Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

80,095cataloged exploits
36,945CVEs with public exploitation
24,695lab-tested
80,095 exploits
Metasploit600
SimpleHelp OIDC Authentication Bypass Remote Code Execution
CVE-2026-48558CRITICAL12 Jun 2026
SimpleHelp Authentication Bypass via Missing OIDC JWT Signature Verification
75RISK
open
GitHub PoC2
CVE-2026-35273
CVE-2026-35273CRITICALunder attackransomware12 Jun 2026
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Mana
100RISK
open
GitHub PoC4
CVE-2026-35273
CVE-2026-35273CRITICALunder attackransomware12 Jun 2026
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Mana
100RISK
open
GitHub PoC1
CVE-2026-50751 — Check Point IKEv1 Authentication Bypass
CVE-2026-50751CRITICALunder attackransomware12 Jun 2026
User Authentication Bypass in VPN Remote Access and Mobile Access
100RISK
open
GitHub PoC1
Safely detect whether a SolarWinds Serv-U host is vulnerable to CVE-2026-28318
CVE-2026-28318HIGHunder attack12 Jun 2026
SolarWinds Serv-U Unauthenticated Denial of Service Vulnerability
83RISK
open
GitHub PoC
rootdirective-sec/CVE-2026-46645-Analysis-Lab
CVE-2026-46645MEDIUM12 Jun 2026
SQLAdmin: Authorization Bypass on `ajax_lookup`
33RISK
open
GitHub PoC
Cisco Unified Communications Manager (Unified CM) deployments affected by CVE-2026-20230.
CVE-2026-20230HIGH12 Jun 2026
Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability
63RISK
open
GitHub PoC13
watchtowrlabs/watchTowr-vs-Splunk-CVE-2026-20253
CVE-2026-20253CRITICALunder attack12 Jun 2026
Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprise
100RISK
open
GitHub PoC3
CVE-2026-48907
CVE-2026-48907CRITICALunder attack12 Jun 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware12 Jun 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
Chains CVE-2025-57819 (stacked query SQL injection) and CVE-2025-61678 (authenticated file upload in FreePBX Endpoint Manager) to achieve Remote Code Execution (RCE). For educational use only.
CVE-2025-57819CRITICALunder attack12 Jun 2026
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISK
open
GitHub PoC4
Toolkit for CVE-2025-55182, also known as React2Shell.
CVE-2025-55182CRITICALunder attackransomware12 Jun 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC3
CVE-2026-25089
CVE-2026-25089CRITICALunder attack12 Jun 2026
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F
100RISK
open
GitHub PoC
anirudhmakkar/cve-2026-7665
CVE-2026-7665MEDIUM11 Jun 2026
Essential Addons for Elementor <= 6.6.4 - Missing Authorization to Unauthenticated Information Exposure via 'load_more' AJAX Handler
33RISK
open
GitHub PoC
byte16384/CVE-2026-49492-PoC
CVE-2026-49492HIGH11 Jun 2026
Markdown Preview Enhanced OS Command Injection in External File and Link Opening
41RISK
open
GitHub PoC
kaleth4/CVE-2021-4045
CVE-2021-4045CRITICAL11 Jun 2026
TP-LINK Tapo C200 remote code execution vulnerability
70RISK
open
VulnCheck XDB
initial-access
CVE-2026-23550CRITICAL11 Jun 2026
WordPress Modular DS plugin <= 2.5.1 - Privilege Escalation vulnerability
68RISK
open
VulnCheck XDB
initial-access
CVE-2026-10795HIGH11 Jun 2026
UpdraftPlus: WP Backup & Migration Plugin <= 1.26.4 - Unauthenticated Authentication Bypass via UpdraftCentral udrpc
41RISK
open
GitHub PoC2
CVE-2026-10795 – UpdraftPlus Authentication Bypass
CVE-2026-10795HIGH11 Jun 2026
UpdraftPlus: WP Backup & Migration Plugin <= 1.26.4 - Unauthenticated Authentication Bypass via UpdraftCentral udrpc
41RISK
open
VulnCheck XDB
initial-access
CVE-2026-10520CRITICAL11 Jun 2026
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote
85RISK
open
VulnCheck XDB
initial-access
CVE-2021-4045CRITICAL11 Jun 2026
TP-LINK Tapo C200 remote code execution vulnerability
70RISK
open
VulnCheck XDB
initial-access
CVE-2026-10520CRITICAL11 Jun 2026
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote
85RISK
open
GitHub PoC
CVE-2026-40791: Unauthenticated stored XSS in WP Time Slots Booking Form <= 1.2.46
CVE-2026-40791HIGH11 Jun 2026
WordPress WP Time Slots Booking Form plugin <= 1.2.46 - Cross Site Scripting (XSS) vulnerability
41RISK
open
GitHub PoC
CVE-2026-23479 Redis Use-After-Free vulnerability detection tool
CVE-2026-23479HIGH11 Jun 2026
redis-server use-after-free in unblock client flow may allow remote code execution
41RISK
open
GitHub PoC
Cyber-DarkNay/CVE-2026-45034
CVE-2026-45034CRITICAL11 Jun 2026
PhpSpreadsheet: File::prohibitWrappers bypass
48RISK
open
GitHub PoC1
PoC didático em Python 3 para a CVE-2019-9053, uma SQL Injection time-based blind no CMS Made Simple <= 2.2.9. Esta versão foi adaptada para uso em CTF/laboratório, com prefixos pré-configurados para reduzir o tempo de extração e mensagens explicativas em português.
CVE-2019-905311 Jun 2026
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISK
open
GitHub PoC4
CVE-2026-10520
CVE-2026-10520CRITICAL11 Jun 2026
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote
85RISK
open
GitHub PoC1
Lab + writeup for CVE-2026-28699: Gitea OAuth2 scope enforcement bypass via HTTP Basic auth
CVE-2026-28699HIGH11 Jun 2026
Gitea Basic Auth bypasses OAuth2 access token scopes
41RISK
open
GitHub PoC
CVE-2026-10520 and CVE-2026-10523
CVE-2026-10520CRITICAL11 Jun 2026
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote
85RISK
open
GitHub PoC
Cyber-DarkNay/CVE-2026-23550
CVE-2026-23550CRITICAL11 Jun 2026
WordPress Modular DS plugin <= 2.5.1 - Privilege Escalation vulnerability
68RISK
open
previouspage 97 / 2,670next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.