Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,794cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
14,946 exploits
GitHub PoC
PoC for CVE-2026-73847 - emlog AI Assistant CSRF to SQL execution to admin takeover (CVSS 6.8)
CVE-2026-73847MEDIUM16 Aug 2026
Emlog: Missing CSRF protection in AI Assistant execute_tool leads to full database compromise and admin account takeover
33RISK
open
GitHub PoC
PoC: changedetection.io unauthenticated OpenAPI schema disclosure (CVE-2026-71203, Medium 5.3)
CVE-2026-71203MEDIUM16 Aug 2026
changedetection.io - Missing Authentication on /api/v1/full-spec Discloses Full OpenAPI Schema
33RISK
open
GitHub PoC
Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator
CVE-2026-18366CRITICAL16 Aug 2026
Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator
48RISK
open
GitHub PoC3
Using CVE-2026-43499 to root your Galaxy S24 Ultra(SM-S9280 ,(China / Hong Kong SAR / Taiwan))
CVE-2026-43499HIGH16 Aug 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC
PoC: changedetection.io settings blind-merge mass assignment (CVE-2026-71204, Medium 6.3)
CVE-2026-71204MEDIUM16 Aug 2026
changedetection.io - Omitted Checkbox in /settings Save Silently Disables API Key Enforcement
33RISK
open
GitHub PoC
eh-amish/Windows-Defender-Security-Auditor-CVE-2026-50656-
CVE-2026-50656HIGH16 Aug 2026
Microsoft Defender Elevation of Privilege Vulnerability
46RISK
open
GitHub PoC
PoC: changedetection.io unlimited login brute-force, no rate limiting (CVE-2026-71205, Medium 6.5)
CVE-2026-71205MEDIUM16 Aug 2026
changedetection.io - No Rate Limiting on /login Enables Unlimited Password Brute-Force
33RISK
open
GitHub PoC3
Public writeup, PoC, and emulation materials for CVE-2026-6837 affecting Zyxel export-cgi PKCS#12 export handling.
CVE-2026-6837HIGH16 Aug 2026
A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions
41RISK
open
GitHub PoC
Public writeup, PoC, and emulation materials for CVE-2026-8508 affecting Zyxel captive-portal social login.
CVE-2026-8508MEDIUM16 Aug 2026
An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions throug
33RISK
open
GitHub PoC
PoC for CVE-2026-73519 - WolfStack hardcoded cluster secret leads to unauthenticated RCE (CVSS 9.8)
CVE-2026-73519CRITICAL16 Aug 2026
WolfStack < 25.9.2 Hard-coded Secret Authentication Bypass via X-WolfStack-Secret
48RISK
open
GitHub PoC
PoC: Grafana Editor role deletes protected contact points (CVE-2026-72585, Medium 6.5)
CVE-2026-7258516 Aug 2026
23RISK
open
GitHub PoC1
Non-destructive detector for CVE-2026-64638 (XSS2Shell) — WordPress pre-auth XSS reflection primitive
CVE-2026-64638HIGH16 Aug 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
68RISK
open
GitHub PoC1
This repository contains a conceptual patch demonstrating the mitigation for CVE-2026-68820, a critical Use-After-Free (UAF) vulnerability in the Windows Ancillary Function Driver for WinSock (`afd.sys`).
CVE-2026-68820HIGHunder attack15 Aug 2026
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
71RISK
open
GitHub PoC
CVE-2026-64638 adalah kerentanan Pre-Auth Reflected Cross-Site Scripting (XSS) di WordPress yang ditemukan pada tahun 2026. Kerentanan ini memungkinkan penyerang untuk menyisipkan kode JavaScript berbahaya ke halaman login WordPress (/wp-login.php) tanpa perlu autentikasi terlebih dahulu.
CVE-2026-64638HIGH15 Aug 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
68RISK
open
GitHub PoC
This is my simple implementation of an exploit for the PwnKit vulnerability.
CVE-2021-4034HIGHunder attackransomware15 Aug 2026
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC
uproot <= 5.7.4 code injection via unsafe Python source generation from ROOT TStreamerInfo metadata.
CVE-2026-9147HIGH15 Aug 2026
uproot 5.7.4 and prior Code Injection via TStreamerInfo Metadata
41RISK
open
GitHub PoC
An explanation and PoC to exploit CVE-2026-20896 Authentication Bypass Vulnerability on Gitea. Being able to steal session tokens for valid users in the Gitea instance.
CVE-2026-20896CRITICAL15 Aug 2026
Gitea Docker image trusts spoofable reverse-proxy headers by default
63RISK
open
GitHub PoC382
CVE-2026-9830 Proof of Concept
CVE-2026-9830HIGH15 Aug 2026
BookingPress Pro < 5.7.3 - Unauthenticated Customer PII Disclosure and Booking Tampering via Permission Callback Bug
41RISK
open
GitHub PoC
CVE-2026-17544: PHP bcmath OOB write → universal memory-only RCE & disable_functions/open_basedir bypass. Offset-free runtime resolver. Verified on PHP 8.4.x / 8.5.x.
CVE-2026-17544HIGH15 Aug 2026
Out-of-bounds write in bccomp() via crafted operand and scale
41RISK
open
GitHub PoC
Alixploit22/CVE-2026-53587
CVE-2026-53587HIGH15 Aug 2026
libgit2 - Unauthenticated network-reachable heap out-of-bounds read in transports/smart_pkt.c:set_data
41RISK
open
GitHub PoC2
PoC for CVE-2026-72898
CVE-2026-72898CRITICALunder attack15 Aug 2026
Metabase SQL injection via password reset endpoint
100RISK
open
GitHub PoC
DuyDuongDuyDuong/CVE-2024-4577-Exploitation-AsyncRAT-Deployment-DFIR-Investigation
CVE-2024-4577CRITICALunder attackransomware15 Aug 2026
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC
Responsible disclosure write-ups for CVE-2026-8793 - PaperCut NG 25.0.11
CVE-2026-8793MEDIUM15 Aug 2026
PaperCut NG/MF: Insufficient brute-force protection
33RISK
open
GitHub PoC
Username Enumeration via Authentication Timing Side-Channel in PaperCut NG
CVE-2026-8794MEDIUM15 Aug 2026
PaperCut NG/MF: User enumeration via timing attack
33RISK
open
GitHub PoC1
CVE-2026-72898-Metabase-SQLi-Fix
CVE-2026-72898CRITICALunder attack15 Aug 2026
Metabase SQL injection via password reset endpoint
100RISK
open
GitHub PoC3
CVE-2026-72898 PoC : Metabase Unauthenticated SQL Injection
CVE-2026-72898CRITICALunder attack15 Aug 2026
Metabase SQL injection via password reset endpoint
100RISK
open
GitHub PoC
CVE-2026-58231 Detection & Confirmation Script
CVE-2026-58231CRITICAL15 Aug 2026
Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)
48RISK
open
GitHub PoC
mencari sebuah kerentanan, wodpres dan mengungah shell di kerentanan wodpres tersebut
CVE-2026-6440MEDIUM15 Aug 2026
GoodMeet <= 1.1.8 - Cross-Site Request Forgery to Google Meet Credential Reset via 'goodmeet_reset_google_meet_credential'
33RISK
open
GitHub PoC
Python StateMachine 3.0.0 < 3.2.0 RCE via unsafe SCXML <data expr> evaluation and Python eval() injection.
CVE-2026-47103CRITICAL15 Aug 2026
Python StateMachine 3.0.0 < 3.2.0 RCE via SCXML eval() Injection
48RISK
open
GitHub PoC2
SambaCry Explanation and Exploitation Demo with POC
CVE-2017-7494CRITICALunder attackransomware15 Aug 2026
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.