Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,794cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
14,946 exploits
GitHub PoC
George0Papasotiriou/CVE-2026-11116-SNMPv3-Authentication-Bypass-via-Default-EngineID
CVE-2026-11116HIGH04 Aug 2026
Use after free in Chromoting in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code
41RISK
open
GitHub PoC
George0Papasotiriou/CVE-2026-11114-Node.js-vm-Sandbox-Escape-via-Proxy
CVE-2026-11114CRITICAL04 Aug 2026
Use after free in Device Trust in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker who had compromi
48RISK
open
GitHub PoC3
GhostLock (CVE-2026-43499) kernel exploit for samsung devices with locked bootloader
CVE-2026-43499HIGH04 Aug 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC
CVE-2026-18577 - Draft
CVE-2026-18577HIGHunder attack04 Aug 2026
Incomplete patch leads to administrative account takeover
98RISK
open
GitHub PoC1
showmeyourhands/CVE-2026-52102-PoC
CVE-2026-52102CRITICAL04 Aug 2026
An OS command injection vulnerability in the openmediavault-md plugin of OpenMediaVault v8.0.4-1 allows attackers to exe
48RISK
open
GitHub PoC
CVE-2026-13934
CVE-2026-13934CRITICAL04 Aug 2026
Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 150.0.7871.47 allowed a remote a
48RISK
open
GitHub PoC
0xdak/CVE-2026-67340_exploit
CVE-2026-67340HIGH04 Aug 2026
ArcadeDB before 26.7.2 Remote Code Execution via Trigger Scripts
41RISK
open
GitHub PoC
George0Papasotiriou/CVE-2026-21017-LDAP-Anonymous-Bind-Privilege-Escalation
CVE-2026-21017MEDIUM04 Aug 2026
Improper handling of insufficient privileges in SecTelephonyProvider prior to SMR Jun-2026 Release 1 allows local attack
33RISK
open
GitHub PoC
CVE-2026-13934
CVE-2026-13934CRITICAL04 Aug 2026
Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 150.0.7871.47 allowed a remote a
48RISK
open
GitHub PoC11
proof-of-concept scripts for 2 unauthenticated RCEs in Samba (CVE-2026-4408 & CVE-2026-4480) and local privilege escalation in TelnetD (CVE-2026-28372)
CVE-2026-4408CRITICAL03 Aug 2026
Samba: remote code execution in samr
48RISK
open
GitHub PoC
sam00/POC-CVE-2026-42826-2026-42826-Microsoft-Azure-DevOps-Information-Disclosure-Vulnerability
CVE-2026-42826CRITICAL03 Aug 2026
Azure DevOps Information Disclosure Vulnerability
48RISK
open
GitHub PoC
George0Papasotiriou/CVE-2026-11104-Python-SSTI-via-Jinja2-attr-Filter-Bypass
CVE-2026-11104MEDIUM03 Aug 2026
Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the ren
33RISK
open
GitHub PoC1
CY376 Blue Team project — pfSense DMZ, Suricata IDS/IPS, and automated host hardening against CVE-2014-6271
CVE-2014-6271CRITICALunder attack03 Aug 2026
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC17
CVE-2026-60004 Pre-Auth RCE Exploit — Gitea <= 1.27.0 diffpatch git hook injection (CVSS 9.8)
CVE-2026-60004CRITICAL03 Aug 2026
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
85RISK
open
GitHub PoC
OXDEV-77637 repro fixture: uv workspace whose transitive CVE (starlette 0.25.0 / CVE-2026-48710) is dropped when the lean clone omits workspace-member pyproject.toml. Tag: repro-OXDEV-77637
CVE-2026-48710MEDIUM03 Aug 2026
Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks
48RISK
open
GitHub PoC
Splunk detection writeup for CVE-2026-54121 (CertiGhost): AD CS certificate chase abuse leading to full domain compromise. Lab-validated detection, triage steps, and incident investigation against a live DC.
CVE-2026-54121HIGH03 Aug 2026
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RISK
open
GitHub PoC
Manage BitLocker recovery keys, unlock encrypted drives, and monitor encryption status with this lightweight Windows utility.
CVE-2026-45585MEDIUM03 Aug 2026
Windows BitLocker Security Feature Bypass Vulnerability
33RISK
open
GitHub PoC
George0Papasotiriou/CVE-2026-9998-Insecure-Deserialization-in-Blockchain-Oracle
CVE-2026-9998HIGH03 Aug 2026
Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the rend
41RISK
open
GitHub PoC
fastjson vulnerability scanner - detect fastjson in JARs and Spring Boot fat-JARs, check exposure to CVE-2026-16723, and verify whether you already run the official patch 1.2.84. Zero-dependency offline CLI. fastjson 漏洞检测与排查工具:一条命令扫描依赖,支持 fat-JAR 与 shaded 依赖,并判定是否已升到官方补丁版本 1.2.84。
CVE-2026-16723CRITICAL03 Aug 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
53RISK
open
GitHub PoC
SQL injection in PyAthena via DefaultParameterFormatter (CVE-2026-65321)
CVE-2026-65321CRITICAL03 Aug 2026
PyAthena SQL Injection via DefaultParameterFormatter DELETE/CTAS
48RISK
open
GitHub PoC
George0Papasotiriou/CVE-2026-9999-Serverless-Event-Injection-to-Code-Overwrite
CVE-2026-9999HIGH03 Aug 2026
Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to execu
41RISK
open
GitHub PoC
CVE-2026-60004 — Gitea/Forgejo Diffpatch Git Hook RCE. Bare clone → post-index-change hook injection. CVSS 9.8 | CWE-94 | Gitea < 1.27.1
CVE-2026-60004CRITICAL03 Aug 2026
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
85RISK
open
GitHub PoC2
PoC for CVE-2026-3891 – Unauthenticated File Upload RCE in Pix for WooCommerce ≤ 1.5.0. Automated nonce retrieval, PHP upload, and command execution.
CVE-2026-3891CRITICAL03 Aug 2026
Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload
68RISK
open
GitHub PoC1
Bu laboratuvar ortamını sıfırdan kendim oluşturdum. Next.js uygulaması içerisinde giriş, ana sayfa ve admin sayfalarını hazırladım. Middleware ile yetkilendirme mekanizmasını kurduktan sonra Burp Suite kullanarak CVE-2025-29927 zafiyetini kontrollü ortamda gösterdim.
CVE-2025-29927CRITICAL03 Aug 2026
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC2
CVE-2026-16232 (Check Point SmartConsole authentication bypass) PoC - unauth to admin; for authorized security testing
CVE-2026-16232CRITICALunder attack03 Aug 2026
Authentication Bypass in the SmartConsole Login Process Using an Application Token
100RISK
open
GitHub PoC
George0Papasotiriou/CVE-2026-8080-DKIM-Signature-Verification-Bypass-Header-Canonicalization-Flaw-
CVE-2026-8080MEDIUM03 Aug 2026
MISP core - Stored XSS in MISP template (old engine) element attribute type
33RISK
open
GitHub PoC
siboy17/CVE-2022-21907-http.sys
CVE-2022-21907CRITICAL03 Aug 2026
HTTP Protocol Stack Remote Code Execution Vulnerability
70RISK
open
GitHub PoC2
CVE-2026-16232 (Check Point SmartConsole authentication bypass) PoC - unauth to admin; for authorized security testing
CVE-2026-16232CRITICALunder attack03 Aug 2026
Authentication Bypass in the SmartConsole Login Process Using an Application Token
100RISK
open
GitHub PoC
George0Papasotiriou/CVE-2026-9997-VPN-Split-Tunneling-Bypass-via-DHCP-Option-Injection
CVE-2026-9997HIGH03 Aug 2026
Use after free in Input in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the rende
41RISK
open
GitHub PoC3
Proof-of-Concept exploit for CVE-2026-15409 (SonicWall SMA 1000 RCE) via Erlang distribution over WebSocket. Achieves unauthenticated remote code execution as couchdb user.
CVE-2026-15409CRITICALunder attackransomware03 Aug 2026
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A
100RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.