Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
79,305 exploits
VulnCheck XDB
initial-access
CVE-2026-18963CRITICAL20 Aug 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open
GitHub PoC
Proof-of-concept for CVE-2026-18315 (TrueBooker WordPress Plugin): Unauthenticated Authorization Bypass Through User-Controlled Key to Account Takeover
CVE-2026-18315CRITICAL20 Aug 2026
TrueBooker <= 1.2.6 - Unauthenticated Authorization Bypass Through User-Controlled Key to Account Takeover to 'truebooker_wp_user_id' Parameter
48RISK
open
GitHub PoC
Deterministic memory-poisoning / prompt-injection measurement axis — CoSnitch (CVE-2026-24301) anchored. Inspect scorer, signed receipts. Measurement, not certification.
CVE-2026-24301HIGH20 Aug 2026
Microsoft Copilot Information Disclosure Vulnerability
41RISK
open
GitHub PoC
aarch64 race condition checker
CVE-2026-46242HIGH20 Aug 2026
eventpoll: fix ep_remove struct eventpoll / struct file UAF
41RISK
open
GitHub PoC
CVE-2026-18366: Events Manager < 7.4.1 — Unauthenticated Privilege Escalation to Administrator. Write-up and proof-of-concept (poc.py).
CVE-2026-18366CRITICAL20 Aug 2026
Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator
48RISK
open
GitHub PoC
wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain
CVE-2026-63030CRITICALunder attack20 Aug 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
GitHub PoC
CVE-2026-19478: GitLab GraphQL Vulnerability PoC
CVE-2026-19478CRITICAL20 Aug 2026
Improper Control of Generation of Code ('Code Injection') in GitLab
63RISK
open
GitHub PoC15
Hunt for CVE-2026-18963 exploitation traces (Keycloak unauthenticated account takeover) in the Keycloak database
CVE-2026-18963CRITICAL20 Aug 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open
GitHub PoC1
elkhaoudari/CVE-2018-7600-PoC
CVE-2018-7600CRITICALunder attackransomware20 Aug 2026
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
GitHub PoC1
halo cms plugin 1-request rce from a url, PoC + exploit chain
CVE-2026-67919CRITICAL19 Aug 2026
An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the PluginEndpoint.java, installFromUri m
48RISK
open
GitHub PoC
CVE-2026-47858
CVE-2026-47858HIGH19 Aug 2026
live information startup mode is vulnerable for remote code execution
41RISK
open
GitHub PoC531
A cPanel and WHM authentication bypassing tool
CVE-2026-41940CRITICALunder attackransomware19 Aug 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISK
open
GitHub PoC1
VsockDrop (CVE-2026-53365) Linux kernel io_uring zerocopy vsock LPE exploit mirror — MaherAzzouzi, MIT; for authorized security testing
CVE-2026-53365HIGH19 Aug 2026
vsock/virtio: fix zerocopy completion for multi-skb sends
41RISK
open
GitHub PoC
Proof of Concept for CVE-2026-19598 affecting Pods <= 3.3.9.
CVE-2026-19598CRITICAL19 Aug 2026
Pods <= 3.3.9 - Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router
63RISK
open
GitHub PoC1
0xdeadroot/SCTPhantom-CVE-2026-64564
CVE-2026-64564CRITICAL19 Aug 2026
sctp: don't free the ASCONF's own transport in DEL-IP processing
48RISK
open
GitHub PoC1
Ring0-level process killer leveraging CVE-2026-0828 (BYOVD). Designed to demonstrate kernel-level process termination via a vulnerable signed driver, highlighting the security risks of Bring Your Own Vulnerable Driver attacks and the importance of driver trust, monitoring, and endpoint protection.
CVE-2026-0828HIGH19 Aug 2026
Kernel driver vulnerability in Safetica Endpoint Client
41RISK
open
GitHub PoC1
4gaBoards < 3.3.9 - User Information Disclosure
CVE-2026-53959MEDIUM19 Aug 2026
4gaBoards: Mass Information Disclosure (Internal PII Leakage) on /api/users to any authenticated user
33RISK
open
GitHub PoC
TranDongA3/POC-CVE-2026-63030-CVE-2026-60137-
CVE-2026-63030CRITICALunder attack19 Aug 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
GitHub PoC
JetBrains TeamCity On-Premises CVE-2026-63077 Emergency Hardening & Patch Runbook Package
CVE-2026-63077CRITICALunder attack19 Aug 2026
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent pollin
100RISK
open
GitHub PoC
zavisco/CVE-2026-64849.yaml
CVE-2026-64849CRITICALunder attack19 Aug 2026
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
98RISK
open
GitHub PoC1
Begitdj/cve-2019-2215-markw
CVE-2019-2215HIGHunder attack19 Aug 2026
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISK
open
GitHub PoC
andreamammano89-maker/CVE-2021-42013_821311
CVE-2021-42013CRITICALunder attackransomware19 Aug 2026
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
GitHub PoC
Oracle OID LDAP Server Privileges Management Exploit
CVE-2026-61241CRITICAL19 Aug 2026
Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Suppor
28RISK
open
VulnCheck XDB
initial-access
CVE-2026-39987CRITICALunder attack19 Aug 2026
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALunder attack19 Aug 2026
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
VulnCheck XDB
local
CVE-2025-21479HIGHunder attack19 Aug 2026
Incorrect Authorization in Graphics
71RISK
open
VulnCheck XDB
initial-access
CVE-2026-19598CRITICAL19 Aug 2026
Pods <= 3.3.9 - Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router
63RISK
open
GitHub PoC1
renzi25031469/CVE-2026-19478
CVE-2026-19478CRITICAL19 Aug 2026
Improper Control of Generation of Code ('Code Injection') in GitLab
63RISK
open
VulnCheck XDB
initial-access
CVE-2023-46604CRITICALunder attackransomware19 Aug 2026
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISK
open
VulnCheck XDB
local
CVE-2019-2215HIGHunder attack19 Aug 2026
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISK
open
previouspage 13 / 2,644next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.