Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,794cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,459Referência 22,721GitHub PoC 14,946VulnCheck XDB 8,829Nuclei 4,350Metasploit 3,489✓ verified onlyrecentpopularrisk
14,946 exploits
GitHub PoC
0init/CVE-2026-45185
Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing p
48RISK
open ↗GitHub PoC
Reproducible Docker lab for the Apache Tomcat JNDIRealm GSSAPI authentication bypass
Apache Tomcat: Authentication bypass with JNDIRealm and GSSAPI authenticated bind
41RISK
open ↗GitHub PoC★ 5
CVE-2026-64638 — WordPress Pre-Auth Reflected XSS → RCE via DOM Clobbering + Application Password Theft + REST API Plugin Activation. Dual-mode PoC (XSS chain & direct).
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.
Via a specially crafted malici
68RISK
open ↗GitHub PoC
log4j 2025/2026 年 7 条「配置静默失效」CVE 自查:按 CVE×模块 判定 4 个模块,结构化解析 log4j2 配置做 applicability 降噪,并算出该升到哪个版本才一次到位(6 条写 2.25.4,但有一条要 2.25.5,而它 Dependabot 报不出来) CVE-2026-49844 / CVE-2026-34477
Apache Log4j API: Improper serialization of non-finite floating-point values in MapMessage.asJson()
33RISK
open ↗GitHub PoC
Hands-on homelab simulating the Log4Shell (CVE-2021-44228) vulnerability. Deploy Docker containers to build a vulnerable target and attacker machine, execute the exploit, and implement security mitigations. Perfect for learning offensive security and application hardening.
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open ↗GitHub PoC★ 1
woshidashabi1126/CVE-2026-70553-PoC
MaxSite CMS Unauthenticated RCE via Install Endpoint
48RISK
open ↗GitHub PoC★ 1
CVE-2026-0163 Exploit
In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could lead to rem
48RISK
open ↗GitHub PoC
The Joomla extension PhocaCommander is vulnerable to Path Traversal in the file upload action - CVSS 6.1
Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3
33RISK
open ↗GitHub PoC★ 5
👾 CVE-2026-58048 – cPanel Root SQL Execution Toolkit (CVSS 9.4) | Full Red/Blue Team Toolkit suite for unpatched cPanel & WHM 11.x. 2 tools: Safe Checker (audit/reporting), Weaponized (reverse shell, persistence, UDF RCE, deployment, file read/write, database operations, mass scan). w/Python. 🦾 Use Ethically, Stay Legal <3
Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.
48RISK
open ↗GitHub PoC
tfawnies/CVE-2026-64633
A vulnerability allowing remote unauthenticated code execution on the agent host.
48RISK
open ↗GitHub PoC
Notepad++ CVE-2026-52886 — session.xml backupFilePath starts_with() path traversal (GHSA-rqfm-pw34-r7j6)
Notepad++: session.xml backupFilePath starts_with Bypass
33RISK
open ↗GitHub PoC
Shams-Ul-Mehmood/CVE-2018-7600-Drupalgeddon2-RCE
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open ↗GitHub PoC★ 58
Microsoft SharePoint JWT Authentication Bypass (CVE-2026-55040)
Microsoft SharePoint Server Security Feature Bypass Vulnerability
100RISK
open ↗GitHub PoC
Read-only N-able N-central CVE-2026-18556/CVE-2026-18577 post-exploitation IoC hunter for Windows endpoints
Unauthenticated administrative account takeover
83RISK
open ↗GitHub PoC
The Joomla extension PhocaCommander is vulnerable to Path Traversal in the getSource function - CVSS 8.2
Joomla Extension - phoca.cz - Arbitrary File Read in Phoca Commander 1.0.0-6.1.3
41RISK
open ↗GitHub PoC★ 1
Hunt-Benito/e-is-for-exploit-cve-2026-17543-php-pgsql-sql-injection-backslash-breakout
SQL injection in ext-pgsql via E'...' backslash breakout
41RISK
open ↗GitHub PoC★ 4
Proof of concept for CVE-2026-18649, a remote denial of service vulnerability in GStreamer's H.264 RTP depayloader (rtph264depay).
Gst-plugins-good: gst-plugins-good: unbounded memory growth in rtph264depay and rtph265depay rtp depayloaders
41RISK
open ↗GitHub PoC★ 1
Joomla RSFiles 未授权文件上传CVE-2026-57827检测&利用脚本
Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12
63RISK
open ↗GitHub PoC
The Joomla extension PhocaCommander is vulnerable to Path Traversal in delete, copy, move actions - CVSS 6.4
Joomla Extension - phoca.cz - Path traversal vulnerability in Phoca Commander 1.0.0-6.1.3
33RISK
open ↗GitHub PoC
CVE-2022-31626, CVE-2024-2961, CVE-2019-6977, PHP security research
gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch funct
35RISK
open ↗GitHub PoC
hasan8babiker/CVE-2024-6387
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open ↗GitHub PoC★ 2
CVE-2026-56164 is a critical missing-authentication vulnerability affecting on-premises Microsoft SharePoint Server. It allows unauthenticated, remote attackers to elevate privileges over a network.
Microsoft SharePoint Server Elevation of Privilege Vulnerability
68RISK
open ↗GitHub PoC
查出 Spring Boot 内嵌 Tomcat 的真实版本(pom 里没有),并对每条 2026 年 CVE 同时给出 ASF 官方评级与 GitHub 评级、触发条件、以及这条会不会进 Dependabot 告警 CVE-2026-41293
Apache Tomcat: HTTP/2 request headers not validated
48RISK
open ↗GitHub PoC
扫出你实际装的 Apache Shiro 模块与版本,逐条判定官方 26 条 CVE 里哪些真的落在你身上。按「CVE × 模块」判定,零依赖单 jar。 CVE-2026-49268
Apache Shiro: LDAP DN Injection in DefaultLdapRealm
41RISK
open ↗GitHub PoC
CVE-2026-67598 — Emlog Pro: disabled TLS certificate validation in AI assistant (MITM → API-key theft). CWE-295, CVSS 9.1. Reported by @IlhomjonR.
Emlog Pro 2.6.23 TLS Certificate Validation Disabled in ai.php
48RISK
open ↗GitHub PoC★ 1
Security research: Trezor Safe calldata confirmation-binding bypass vulnerability analysis. Educational proof-of-concept for hardware wallet transaction display verification.
Trezor Safe improper security check in on-device display
13RISK
open ↗GitHub PoC
0xdak/CVE-2026-69098_exploit
kotaemon 0.12.0 Unauthenticated Remote Code Execution via Insecure Deserialization
48RISK
open ↗GitHub PoC★ 1
Craft CMS CVE-2025-32432 command runner adapted from Nicolas Bourras and Orange Cyberdefense research
Craft CMS Allows Remote Code Execution
100RISK
open ↗GitHub PoC★ 2
Seraphinite Accelerator <= 2.29.18 - Reflected Cross-Site Scripting PoC
Seraphinite Accelerator <= 2.29.18 - Reflected Cross-Site Scripting
48RISK
open ↗GitHub PoC
CVE-2026-33017 Langflow RCE PoC
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.