Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,386cataloged exploits
36,533CVEs with public exploitation
24,695lab-tested
79,305 exploits
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware17 Aug 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
Exploit-DB
Joomla JCE_2.9.15 - Remote Code Execution
CVE-2026-48907CRITICALunder attackwebappsmultiple17 Aug 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RISK
open
GitHub PoC
Isolated Docker lab, static detection scanner, and PoC validation for React2Shell (CVE-2025-55182).
CVE-2025-55182CRITICALunder attackransomware17 Aug 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
CVE-2026-19650, CVE-2026-19478 - Draft or TODO
CVE-2026-19650HIGH17 Aug 2026
Cross-Site Request Forgery (CSRF) in GitLab
41RISK
open
GitHub PoC
CVE-2026-59310 PoC
CVE-2026-59310CRITICALunder attack17 Aug 2026
vCenter directory-traversal vulnerability
90RISK
open
GitHub PoC
CVE-2026-59310
CVE-2026-59310CRITICALunder attack17 Aug 2026
vCenter directory-traversal vulnerability
90RISK
open
GitHub PoC
CVE-2026-68138 Linux Local Privilege Escalation Exploit
CVE-2026-68138HIGH17 Aug 2026
net/sched: serialize qdisc_rtab_list against concurrent get/put
41RISK
open
Exploit-DB
WooCommerce 1.5.0 - Unauthenticated Arbitrary File Upload
CVE-2026-3891CRITICALwebappsmultiple17 Aug 2026
Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload
68RISK
open
GitHub PoC9
Kernel root exploit (CVE-2026-43499) for some 5.X devices (mostly Amazon)
CVE-2026-43499HIGH17 Aug 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
Exploit-DB
webpack_devserver 5.2.5 - CSRF
CVE-2026-14620MEDIUMwebappsmultiple17 Aug 2026
webpack-dev-server vulnerable to cross-site request forgery via internal developer endpoints
33RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware17 Aug 2026
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC
Unauthenticated SQL Injection via Attribute Filter in Phoca Cart - CVSS 9.3
CVE-2026-74251CRITICAL17 Aug 2026
Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0-6.1.6
48RISK
open
GitHub PoC1
CVE-2026-71518 — Typemill <2.26.0 unauthenticated authorization bypass in media file download (path-equivalent URL variants). Advisory + PoC.
CVE-2026-71518HIGH17 Aug 2026
Typemill < 2.26.0 Authorization Bypass via Media File Download Route
41RISK
open
GitHub PoC
CVE-2026-74970, Fission site isolation bypass in Firefox WebRender
CVE-2026-74970MEDIUM17 Aug 2026
Site isolation issue in the Graphics component
33RISK
open
Exploit-DB
D-Link DNS_340L - OS Command Injection
CVE-2024-10914CRITICALremotehardware17 Aug 2026
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISK
open
GitHub PoC
Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator
CVE-2026-18366CRITICAL16 Aug 2026
Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator
48RISK
open
GitHub PoC1
CVE-2026-73678 — MindsDB Minds Platform unauthenticated RCE via scratchpad exec (CVSS 10.0). Verified end-to-end with real LLM
CVE-2026-73678CRITICAL16 Aug 2026
MindsDB Minds Platform v26.1.0 Unauthenticated RCE via scratchpad exec()
48RISK
open
GitHub PoC
PoC: Shiori JWT CheckToken never re-validates account state (CVE-2026-71206, High 8.2)
CVE-2026-71206HIGH16 Aug 2026
shiori - JWT CheckToken Never Re-Validates Account State, Allowing Stale-Privilege Access After Deletion or Demotion
41RISK
open
GitHub PoC
PoC: changedetection.io unlimited login brute-force, no rate limiting (CVE-2026-71205, Medium 6.5)
CVE-2026-71205MEDIUM16 Aug 2026
changedetection.io - No Rate Limiting on /login Enables Unlimited Password Brute-Force
33RISK
open
GitHub PoC1
Non-destructive detector for CVE-2026-64638 (XSS2Shell) — WordPress pre-auth XSS reflection primitive
CVE-2026-64638HIGH16 Aug 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
68RISK
open
GitHub PoC
Simple script to achieve safe and non-desruptive active detection of CVE-2026-72898 (SQLi in Metabase)
CVE-2026-72898CRITICALunder attack16 Aug 2026
Metabase SQL injection via password reset endpoint
100RISK
open
GitHub PoC
eh-amish/Windows-Defender-Security-Auditor-CVE-2026-50656-
CVE-2026-50656HIGH16 Aug 2026
Microsoft Defender Elevation of Privilege Vulnerability
46RISK
open
GitHub PoC
a-mansilla/CVE-2020-6418
CVE-2020-6418HIGHunder attack16 Aug 2026
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corru
100RISK
open
GitHub PoC
PoC: changedetection.io settings blind-merge mass assignment (CVE-2026-71204, Medium 6.3)
CVE-2026-71204MEDIUM16 Aug 2026
changedetection.io - Omitted Checkbox in /settings Save Silently Disables API Key Enforcement
33RISK
open
GitHub PoC
POC of CVE-2026-51031 for arbitrary local file read
CVE-2026-51031HIGH16 Aug 2026
FlareSolverr before version 3.4.7 contains a server-side request forgery (SSRF) vulnerability in the /v1 API endpoint. T
41RISK
open
GitHub PoC
PoC: changedetection.io unauthenticated OpenAPI schema disclosure (CVE-2026-71203, Medium 5.3)
CVE-2026-71203MEDIUM16 Aug 2026
changedetection.io - Missing Authentication on /api/v1/full-spec Discloses Full OpenAPI Schema
33RISK
open
GitHub PoC3
One-Day POC | GeoServer Unauthenticated SQL injection to complete RCE
CVE-2026-76904CRITICAL16 Aug 2026
GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers
63RISK
open
GitHub PoC
PoC for CVE-2026-73847 - emlog AI Assistant CSRF to SQL execution to admin takeover (CVSS 6.8)
CVE-2026-73847MEDIUM16 Aug 2026
Emlog: Missing CSRF protection in AI Assistant execute_tool leads to full database compromise and admin account takeover
33RISK
open
VulnCheck XDB
initial-access
CVE-2026-18366CRITICAL16 Aug 2026
Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator
48RISK
open
GitHub PoC
Public writeup, PoC, and emulation materials for CVE-2026-8508 affecting Zyxel captive-portal social login.
CVE-2026-8508MEDIUM16 Aug 2026
An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions throug
33RISK
open
previouspage 16 / 2,644next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.