Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,275cataloged exploits
36,462CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,465Referência 23,051GitHub PoC 15,045VulnCheck XDB 8,860Nuclei 4,361Metasploit 3,493✓ verified onlyrecentpopularrisk
79,278 exploits
GitHub PoC
Stored XSS via Location Title in DPCalendar Free
Joomla Extension - digital-peak.com - Authenticated, privileged stored XSS in DP Calendar 7.0.0 - 10.11.2
41RISK
open ↗GitHub PoC
CVE-2026-64788 PoC — IOGPUFamily Use-After-Free (iOS 26.6 / 23G71)
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe
33RISK
open ↗GitHub PoC
🧰 CVE-2026-65643 – cPanel Domain Parking RCE Toolkit (CVSS 8.7) | Red/Blue Team suite for unpatched cPanel & WHM 11.x (110,134,136,138). 2 tools: Full Exploit (reverse shell, webshell, persistence, root passwd, file R/W, mass scan, Tor), Blue Team PoC (detection, reporting, audit). w/Python. 🦾 Only Use Ethically, Stay Legal <3
Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.
41RISK
open ↗GitHub PoC
Research lab and exploit chain for CVE-2026-75604: path traversal in the Next.js incremental cache, to RCE on Windows.
Next.js: Unauthenticated Remote Code Execution on windows-hosted servers
48RISK
open ↗GitHub PoC
CVE-2026-80428 PoC
ILIAS before 9.22, 10.10 and 11.3 Unauthenticated PHP Object Injection via Shibboleth Logout Endpoint
48RISK
open ↗GitHub PoC
CVE-2026-19949 - Draft or TODO
All-in-One WP Migration and Backup <= 7.109 - Unauthenticated Second-Order SQL Injection via Archive Restore to Remote Code Execution
41RISK
open ↗GitHub PoC
CVE-2026-20212 - Draft or TODO
Cisco Nexus 3000 and 9000 Series Switches Silicon One Hardware Abstraction Layer Remote Code Execution Vulnerability
48RISK
open ↗GitHub PoC
CVE-2026-80428 PoC
ILIAS before 9.22, 10.10 and 11.3 Unauthenticated PHP Object Injection via Shibboleth Logout Endpoint
48RISK
open ↗GitHub PoC
Vulnerability Analysis of CVE-2026-83548 affecting SonicWall SMA1000 security systems.
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended altern
78RISK
open ↗GitHub PoC
Recovery notes for proxmox advisory ID: PSA-2026-00043-1 (CVE-2023-54391)
Proxmox VE 7.0-8.0 Authentication Bypass via tfa-challenge Parameter
48RISK
open ↗GitHub PoC
AJCloud AJY IPC Firmware Path Traversal via jdbhttpd
AJCloud AJY IPC Firmware Path Traversal via jdbhttpd
41RISK
open ↗GitHub PoC
SQL Injection via ORDER BY Shortcode in plg_content_dpcalendar — DPCalendar Free ≤ 10.11.2
Joomla Extension - digital-peak.com - Authenticated, privileged blind SQL injection in DP Calendar 5.5.0 - 10.11.2
33RISK
open ↗GitHub PoC
CVE‑2026‑82329 is a critical authentication bypass in JFrog Artifactory (CVSS 9.8) allowing unauthenticated attackers to obtain full administrative privileges. Actively exploited in the wild. Affects self‑hosted versions before patches. PoC for authorized testing only.
Potential authentication bypass leading to administrative access in Artifactory
93RISK
open ↗GitHub PoC
CVE-2026-65343 PoC — AppleKeyStore OOB read → KASLR defeat (iOS 26.6 / 23G71)
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.
41RISK
open ↗GitHub PoC★ 2
CVE-2026-65349 PoC — getattrlist OOB write in vfs_attr_pack_internal (iOS 26.6 / 23G71)
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1,
33RISK
open ↗GitHub PoC★ 3
CVE-2026-64788 PoC — IOGPUFamily Use-After-Free (iOS 26.6 / 23G71)
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe
33RISK
open ↗GitHub PoC
Saku0512/CVE-2026-84361-poc
Composer: Perforce source URL permits P4PORT `rsh:` command execution
41RISK
open ↗GitHub PoC★ 51
CVE-2026-65343 PoC — AppleKeyStore OOB read → KASLR defeat (iOS 26.6 / 23G71)
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.
41RISK
open ↗GitHub PoC
AneKazek/cve-2026-47627
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause path traversal. A succes
48RISK
open ↗GitHub PoC
CVE-2026-38577
Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.0-260302 allows attackers to gain root access.
48RISK
open ↗VulnCheck XDB
initial-access
Langflow code Code Injection Remote Code Execution Vulnerability
48RISK
open ↗VulnCheck XDB
initial-access
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open ↗GitHub PoC★ 6
NetScaler ADC/Gateway SAML unsigned-assertion bypass via HTTP-Redirect binding (CTX696939) - root cause analysis + PoC
NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490
48RISK
open ↗Exploit-DB
Langflow 1.10.0 - RCE
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RISK
open ↗GitHub PoC
SAP-system-update/CVE-2026-58231
Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)
48RISK
open ↗GitHub PoC
CVE-2026-73296
Microsoft UFO: Unauthenticated Mobile MCP access allows remote Android device control and screen disclosure
48RISK
open ↗GitHub PoC
CVE-2026-9335: KerasFileEditor and load_weights follow h5py ExternalLinks, disclosing arbitrary local HDF5 file contents in keras ≤ 3.14.0. Advisory + verified PoCs.
Improper Handling of HDF5 ExternalLinks in keras-team/keras
33RISK
open ↗GitHub PoC
CVE-2026-38577
Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.0-260302 allows attackers to gain root access.
48RISK
open ↗GitHub PoC
CVE-2026-9586 - Draft or TODO
Unauthenticated SQL Injection Leading to Remote Code Execution in Switchvox SMB
83RISK
open ↗page 1 / 2,643next →
We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.