Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,329cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
14,482 exploits
GitHub PoC
morzelowski/CVE-2026-12243-NLTK-PoC
CVE-2026-1224329 Aug 2026
23RISK
open
GitHub PoC
Static XML fixtures for authorized bug bounty testing of XML parser behaviour (CVE-2026-45071).
CVE-2026-45071HIGH29 Aug 2026
Symfony: XXE (Local File Disclosure) in DomCrawler::addXmlContent() via validateOnParse = true
41RISK
open
GitHub PoC
joaovicdev/EXPLOIT-CVE-2026-9198
CVE-2026-9198CRITICALunder attack29 Aug 2026
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RISK
open
GitHub PoC2
Learn how I found my first two CVEs by pure accident.
CVE-2026-19745MEDIUM29 Aug 2026
Calix GigaSpire Web Management utilities_configurationsave.cgi denial of service
33RISK
open
GitHub PoC
FranklinF25/cve-2026-42533
CVE-2026-42533CRITICAL29 Aug 2026
NGINX Map directive and Regex matching vulnerability
48RISK
open
GitHub PoC
CVE-2026-66384 - Draft or TODO
CVE-2026-66384MEDIUM28 Aug 2026
Authenticated users may write data outside the intended Docker cache path
33RISK
open
GitHub PoC
A specialized Python framework that executes unauthenticated remote code execution via the 9Router Model Context Protocol (MCP) bridge by deploying a 33-layer temporal phase cascade, Riemann-Hadamard dispersion, and an 11 ns wedge filter to bypass traditional proxy and process-monitoring defenses.
CVE-2026-46339CRITICAL28 Aug 2026
9Router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes
63RISK
open
GitHub PoC
fastjson-cve-2026-16723
CVE-2026-16723CRITICAL28 Aug 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
53RISK
open
GitHub PoC
IKEv1 VPN scanners, attempts a Check Point authentication-bypass exploit, and includes internal network scanning and reverse-shell features.
CVE-2026-50751CRITICALunder attackransomware28 Aug 2026
User Authentication Bypass in VPN Remote Access and Mobile Access
100RISK
open
GitHub PoC
Hari-v542/CVE-2026-52923
CVE-2026-52923HIGH28 Aug 2026
ipc: limit next_id allocation to the valid ID range
41RISK
open
GitHub PoC
Wazuh Rules for Detection Zimbra (CVE-2026-73570).
CVE-2026-73570HIGHunder attack28 Aug 2026
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp
91RISK
open
GitHub PoC
Testing CVE-2026-70463 by Fyyre
CVE-2026-70463HIGH28 Aug 2026
rsync 3.1.0 < 3.5.0 Authorization Bypass via auth users Directive Parsing
41RISK
open
GitHub PoC17
Metabase SQLi
CVE-2026-72898CRITICALunder attack27 Aug 2026
Metabase SQL injection via password reset endpoint
100RISK
open
GitHub PoC
Hunt-Benito/the-token-was-a-row-number-cve-2026-67602-phpipam-rest-api-authentication-bypass
CVE-2026-67602CRITICAL27 Aug 2026
phpIPAM < 1.8.2 Authentication Bypass via REST API Object Cache
48RISK
open
GitHub PoC
sahmsec/CVE-2026-32475
CVE-2026-32475CRITICAL27 Aug 2026
WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability
63RISK
open
GitHub PoC
CVE-2026-20303, CVE-2026-20304, CVE-2026-20310, CVE-2026-20312, CVE-2026-20313
CVE-2026-20303CRITICAL27 Aug 2026
Cisco Catalyst SD-WAN Security Hardening Release - Input Validation Vulnerabilities
48RISK
open
GitHub PoC3
GitLab Code injection
CVE-2026-19478CRITICAL27 Aug 2026
Improper Control of Generation of Code ('Code Injection') in GitLab
63RISK
open
GitHub PoC2
CVE-2026-18963 Keycloak Reset-Credentials State Bypass Detector
CVE-2026-18963CRITICAL27 Aug 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open
GitHub PoC
SneakyNachos/CVE-2026-74936-gc-potato
CVE-2026-74936CRITICAL27 Aug 2026
Use-after-free in the JavaScript: WebAssembly component
48RISK
open
GitHub PoC
CVE-2026-55040
CVE-2026-55040CRITICALunder attack27 Aug 2026
Microsoft SharePoint Server Security Feature Bypass Vulnerability
100RISK
open
GitHub PoC
Minimal reproduction for Spring AI ParagraphManager sibling self-loop OOM (incomplete fix of CVE-2026-47851)
CVE-2026-47851HIGH27 Aug 2026
Unbounded recursion over attacker-controlled PDF outline tree in Spring AI PDF Document Reader
41RISK
open
GitHub PoC1
CVE-2026-18431 - Draft or TODO
CVE-2026-18431CRITICAL27 Aug 2026
Avada <= 7.16 and Fusion Builder <= 3.16 - Unauthenticated Remote Code Execution via Arbitrary File Write
48RISK
open
GitHub PoC
CVE-2026-77542, CVE-2026-77543, CVE-2026-77545, CVE-2026-77550, CVE-2026-77551, CVE-2026-77552, CVE-2026-77553, CVE-2026-77554, CVE-2026-77557 - Draft or TODO
CVE-2026-77542CRITICAL27 Aug 2026
A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerabilit
48RISK
open
GitHub PoC
A scanner for CVE-2026-55040 and CVE-2026-63520, designed to determine whether the server is affected by these two CVEs.
CVE-2026-55040CRITICALunder attack27 Aug 2026
Microsoft SharePoint Server Security Feature Bypass Vulnerability
100RISK
open
GitHub PoC
sergiofigueras/cve-2026-46858
CVE-2026-46858CRITICAL26 Aug 2026
Vulnerability in the APM - Application Performance Management product of Oracle Enterprise Manager (component: JADM, JVM
48RISK
open
GitHub PoC
zenzue/CVE-2026-55040
CVE-2026-55040CRITICALunder attack26 Aug 2026
Microsoft SharePoint Server Security Feature Bypass Vulnerability
100RISK
open
GitHub PoC
WooCommerce plugin: photo & video product reviews, closing CVE-2026-12684's unauthenticated-upload vulnerability class by construction
CVE-2026-12684MEDIUM26 Aug 2026
Customer Reviews for WooCommerce < 5.113.0 - Unauthenticated Arbitrary Media Upload via cr_upload_media
33RISK
open
GitHub PoC
Poc CVE-2026-18080
CVE-2026-18080CRITICAL26 Aug 2026
ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce <= 1.17.8 - Unauthenticated Arbitrary File Upload via CRM Email Connect IMAP Attachment
48RISK
open
GitHub PoC
PostGIS SQL Injection GeoTools
CVE-2026-76904CRITICAL26 Aug 2026
GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers
63RISK
open
GitHub PoC1
CVE-2026-19632 - TranslatePress One-Day PoC
CVE-2026-19632CRITICAL26 Aug 2026
TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure
48RISK
open
page 1 / 483next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.