Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,232cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,465Referência 23,022GitHub PoC 15,031VulnCheck XDB 8,860Nuclei 4,361Metasploit 3,493✓ verified onlyrecentpopularrisk
79,232 exploits
GitHub PoC★ 1
CVE-2026-65349 PoC — getattrlist OOB write in vfs_attr_pack_internal (iOS 26.6 / 23G71)
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1,
33RISK
open ↗GitHub PoC
byt3l0rd/CVE-2026-73570
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp
98RISK
open ↗GitHub PoC★ 1
CVE-2026-64788 PoC — IOGPUFamily Use-After-Free (iOS 26.6 / 23G71)
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe
33RISK
open ↗GitHub PoC
CVE-2026-73296
Microsoft UFO: Unauthenticated Mobile MCP access allows remote Android device control and screen disclosure
48RISK
open ↗GitHub PoC★ 1
NetScaler ADC/Gateway SAML unsigned-assertion bypass via HTTP-Redirect binding (CTX696939) - root cause analysis + PoC
NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490
48RISK
open ↗VulnCheck XDB
initial-access
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resou
100RISK
open ↗VulnCheck XDB
initial-access
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RISK
open ↗GitHub PoC
SAP-system-update/CVE-2026-58231
Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)
48RISK
open ↗VulnCheck XDB
initial-access
Langflow code Code Injection Remote Code Execution Vulnerability
48RISK
open ↗VulnCheck XDB
initial-access
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open ↗GitHub PoC★ 1
CVE-2026-65343 PoC — AppleKeyStore OOB read → KASLR defeat (iOS 26.6 / 23G71)
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.
41RISK
open ↗GitHub PoC★ 1
CVE-2026-65330 PoC — setxattr PAC bypass via fixed #0x307a diversifier (iOS 26.6 / 23G71)
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe
33RISK
open ↗VulnCheck XDB
initial-access
Potential authentication bypass leading to administrative access in Artifactory
93RISK
open ↗VulnCheck XDB
initial-access
LA-Studio Element Kit for Elementor <= 1.5.6.3 - Unauthenticated Privilege Escalation via Backdoor to Administrative User Creation via lakit_bkrole parameter
48RISK
open ↗GitHub PoC
tcollins-hashicorp/vault-cve-2026-5006-audit
Vault Vulnerable to Privilege Escalation via Slash Injection in Templated Policy Paths
33RISK
open ↗VulnCheck XDB
initial-access
The ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[
50RISK
open ↗VulnCheck XDB
initial-access
Langflow - Path Traversal Arbitrary File Write via upload_user_file
68RISK
open ↗VulnCheck XDB
initial-access
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro
100RISK
open ↗GitHub PoC
Bypassing connect()-based syscall rules using TCP Fast Open (CVE-2026-63828 PoC)
apparmor: mediate the implicit connect of TCP fast open sendmsg
41RISK
open ↗GitHub PoC
CVE-2026-82329 — JFrog Artifactory unauthenticated authentication bypass ("phantom join key" -> forged service admin token)
Potential authentication bypass leading to administrative access in Artifactory
93RISK
open ↗GitHub PoC★ 1
CVE-2026-82329 — JFrog Artifactory (self-hosted) Auth Bypass
Potential authentication bypass leading to administrative access in Artifactory
93RISK
open ↗GitHub PoC
CVE-2026-9586 - Draft or TODO
Unauthenticated SQL Injection Leading to Remote Code Execution in Switchvox SMB
83RISK
open ↗GitHub PoC
CVE-2026-9335: KerasFileEditor and load_weights follow h5py ExternalLinks, disclosing arbitrary local HDF5 file contents in keras ≤ 3.14.0. Advisory + verified PoCs.
Improper Handling of HDF5 ExternalLinks in keras-team/keras
33RISK
open ↗Exploit-DB
Langflow 1.10.0 - RCE
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RISK
open ↗GitHub PoC
CVE-2026-38577
Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.0-260302 allows attackers to gain root access.
48RISK
open ↗GitHub PoC
EXEcution-py/CVE-2026-9055
Booking for Appointments and Events Calendar – Amelia (Premium) 8.0 - 9.6.2 - Unauthenticated Privilege Escalation to Administrator via 'externalId'
48RISK
open ↗GitHub PoC
Saku0512/CVE-2026-84361-poc
Composer: Perforce source URL permits P4PORT `rsh:` command execution
41RISK
open ↗Exploit-DB
EasyAppointments 1.5.1 - Blind SQL Injection
SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint in Alex Tselegidis EasyAp
48RISK
open ↗GitHub PoC
CVE-2026-82329 - Draft or TODO
Potential authentication bypass leading to administrative access in Artifactory
93RISK
open ↗page 1 / 2,642next →
We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.