Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
79,305 exploits
VulnCheck XDB
initial-access
CVE-2026-60137MEDIUMunder attack21 Aug 2026
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-8181CRITICAL21 Aug 2026
Burst Statistics 3.4.0 - 3.4.1.1 - Authentication Bypass to Admin Account Takeover
68RISK
open
VulnCheck XDB
client-side
CVE-2024-4947CRITICALunder attack21 Aug 2026
Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside
83RISK
open
GitHub PoC
JCEzploit is a powerful, fully-automated RCE exploit for Joomla JCE (CVE-2026-48907) featuring interactive shell, batch command execution, file download capability, and proxy support. Built with Python & Rich for penetration testers. Ethical use only. By Sudeepa Wanigarathna.
CVE-2026-48907CRITICALunder attack21 Aug 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RISK
open
VulnCheck XDB
local
CVE-2022-2586MEDIUMunder attack21 Aug 2026
It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-a
68RISK
open
VulnCheck XDB
initial-access
CVE-2026-33032CRITICAL21 Aug 2026
Nginx UI: Unauthenticated MCP Endpoint Allows Remote Nginx Takeover
75RISK
open
GitHub PoC1
Custom Content Types and Fields plugin for WordPress
CVE-2026-19598CRITICAL21 Aug 2026
Pods <= 3.3.9 - Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router
63RISK
open
GitHub PoC
Reflected XSS via price_from & price_to Filter Parameters in PhocaCart
CVE-2026-76565MEDIUM21 Aug 2026
Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7
33RISK
open
VulnCheck XDB
initial-access
CVE-2026-58455CRITICAL21 Aug 2026
Dockwatch 0.6.567 Unauthenticated OS Command Injection via ajax/compose.php
63RISK
open
GitHub PoC
CVE-2026-69836 - Draft or TODO
CVE-2026-69836CRITICAL21 Aug 2026
Microsoft Entra ID Remote Code Execution Vulnerability
48RISK
open
GitHub PoC5
CVE-2026-73570
CVE-2026-73570HIGHunder attack21 Aug 2026
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp
98RISK
open
GitHub PoC1
Educational use only!
CVE-2026-64638HIGH21 Aug 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
68RISK
open
GitHub PoC
CVE-2026-41567 1day
CVE-2026-41567HIGH21 Aug 2026
Docker: `PUT /containers/{id}/archive` executes container binary on the host
41RISK
open
GitHub PoC2
wp2shell — WordPress Core Pre-Auth RCE Chain poc for CVE-2026-63030 and CVE-2026-60137
CVE-2026-63030CRITICALunder attack21 Aug 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
VulnCheck XDB
info-leak
CVE-2026-65400CRITICALunder attack21 Aug 2026
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS
78RISK
open
VulnCheck XDB
initial-access
CVE-2026-32475CRITICAL21 Aug 2026
WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability
63RISK
open
GitHub PoC1
Hunt-Benito/rendering-code-outside-the-sandbox-cve-2026-76036-dawn-webgpu-buffer-overflow-in-chrome-on-android
CVE-2026-76036CRITICAL21 Aug 2026
Buffer overflow in Dawn in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker to execute arbi
48RISK
open
GitHub PoC
CVE-2022-36804 Bitbucket command execution and file transfer tool
CVE-2022-36804HIGHunder attack21 Aug 2026
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISK
open
Metasploit600
SPIP X-Spip-Filtre Unauthenticated RCE
CVE-2026-77647CRITICAL20 Aug 2026
SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August
43RISK
open
VulnCheck XDB
initial-access
CVE-2026-18963CRITICAL20 Aug 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open
VulnCheck XDB
initial-access
CVE-2026-18366CRITICAL20 Aug 2026
Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator
48RISK
open
GitHub PoC
Deterministic memory-poisoning / prompt-injection measurement axis — CoSnitch (CVE-2026-24301) anchored. Inspect scorer, signed receipts. Measurement, not certification.
CVE-2026-24301HIGH20 Aug 2026
Microsoft Copilot Information Disclosure Vulnerability
41RISK
open
GitHub PoC
Proof-of-concept for CVE-2026-18315 (TrueBooker WordPress Plugin): Unauthenticated Authorization Bypass Through User-Controlled Key to Account Takeover
CVE-2026-18315CRITICAL20 Aug 2026
TrueBooker <= 1.2.6 - Unauthenticated Authorization Bypass Through User-Controlled Key to Account Takeover to 'truebooker_wp_user_id' Parameter
48RISK
open
VulnCheck XDB
local
CVE-2022-38181HIGHunder attack20 Aug 2026
The Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishan
76RISK
open
GitHub PoC
Analyze and reproduce CVE-2025-55182.
CVE-2025-55182CRITICALunder attackransomware20 Aug 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC38
Exploit for KeyCloak CVE-2026-18963
CVE-2026-18963CRITICAL20 Aug 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open
GitHub PoC
Controlled PenTest lab report for UnrealIRCd 3.2.8.1 backdoor (CVE-2010-2075) on Metasploitable3 with remediation steps.
CVE-2010-207520 Aug 2026
UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally
60RISK
open
GitHub PoC
Hunt-Benito/the-same-key-opens-every-box-cve-2026-71960-hard-coded-jwt-secret-in-cudy-wr3000-mesh-mqtt
CVE-2026-71960CRITICAL20 Aug 2026
Cudy WR3000 2.0 Hard-coded JWT Secret Authentication Bypass via MQTT
48RISK
open
VulnCheck XDB
initial-access
CVE-2026-19478CRITICAL20 Aug 2026
Improper Control of Generation of Code ('Code Injection') in GitLab
63RISK
open
VulnCheck XDB
local
CVE-2025-21479HIGHunder attack20 Aug 2026
Incorrect Authorization in Graphics
71RISK
open
previouspage 12 / 2,644next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.