Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,386cataloged exploits
36,533CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,466Referência 23,104GitHub PoC 15,075VulnCheck XDB 8,883Nuclei 4,365Metasploit 3,493✓ verified onlyrecentpopularrisk
79,305 exploits
GitHub PoC
MattiaCervelli/CVE-2025-24893_Analysis
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open ↗VulnCheck XDB
local
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISK
open ↗GitHub PoC
CVE-2026-64849 PoC
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
98RISK
open ↗GitHub PoC
Forminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration
Forminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration
48RISK
open ↗VulnCheck XDB
initial-access
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open ↗GitHub PoC
open-flaw/CVE-2026-56848
A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_m
41RISK
open ↗GitHub PoC★ 1
Begitdj/cve-2019-2215-markw
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISK
open ↗GitHub PoC
CVE-2026-18504, CVE-2026-16732 - Draft or TODO
fastify vulnerable to schema validation bypass via root primitive coercion mismatch
33RISK
open ↗GitHub PoC
zavisco/CVE-2026-64849.yaml
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
98RISK
open ↗GitHub PoC
andreamammano89-maker/CVE-2021-42013_821311
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open ↗GitHub PoC★ 1
halo cms plugin 1-request rce from a url, PoC + exploit chain
An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the PluginEndpoint.java, installFromUri m
48RISK
open ↗GitHub PoC
CVE-2026-47858
live information startup mode is vulnerable for remote code execution
41RISK
open ↗GitHub PoC★ 1
VsockDrop (CVE-2026-53365) Linux kernel io_uring zerocopy vsock LPE exploit mirror — MaherAzzouzi, MIT; for authorized security testing
vsock/virtio: fix zerocopy completion for multi-skb sends
41RISK
open ↗GitHub PoC★ 10
Reproducible A/B lab + safe PoC for GitLab CVE-2026-19478 / CVE-2026-19650 (GraphQL @gl_introduced)
Improper Control of Generation of Code ('Code Injection') in GitLab
63RISK
open ↗GitHub PoC
kaleth4/CVE-2026-64638
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.
Via a specially crafted malici
68RISK
open ↗GitHub PoC
codeb0ssx/CVE-2026-64849-PoC
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
98RISK
open ↗GitHub PoC
TP-Link Archer BE800 V1 — Parental Control LAN RCE
Command Injection Vulnerability in Parent Control of Multiple TP-Link Archer Devices
41RISK
open ↗GitHub PoC★ 3
CVE-2026-65400
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS
78RISK
open ↗VulnCheck XDB
initial-access
Pods <= 3.3.9 - Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router
63RISK
open ↗VulnCheck XDB
initial-access
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open ↗GitHub PoC
Technical analysis and clean Java Thread Echo PoC for Oracle WebLogic Server vulnerability chain.
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open ↗GitHub PoC★ 2
CVE-2026-14669 - PostgreSQL to_char() timezone abbreviation heap buffer overflow PoC; for authorized security testing
PostgreSQL to_char heap buffer overflow executes arbitrary code
41RISK
open ↗GitHub PoC
CVE-2026-43499 (GhostLock) — Linux kernel futex PI rt_mutex UAF ARM32 privilege escalation research targeting Huawei Watch 4 Pro (kernel 5.4.210)
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open ↗VulnCheck XDB
initial-access
Ray is vulnerable to RCE via Safari & Firefox Browsers through DNS Rebinding Attack
83RISK
open ↗VulnCheck XDB
local
The (1) pipe_read and (2) pipe_write implementations in fs/pipe.c in the Linux kernel before 3.16 do not properly consid
23RISK
open ↗GitHub PoC★ 1
PoC for CVE-2026-44848: Portainer missing authorization on Docker plugin endpoints -> host RCE (GHSA-rrmm-9v76-h3p4). Stdlib-only Python.
Portainer: Missing authorization on Docker plugin endpoints allows host RCE
48RISK
open ↗GitHub PoC★ 1
CVE-2026-19500 poc
SureForms contains an uncontrolled resource consumption vulnerability
41RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.