Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,232cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
79,232 exploits
GitHub PoC1
CVE-2026-65349 PoC — getattrlist OOB write in vfs_attr_pack_internal (iOS 26.6 / 23G71)
CVE-2026-65349MEDIUM02 Sep 2026
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1,
33RISK
open
GitHub PoC
byt3l0rd/CVE-2026-73570
CVE-2026-73570HIGHunder attack02 Sep 2026
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp
98RISK
open
GitHub PoC1
CVE-2026-64788 PoC — IOGPUFamily Use-After-Free (iOS 26.6 / 23G71)
CVE-2026-64788MEDIUM02 Sep 2026
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe
33RISK
open
GitHub PoC
CVE-2026-73296
CVE-2026-73296CRITICAL02 Sep 2026
Microsoft UFO: Unauthenticated Mobile MCP access allows remote Android device control and screen disclosure
48RISK
open
GitHub PoC1
NetScaler ADC/Gateway SAML unsigned-assertion bypass via HTTP-Redirect binding (CTX696939) - root cause analysis + PoC
CVE-2026-19490CRITICAL02 Sep 2026
NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490
48RISK
open
VulnCheck XDB
initial-access
CVE-2018-14667CRITICALunder attack02 Sep 2026
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resou
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-39987CRITICALunder attack02 Sep 2026
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RISK
open
GitHub PoC
SAP-system-update/CVE-2026-58231
CVE-2026-58231CRITICAL02 Sep 2026
Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)
48RISK
open
VulnCheck XDB
initial-access
CVE-2026-0768CRITICAL02 Sep 2026
Langflow code Code Injection Remote Code Execution Vulnerability
48RISK
open
VulnCheck XDB
initial-access
CVE-2026-18963CRITICAL02 Sep 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open
GitHub PoC1
CVE-2026-65343 PoC — AppleKeyStore OOB read → KASLR defeat (iOS 26.6 / 23G71)
CVE-2026-65343HIGH02 Sep 2026
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.
41RISK
open
GitHub PoC1
CVE-2026-65330 PoC — setxattr PAC bypass via fixed #0x307a diversifier (iOS 26.6 / 23G71)
CVE-2026-65330MEDIUM02 Sep 2026
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe
33RISK
open
VulnCheck XDB
initial-access
CVE-2026-82329CRITICALunder attack02 Sep 2026
Potential authentication bypass leading to administrative access in Artifactory
93RISK
open
VulnCheck XDB
initial-access
CVE-2026-0920CRITICAL02 Sep 2026
LA-Studio Element Kit for Elementor <= 1.5.6.3 - Unauthenticated Privilege Escalation via Backdoor to Administrative User Creation via lakit_bkrole parameter
48RISK
open
GitHub PoC
tcollins-hashicorp/vault-cve-2026-5006-audit
CVE-2026-5006MEDIUM02 Sep 2026
Vault Vulnerable to Privilege Escalation via Slash Injection in Templated Policy Paths
33RISK
open
VulnCheck XDB
initial-access
CVE-2022-2907802 Sep 2026
The ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[
50RISK
open
VulnCheck XDB
initial-access
CVE-2026-5027HIGH02 Sep 2026
Langflow - Path Traversal Arbitrary File Write via upload_user_file
68RISK
open
VulnCheck XDB
initial-access
CVE-2024-55591CRITICALunder attackransomware02 Sep 2026
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro
100RISK
open
GitHub PoC
Bypassing connect()-based syscall rules using TCP Fast Open (CVE-2026-63828 PoC)
CVE-2026-63828HIGH02 Sep 2026
apparmor: mediate the implicit connect of TCP fast open sendmsg
41RISK
open
GitHub PoC
CVE-2026-0828
CVE-2026-0828HIGH02 Sep 2026
Kernel driver vulnerability in Safetica Endpoint Client
41RISK
open
GitHub PoC
CVE-2026-82329 — JFrog Artifactory unauthenticated authentication bypass ("phantom join key" -> forged service admin token)
CVE-2026-82329CRITICALunder attack02 Sep 2026
Potential authentication bypass leading to administrative access in Artifactory
93RISK
open
GitHub PoC1
CVE-2026-82329 — JFrog Artifactory (self-hosted) Auth Bypass
CVE-2026-82329CRITICALunder attack02 Sep 2026
Potential authentication bypass leading to administrative access in Artifactory
93RISK
open
GitHub PoC
CVE-2026-9586 - Draft or TODO
CVE-2026-9586CRITICALunder attack02 Sep 2026
Unauthenticated SQL Injection Leading to Remote Code Execution in Switchvox SMB
83RISK
open
GitHub PoC
CVE-2026-9335: KerasFileEditor and load_weights follow h5py ExternalLinks, disclosing arbitrary local HDF5 file contents in keras ≤ 3.14.0. Advisory + verified PoCs.
CVE-2026-9335MEDIUM02 Sep 2026
Improper Handling of HDF5 ExternalLinks in keras-team/keras
33RISK
open
Exploit-DB
Langflow 1.10.0 - RCE
CVE-2026-9198CRITICALunder attackwebappsmultiple02 Sep 2026
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RISK
open
GitHub PoC
CVE-2026-38577
CVE-2026-38577CRITICAL02 Sep 2026
Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.0-260302 allows attackers to gain root access.
48RISK
open
GitHub PoC
EXEcution-py/CVE-2026-9055
CVE-2026-9055CRITICAL02 Sep 2026
Booking for Appointments and Events Calendar – Amelia (Premium) 8.0 - 9.6.2 - Unauthenticated Privilege Escalation to Administrator via 'externalId'
48RISK
open
GitHub PoC
Saku0512/CVE-2026-84361-poc
CVE-2026-84361HIGH02 Sep 2026
Composer: Perforce source URL permits P4PORT `rsh:` command execution
41RISK
open
Exploit-DB
EasyAppointments 1.5.1 - Blind SQL Injection
CVE-2025-50455CRITICALwebappsmultiple01 Sep 2026
SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint in Alex Tselegidis EasyAp
48RISK
open
GitHub PoC
CVE-2026-82329 - Draft or TODO
CVE-2026-82329CRITICALunder attack01 Sep 2026
Potential authentication bypass leading to administrative access in Artifactory
93RISK
open
page 1 / 2,642next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.