab. CVSS 8.6, CWE-22.
CVE-2026-82286HIGH29 Aug 2026
gpt-crawler Arbitrary File Write via outputFileName Parameter
41RISK
open
VulnCheck XDB
initial-access
CVE-2026-1357CRITICAL29 Aug 2026
Migration, Backup, Staging <= 0.9.123 - Unauthenticated Arbitrary File Upload
75RISK
open
GitHub PoC
morzelowski/CVE-2026-12243-NLTK-PoC
CVE-2026-1224329 Aug 2026
23RISK
open
GitHub PoC
Static XML fixtures for authorized bug bounty testing of XML parser behaviour (CVE-2026-45071).
CVE-2026-45071HIGH29 Aug 2026
Symfony: XXE (Local File Disclosure) in DomCrawler::addXmlContent() via validateOnParse = true
41RISK
open
GitHub PoC
FranklinF25/cve-2026-42533
CVE-2026-42533CRITICAL29 Aug 2026
NGINX Map directive and Regex matching vulnerability
48RISK
open
GitHub PoC
rmhowe425/POC-CVE-2026-18729
CVE-2026-18729HIGH29 Aug 2026
Langflow is affected by multiple remote code execution vulnerabilities due to insufficient code-execution policy enforcement
41RISK
open
GitHub PoC
joaovicdev/EXPLOIT-CVE-2026-9198
CVE-2026-9198CRITICALunder attack29 Aug 2026
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RISK
open
GitHub PoC
CVE-2026-47884:覆盖 15 条 Spring / Tomcat 官方安全公告,8 条被 NVD 报成 CRITICAL 9.x 而厂商官方评 LOW/MEDIUM,另 7 条两边一致 —— 差别只在厂商有没有自己提交 CVSS。工具告诉你中了哪几条、官方评多少分、是否真满足触发条件,以及官方叫你升的版本 Maven Central 上有没有。
CVE-2026-47884CRITICAL29 Aug 2026
Spring Framework Improper Path Limitation in XsltView
48RISK
open
GitHub PoC2
Learn how I found my first two CVEs by pure accident.
CVE-2026-19745MEDIUM29 Aug 2026
Calix GigaSpire Web Management utilities_configurationsave.cgi denial of service
33RISK
open
GitHub PoC
rmhowe425/POC-CVE-2026-19286
CVE-2026-19286CRITICAL29 Aug 2026
Langflow is affected by multiple remote code execution vulnerabilities due to insufficient code-execution policy enforcement
48RISK
open
GitHub PoC2
#PaperCut CVE-2026-81578 + CVE-2026-82078 Defense Toolkit 2 3 A **defensive** toolkit to check and understand exposure to the chained
CVE-2026-81578HIGHunder attack29 Aug 2026
PaperCut MF/NG: Authentication Bypass
86RISK
open
GitHub PoC3
Security research tool for PaperCut CVE-2026-81578 & CVE-2026-82078
CVE-2026-81578HIGHunder attack29 Aug 2026
PaperCut MF/NG: Authentication Bypass
86RISK
open
GitHub PoC
SOC investigation of a CVE-2024-49138 exploitation alert using log analysis, threat intelligence, and endpoint containment.
CVE-2024-49138HIGHunder attack29 Aug 2026
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISK
open
GitHub PoC
Hunt-Benito/your-bot-my-inbox-cve-2026-68929-fastgpt-unauthenticated-wechat-channel-hijack
CVE-2026-68929CRITICAL29 Aug 2026
FastGPT: Unauthenticated WeChat channel hijack and denial of service via shareId-only authorization
48RISK
open
GitHub PoC2
hideki233/CVE-2025-3248-Langflow-RCE
CVE-2025-3248CRITICALunder attackransomware28 Aug 2026
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open
GitHub PoC1
CVE-2026-33017 - Langflow Unauthenticated RCE Exploit
CVE-2026-33017CRITICALunder attack28 Aug 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISK
open
previouspage 9 / 2,660next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.