Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

80,095cataloged exploits
36,945CVEs with public exploitation
24,695lab-tested
80,095 exploits
GitHub PoC
CVE-2026-23479 Redis Use-After-Free vulnerability detection tool
CVE-2026-23479HIGH11 Jun 2026
redis-server use-after-free in unblock client flow may allow remote code execution
41RISK
open
VulnCheck XDB
initial-access
CVE-2025-6440CRITICAL11 Jun 2026
WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload
60RISK
open
GitHub PoC5
CVE-2026-36213 | Local Privilege Escalation in MEmu Android Emulator 9.2.7.0 via Insecure Service Binary Permissions | Patched in 9.3.2
CVE-2026-36213HIGH11 Jun 2026
An issue in Microvirt MEmu Android Emulator 9.2.7.0 allows a local attacker to escalate privileges via the MemuService.e
41RISK
open
VulnCheck XDB
info-leak
CVE-2025-43529HIGHunder attack11 Jun 2026
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and
71RISK
open
VulnCheck XDB
initial-access
CVE-2021-4045CRITICAL11 Jun 2026
TP-LINK Tapo C200 remote code execution vulnerability
70RISK
open
GitHub PoC1
Lab + writeup for CVE-2026-28699: Gitea OAuth2 scope enforcement bypass via HTTP Basic auth
CVE-2026-28699HIGH11 Jun 2026
Gitea Basic Auth bypasses OAuth2 access token scopes
41RISK
open
GitHub PoC
CVE-2026-5027 - Draft
CVE-2026-5027HIGH11 Jun 2026
Langflow - Path Traversal Arbitrary File Write via upload_user_file
68RISK
open
GitHub PoC16
PoC for CVE-2026-48907 - Joomla! JCE extension < 2.9.99.5 unauthenticated RCE
CVE-2026-48907CRITICALunder attack11 Jun 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RISK
open
GitHub PoC
Cyber-DarkNay/CVE-2026-23550
CVE-2026-23550CRITICAL11 Jun 2026
WordPress Modular DS plugin <= 2.5.1 - Privilege Escalation vulnerability
68RISK
open
GitHub PoC
CVE-2026-40791: Unauthenticated stored XSS in WP Time Slots Booking Form <= 1.2.46
CVE-2026-40791HIGH11 Jun 2026
WordPress WP Time Slots Booking Form plugin <= 1.2.46 - Cross Site Scripting (XSS) vulnerability
41RISK
open
GitHub PoC
This repository contains a lab validation report and detection artefacts for DirtyFrag CVE-2026-43284, a Linux local privilege escalation issue related to the XFRM/ESP page-cache write path. The focus is on auditd telemetry, event correlation, and SOC-oriented detection logic.
CVE-2026-43284HIGH11 Jun 2026
xfrm: esp: avoid in-place decrypt on shared skb frags
78RISK
open
GitHub PoC
CVE-2017-9841 is a Remote Code Execution (RCE) vulnerability in the PHPUnit library affecting versions prior to 5.6.3 and 6.x prior to 6.4.2.
CVE-2017-9841CRITICALunder attack11 Jun 2026
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-9841CRITICALunder attack11 Jun 2026
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISK
open
GitHub PoC39
A demonstration of read write using cve-2025-43529 on iOS 26.1
CVE-2025-43529HIGHunder attack11 Jun 2026
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and
71RISK
open
GitHub PoC1
CVE-2026-11645
CVE-2026-11645HIGHunder attack11 Jun 2026
Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitra
71RISK
open
VulnCheck XDB
local
CVE-2023-21768HIGH11 Jun 2026
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
68RISK
open
GitHub PoC
anirudhmakkar/cve-2026-7665
CVE-2026-7665MEDIUM11 Jun 2026
Essential Addons for Elementor <= 6.6.4 - Missing Authorization to Unauthenticated Information Exposure via 'load_more' AJAX Handler
33RISK
open
GitHub PoC
CVE-2026-50507 - Draft
CVE-2026-50507MEDIUM11 Jun 2026
Windows BitLocker Security Feature Bypass Vulnerability
33RISK
open
GitHub PoC
FangFang-Yi/CVE-2024-30088
CVE-2024-30088HIGHunder attackransomware11 Jun 2026
Windows Kernel Elevation of Privilege Vulnerability
83RISK
open
GitHub PoC
This repository contains a lab validation report and detection artefacts for DirtyFrag CVE-2026-43284, a Linux local privilege escalation issue related to the XFRM/ESP page-cache write path. The focus is on auditd telemetry, event correlation, and SOC-oriented detection logic.
CVE-2026-43284HIGH11 Jun 2026
xfrm: esp: avoid in-place decrypt on shared skb frags
78RISK
open
GitHub PoC
Cyber-DarkNay/CVE-2025-6440
CVE-2025-6440CRITICAL11 Jun 2026
WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload
60RISK
open
GitHub PoC
From deobfuscating code.js to root, CVE-2023-0386
CVE-2023-0386HIGHunder attack11 Jun 2026
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISK
open
VulnCheck XDB
local
CVE-2023-0386HIGHunder attack11 Jun 2026
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISK
open
GitHub PoC
CVE-2026-10795 The UpdraftPlus POC
CVE-2026-10795HIGH11 Jun 2026
UpdraftPlus: WP Backup & Migration Plugin <= 1.26.4 - Unauthenticated Authentication Bypass via UpdraftCentral udrpc
41RISK
open
GitHub PoC
xxconi/CVE-2025-6254
CVE-2025-6254CRITICAL11 Jun 2026
Doctreat Core <= 1.6.8 - Unauthenticated Privilege Escalation
48RISK
open
VulnCheck XDB
initial-access
CVE-2026-23550CRITICAL11 Jun 2026
WordPress Modular DS plugin <= 2.5.1 - Privilege Escalation vulnerability
68RISK
open
GitHub PoC
CVE-2026-45447 - Draft
CVE-2026-45447HIGH11 Jun 2026
Heap Use-After-Free in the PKCS7_verify() Function
41RISK
open
GitHub PoC
CVE-2026-50751 Check Point IKEv1 vulnerability scanner
CVE-2026-50751CRITICALunder attackransomware10 Jun 2026
User Authentication Bypass in VPN Remote Access and Mobile Access
100RISK
open
GitHub PoC2
HTTP.sys RCE
CVE-2026-47291CRITICAL10 Jun 2026
HTTP.sys Remote Code Execution Vulnerability
33RISK
open
GitHub PoC2
CVE-2026-10520 - Ivanti Sentry Pre-Auth OS Command Injection Mass Scanner
CVE-2026-10520CRITICAL10 Jun 2026
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote
85RISK
open
previouspage 98 / 2,670next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.