Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,466Referência 23,051GitHub PoC 15,051VulnCheck XDB 8,883Nuclei 4,361Metasploit 3,493✓ verified onlyrecentpopularrisk
79,305 exploits
VulnCheck XDB
initial-access
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RISK
open ↗VulnCheck XDB
initial-access
Burst Statistics 3.4.0 - 3.4.1.1 - Authentication Bypass to Admin Account Takeover
68RISK
open ↗VulnCheck XDB
client-side
Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside
83RISK
open ↗GitHub PoC
JCEzploit is a powerful, fully-automated RCE exploit for Joomla JCE (CVE-2026-48907) featuring interactive shell, batch command execution, file download capability, and proxy support. Built with Python & Rich for penetration testers. Ethical use only. By Sudeepa Wanigarathna.
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RISK
open ↗VulnCheck XDB
local
It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-a
68RISK
open ↗VulnCheck XDB
initial-access
Nginx UI: Unauthenticated MCP Endpoint Allows Remote Nginx Takeover
75RISK
open ↗GitHub PoC★ 1
Custom Content Types and Fields plugin for WordPress
Pods <= 3.3.9 - Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router
63RISK
open ↗GitHub PoC
Reflected XSS via price_from & price_to Filter Parameters in PhocaCart
Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7
33RISK
open ↗VulnCheck XDB
initial-access
Dockwatch 0.6.567 Unauthenticated OS Command Injection via ajax/compose.php
63RISK
open ↗GitHub PoC
CVE-2026-69836 - Draft or TODO
Microsoft Entra ID Remote Code Execution Vulnerability
48RISK
open ↗GitHub PoC★ 5
CVE-2026-73570
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp
98RISK
open ↗GitHub PoC★ 1
Educational use only!
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.
Via a specially crafted malici
68RISK
open ↗GitHub PoC
CVE-2026-41567 1day
Docker: `PUT /containers/{id}/archive` executes container binary on the host
41RISK
open ↗GitHub PoC★ 2
wp2shell — WordPress Core Pre-Auth RCE Chain poc for CVE-2026-63030 and CVE-2026-60137
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open ↗VulnCheck XDB
info-leak
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS
78RISK
open ↗VulnCheck XDB
initial-access
WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability
63RISK
open ↗GitHub PoC★ 1
Hunt-Benito/rendering-code-outside-the-sandbox-cve-2026-76036-dawn-webgpu-buffer-overflow-in-chrome-on-android
Buffer overflow in Dawn in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker to execute arbi
48RISK
open ↗GitHub PoC
CVE-2022-36804 Bitbucket command execution and file transfer tool
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISK
open ↗Metasploit600
SPIP X-Spip-Filtre Unauthenticated RCE
SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August
43RISK
open ↗VulnCheck XDB
initial-access
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open ↗VulnCheck XDB
initial-access
Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator
48RISK
open ↗GitHub PoC
Deterministic memory-poisoning / prompt-injection measurement axis — CoSnitch (CVE-2026-24301) anchored. Inspect scorer, signed receipts. Measurement, not certification.
Microsoft Copilot Information Disclosure Vulnerability
41RISK
open ↗GitHub PoC
Proof-of-concept for CVE-2026-18315 (TrueBooker WordPress Plugin): Unauthenticated Authorization Bypass Through User-Controlled Key to Account Takeover
TrueBooker <= 1.2.6 - Unauthenticated Authorization Bypass Through User-Controlled Key to Account Takeover to 'truebooker_wp_user_id' Parameter
48RISK
open ↗VulnCheck XDB
local
The Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishan
76RISK
open ↗GitHub PoC
Analyze and reproduce CVE-2025-55182.
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open ↗GitHub PoC★ 38
Exploit for KeyCloak CVE-2026-18963
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open ↗GitHub PoC
Controlled PenTest lab report for UnrealIRCd 3.2.8.1 backdoor (CVE-2010-2075) on Metasploitable3 with remediation steps.
UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally
60RISK
open ↗GitHub PoC
Hunt-Benito/the-same-key-opens-every-box-cve-2026-71960-hard-coded-jwt-secret-in-cudy-wr3000-mesh-mqtt
Cudy WR3000 2.0 Hard-coded JWT Secret Authentication Bypass via MQTT
48RISK
open ↗VulnCheck XDB
initial-access
Improper Control of Generation of Code ('Code Injection') in GitLab
63RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.