Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,386cataloged exploits
36,533CVEs with public exploitation
24,695lab-tested
79,305 exploits
VulnCheck XDB
initial-access
CVE-2026-19478CRITICAL18 Aug 2026
Improper Control of Generation of Code ('Code Injection') in GitLab
63RISK
open
VulnCheck XDB
initial-access
CVE-2026-19598CRITICAL18 Aug 2026
Pods <= 3.3.9 - Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router
63RISK
open
GitHub PoC
CVE-2026-43499 (GhostLock) — Linux kernel futex PI rt_mutex UAF ARM32 privilege escalation research targeting Huawei Watch 4 Pro (kernel 5.4.210)
CVE-2026-43499HIGH18 Aug 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
VulnCheck XDB
initial-access
CVE-2025-62593CRITICALunder attack18 Aug 2026
Ray is vulnerable to RCE via Safari & Firefox Browsers through DNS Rebinding Attack
83RISK
open
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALunder attack18 Aug 2026
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
VulnCheck XDB
local
CVE-2015-180518 Aug 2026
The (1) pipe_read and (2) pipe_write implementations in fs/pipe.c in the Linux kernel before 3.16 do not properly consid
23RISK
open
VulnCheck XDB
initial-access
CVE-2026-19478CRITICAL18 Aug 2026
Improper Control of Generation of Code ('Code Injection') in GitLab
63RISK
open
GitHub PoC
Technical analysis and clean Java Thread Echo PoC for Oracle WebLogic Server vulnerability chain.
CVE-2020-14882CRITICALunder attack18 Aug 2026
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
VulnCheck XDB
local
CVE-2018-8611HIGHunder attack17 Aug 2026
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "
71RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2017-7494CRITICALunder attackransomware17 Aug 2026
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-72898CRITICALunder attack17 Aug 2026
Metabase SQL injection via password reset endpoint
100RISK
open
GitHub PoC
CVE-2026-59310
CVE-2026-59310CRITICALunder attack17 Aug 2026
vCenter directory-traversal vulnerability
90RISK
open
GitHub PoC
CVE-2026-59310 PoC
CVE-2026-59310CRITICALunder attack17 Aug 2026
vCenter directory-traversal vulnerability
90RISK
open
GitHub PoC
CVE-2026-74943, Use after free in Firefox RasterImage (sec-high)
CVE-2026-74943CRITICAL17 Aug 2026
Use-after-free in the Graphics: ImageLib component
48RISK
open
Exploit-DB
Joomla JCE_2.9.15 - Remote Code Execution
CVE-2026-48907CRITICALunder attackwebappsmultiple17 Aug 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RISK
open
GitHub PoC
golang.org/x/text v0.33.0 backport of CVE-2026-56852 (GO-2026-5970) for Go 1.24
CVE-2026-56852HIGH17 Aug 2026
Infinite loop on invalid input in golang.org/x/text
41RISK
open
GitHub PoC
Unauthenticated SQL Injection via Attribute Filter in Phoca Cart - CVSS 9.3
CVE-2026-74251CRITICAL17 Aug 2026
Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0-6.1.6
48RISK
open
GitHub PoC1
CVE-2026-62737 ExecutionContext.sys arbitrary kernel-call PoC
CVE-2026-62737HIGH17 Aug 2026
Windows Kernel Elevation of Privilege Vulnerability
41RISK
open
GitHub PoC
Isolated Docker lab, static detection scanner, and PoC validation for React2Shell (CVE-2025-55182).
CVE-2025-55182CRITICALunder attackransomware17 Aug 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
Exploit-DB
WooCommerce 1.5.0 - Unauthenticated Arbitrary File Upload
CVE-2026-3891CRITICALwebappsmultiple17 Aug 2026
Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload
68RISK
open
GitHub PoC1
ZendTo unauthenticated ClamAV CVE-2026-20217 RCE and default-profile root escalation reproduction
CVE-2026-20217HIGH17 Aug 2026
ClamAV PESpin File Format Processing Out-of-Bounds Memory Corruption Vulnerability
41RISK
open
GitHub PoC
CVE-2026-74970, Fission site isolation bypass in Firefox WebRender
CVE-2026-74970MEDIUM17 Aug 2026
Site isolation issue in the Graphics component
33RISK
open
GitHub PoC6
A poc and write-up for CVE-2026-40345
CVE-2026-40345HIGH17 Aug 2026
deepmerge-ts: Stack exhaustion when merging recursive object graphs
41RISK
open
GitHub PoC1
CVE-2026-71518 — Typemill <2.26.0 unauthenticated authorization bypass in media file download (path-equivalent URL variants). Advisory + PoC.
CVE-2026-71518HIGH17 Aug 2026
Typemill < 2.26.0 Authorization Bypass via Media File Download Route
41RISK
open
Exploit-DB
phpSysInfo 3.4.5 - IP Allowlist Bypass
CVE-2026-55584HIGHremotelinux17 Aug 2026
phpSysInfo: IP allowlist (PSI_ALLOWED) bypass via spoofed X-Forwarded-For / Client-IP headers
41RISK
open
Exploit-DB
NanaZip 6.5 - DoS
CVE-2026-55780LOWdoswindows17 Aug 2026
NanaZip: Uncaught exception / unbounded allocation in NanaZip .NET single-file Extract() via unvalidated entry Size
28RISK
open
GitHub PoC
katranSefa/CVE-2026-13714
CVE-2026-13714CRITICAL17 Aug 2026
Realtyna Organic IDX plugin + WPL Real Estate < 5.3.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution
48RISK
open
GitHub PoC
CVE-2026-19650, CVE-2026-19478 - Draft or TODO
CVE-2026-19650HIGH17 Aug 2026
Cross-Site Request Forgery (CSRF) in GitLab
41RISK
open
GitHub PoC
CVE-2026-68138 Linux Local Privilege Escalation Exploit
CVE-2026-68138HIGH17 Aug 2026
net/sched: serialize qdisc_rtab_list against concurrent get/put
41RISK
open
GitHub PoC
POC for CVE-2026-41042
CVE-2026-41042CRITICAL17 Aug 2026
Apache Gravitino: Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java code on the server via H2's INIT parameter
63RISK
open
previouspage 15 / 2,644next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.