Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,325cataloged exploits
36,055CVEs with public exploitation
24,695lab-tested
14,316 exploits
GitHub PoC1
PoC for CVE-2026-44848: Portainer missing authorization on Docker plugin endpoints -> host RCE (GHSA-rrmm-9v76-h3p4). Stdlib-only Python.
CVE-2026-44848CRITICAL18 Aug 2026
Portainer: Missing authorization on Docker plugin endpoints allows host RCE
48RISK
open
GitHub PoC1
Windows Defender 0day vulnerability CVE-2026-69414 ShieldBreak
CVE-2026-69414HIGH18 Aug 2026
Microsoft Defender Elevation of Privilege Vulnerability
41RISK
open
GitHub PoC1
CVE-2026-19500 poc
CVE-2026-19500HIGH18 Aug 2026
SureForms contains an uncontrolled resource consumption vulnerability
41RISK
open
GitHub PoC
CVE-2026-19501 poc
CVE-2026-19501HIGH18 Aug 2026
CVE-2026-19501
41RISK
open
GitHub PoC
CVE-2026-59310 PoC
CVE-2026-59310CRITICALunder attack17 Aug 2026
vCenter directory-traversal vulnerability
78RISK
open
GitHub PoC
ZendTo unauthenticated ClamAV CVE-2026-20217 RCE and default-profile root escalation reproduction
CVE-2026-20217HIGH17 Aug 2026
ClamAV PESpin File Format Processing Out-of-Bounds Memory Corruption Vulnerability
41RISK
open
GitHub PoC
iPad 8 iPadOS 26.3 AVE toolchain research (CVE-2026-64747 class)
CVE-2026-64747HIGH17 Aug 2026
A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iO
41RISK
open
GitHub PoC
CVE-2026-62737 ExecutionContext.sys arbitrary kernel-call PoC
CVE-2026-62737HIGH17 Aug 2026
Windows Kernel Elevation of Privilege Vulnerability
41RISK
open
GitHub PoC
Tracking CVE-2026-68138, the Linux kernel net/sched qdisc rate-table use-after-free
CVE-2026-68138HIGH17 Aug 2026
net/sched: serialize qdisc_rtab_list against concurrent get/put
41RISK
open
GitHub PoC9
Kernel root exploit (CVE-2026-43499) for some 5.X devices (mostly Amazon)
CVE-2026-43499HIGH17 Aug 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC
POC for CVE-2026-41042
CVE-2026-41042CRITICAL17 Aug 2026
Apache Gravitino: Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java code on the server via H2's INIT parameter
63RISK
open
GitHub PoC
CVE-2026-68138 Linux Local Privilege Escalation Exploit
CVE-2026-68138HIGH17 Aug 2026
net/sched: serialize qdisc_rtab_list against concurrent get/put
41RISK
open
GitHub PoC5
A poc and write-up for CVE-2026-40345
CVE-2026-40345HIGH17 Aug 2026
deepmerge-ts: Stack exhaustion when merging recursive object graphs
41RISK
open
GitHub PoC
CVE-2026-33017, vuln in langflow.
CVE-2026-33017CRITICALunder attack17 Aug 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISK
open
GitHub PoC
golang.org/x/text v0.33.0 backport of CVE-2026-56852 (GO-2026-5970) for Go 1.24
CVE-2026-56852HIGH17 Aug 2026
Infinite loop on invalid input in golang.org/x/text
41RISK
open
GitHub PoC
katranSefa/CVE-2026-13714
CVE-2026-13714CRITICAL17 Aug 2026
Realtyna Organic IDX plugin + WPL Real Estate < 5.3.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution
48RISK
open
GitHub PoC
CVE-2026-74945 · Uninitialized heap disclosure via a crafted web font (sec-high)
CVE-2026-74945MEDIUM17 Aug 2026
Information disclosure in the Graphics: Text component
33RISK
open
GitHub PoC
CVE-2026-15826, CVE-2026-15748
CVE-2026-15826CRITICAL17 Aug 2026
User Profile Builder <= 3.16.4 - Unauthenticated Authentication Bypass via Type Confusion to Administrator Account Takeover via 'username' Parameter
63RISK
open
GitHub PoC
CVE-2026-74943 · Use after free in Firefox RasterImage (sec-high)
CVE-2026-74943CRITICAL17 Aug 2026
Use-after-free in the Graphics: ImageLib component
48RISK
open
GitHub PoC
Isolated Docker lab, static detection scanner, and PoC validation for React2Shell (CVE-2025-55182).
CVE-2025-55182CRITICALunder attackransomware17 Aug 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
CVE-2026-59310
CVE-2026-59310CRITICALunder attack17 Aug 2026
vCenter directory-traversal vulnerability
78RISK
open
GitHub PoC
Unauthenticated SQL Injection via Attribute Filter in Phoca Cart - CVSS 9.3
CVE-2026-74251CRITICAL17 Aug 2026
Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0-6.1.6
48RISK
open
GitHub PoC
CVE-2026-19650, CVE-2026-19478 - Draft or TODO
CVE-2026-19650HIGH17 Aug 2026
Cross-Site Request Forgery (CSRF) in GitLab
41RISK
open
GitHub PoC
CVE-2026-74970 · Fission site isolation bypass in Firefox WebRender
CVE-2026-74970MEDIUM17 Aug 2026
Site isolation issue in the Graphics component
33RISK
open
GitHub PoC1
CVE-2026-71518 — Typemill <2.26.0 unauthenticated authorization bypass in media file download (path-equivalent URL variants). Advisory + PoC.
CVE-2026-71518HIGH17 Aug 2026
Typemill < 2.26.0 Authorization Bypass via Media File Download Route
41RISK
open
GitHub PoC
Simple script to achieve safe and non-desruptive active detection of CVE-2026-72898 (SQLi in Metabase)
CVE-2026-72898CRITICALunder attack16 Aug 2026
Metabase SQL injection via password reset endpoint
98RISK
open
GitHub PoC
Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator
CVE-2026-18366CRITICAL16 Aug 2026
Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator
48RISK
open
GitHub PoC
PoC for CVE-2026-73519 - WolfStack hardcoded cluster secret leads to unauthenticated RCE (CVSS 9.8)
CVE-2026-73519CRITICAL16 Aug 2026
WolfStack < 25.9.2 Hard-coded Secret Authentication Bypass via X-WolfStack-Secret
48RISK
open
GitHub PoC
PoC for CVE-2026-73847 - emlog AI Assistant CSRF to SQL execution to admin takeover (CVSS 6.8)
CVE-2026-73847MEDIUM16 Aug 2026
Emlog: Missing CSRF protection in AI Assistant execute_tool leads to full database compromise and admin account takeover
33RISK
open
GitHub PoC1
CVE-2026-73678 — MindsDB Minds Platform unauthenticated RCE via scratchpad exec (CVSS 10.0). Verified end-to-end with real LLM
CVE-2026-73678CRITICAL16 Aug 2026
MindsDB Minds Platform v26.1.0 Unauthenticated RCE via scratchpad exec()
48RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.