Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,794cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,459Referência 22,721GitHub PoC 14,946VulnCheck XDB 8,829Nuclei 4,350Metasploit 3,489✓ verified onlyrecentpopularrisk
14,946 exploits
GitHub PoC
CVE-2026-33017 Langflow RCE PoC
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISK
open ↗GitHub PoC★ 12
PoCs for Wellbia XIGNCODE3 anti-cheat xhunter driver family - xhunter1.sys v2023.12.7.78 and xhunter2.sys v2026.6.1.192 (CVE-2026-15430, CVE-2026-3609).
CVE-2026-15430
33RISK
open ↗GitHub PoC
Python script to bypass Azure APIM signup when UI is disabled, this is different from the CVE-2025-66390 as it does not require you to setup anything cross tenant.
In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/password Basic Authentication)
48RISK
open ↗GitHub PoC★ 914
CVE-2026-63030 & CVE-2026-60137 RCE chain proof-of-concept
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open ↗GitHub PoC
Non-destructive proof-of-concept and verification harness for CVE-2026-60137, a blind SQL injection in WordPress core (`WP_Query::author__not_in`), reachable via the REST API's `author_exclude` parameter.
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RISK
open ↗GitHub PoC
Offline scanner telling you which of the 2026 Bouncy Castle CVEs actually apply to you - across BC, BC-LTS and BC-FJA (FIPS), which do not share a version scheme. CVE-2026-58062 / CVE-2026-8763 / CVE-2026-59650 / CVE-2026-59638
Stapled OCSP response accepted without binding to the checked certificate
48RISK
open ↗GitHub PoC
CVE-2026-71211 exploit
mlflow - Unvalidated Gateway Secret api_base Enables SSRF via Gateway Proxy Endpoint
41RISK
open ↗GitHub PoC
minwunn/wp2shell-CVE-2026-63030
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open ↗GitHub PoC
CVE-2026-0092- Possible device lock controller bypass due to a missing permission check.
In Package Manager, there is a possible device lock controller bypass due to a missing permission check. This could lead
48RISK
open ↗GitHub PoC★ 1
CVE-2026-42533: pre-auth nginx heap overflow and info leak from PCRE capture clobbering in the map/script engine, chained to RCE.
NGINX Map directive and Regex matching vulnerability
48RISK
open ↗GitHub PoC★ 4
learner330/fastjson-cve-2026-16723
Remote Code Execution in fastjson 1.2.68–1.2.83
53RISK
open ↗GitHub PoC
Dungsocool/CVE-2023-6553
Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
85RISK
open ↗GitHub PoC
lucastran05/CVE-2021-41773
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open ↗GitHub PoC
PoC + analysis for CVE-2026-54917 — SeaweedFS S3 gateway cross-bucket path traversal (CVSS 10.0, <4.30). Read/write any bucket via .. in the object key.
SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access
56RISK
open ↗GitHub PoC
qflksheep/CVE-2026-67689-FineAdmin.Mvc-vulnerability
SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `or
48RISK
open ↗GitHub PoC★ 1
rmhowe425/PoC-CVE-2026-9198
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RISK
open ↗GitHub PoC★ 1
Craft CMS CVE-2025-32432 command runner adapted from Nicolas Bourras and Orange Cyberdefense research
Craft CMS Allows Remote Code Execution
100RISK
open ↗GitHub PoC★ 1
WordPress Core Pre-Auth RCE — Batch Route Confusion + SQL Injection
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open ↗GitHub PoC
ICS-Park Smart Park Management System v2.0
Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via the /system/rol
41RISK
open ↗GitHub PoC
0xdak/CVE-2026-44024_exploit
Fluentd: Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
48RISK
open ↗GitHub PoC
George0Papasotiriou/CVE-2026-21015-PHP-Filter-Chain-Arbitrary-File-Read
Incorrect default permissions in FactoryCamera prior to SMR May-2026 Release 1 allows local attacker to access unique id
33RISK
open ↗GitHub PoC
George0Papasotiriou/CVE-2026-11118-HTTP-2-Rapid-Reset-DDoS
Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code ins
41RISK
open ↗GitHub PoC
George0Papasotiriou/CVE-2026-11109-Bluetooth-Classic-KNOB-Attack-Key-Negotiation-of-Bluetooth-
Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data v
33RISK
open ↗GitHub PoC
George0Papasotiriou/CVE-2026-11114-Node.js-vm-Sandbox-Escape-via-Proxy
Use after free in Device Trust in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker who had compromi
48RISK
open ↗GitHub PoC
George0Papasotiriou/CVE-2026-11116-SNMPv3-Authentication-Bypass-via-Default-EngineID
Use after free in Chromoting in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code
41RISK
open ↗GitHub PoC
George0Papasotiriou/CVE-2026-11117-WPA2-4-Way-Handshake-Reinstallation-KRACK-Sim-
Use after free in Views in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to execute arbitrar
41RISK
open ↗GitHub PoC
George0Papasotiriou/CVE-2026-11115-Database-Connection-String-Injection-via-Env-Variable
Use after free in Updater in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to perform OS-leve
41RISK
open ↗GitHub PoC★ 1
showmeyourhands/CVE-2026-52102-PoC
An OS command injection vulnerability in the openmediavault-md plugin of OpenMediaVault v8.0.4-1 allows attackers to exe
48RISK
open ↗GitHub PoC
0xdak/CVE-2026-52680_exploit
Apache Kyuubi: REST batch multipart upload path traversal allows controlled file write
48RISK
open ↗GitHub PoC
George0Papasotiriou/CVE-2026-11119-Padding-Oracle-Attack-on-CBC-Mode-Encryption
Inappropriate implementation in GPU in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had
48RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.