Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,794cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
14,946 exploits
GitHub PoC
siboy17/CVE-2022-21907-http.sys
CVE-2022-21907CRITICAL03 Aug 2026
HTTP Protocol Stack Remote Code Execution Vulnerability
70RISK
open
GitHub PoC7
CVE-2026-64531 (OVSwrap) PoC - Linux kernel Open vSwitch LPE; for patch validation and security research
CVE-2026-64531HIGH03 Aug 2026
net: openvswitch: reject oversized nested action attrs
41RISK
open
GitHub PoC
George0Papasotiriou/CVE-2026-8080-DKIM-Signature-Verification-Bypass-Header-Canonicalization-Flaw-
CVE-2026-8080MEDIUM03 Aug 2026
MISP core - Stored XSS in MISP template (old engine) element attribute type
33RISK
open
GitHub PoC2
CVE-2026-66066 (KindaRails2Shell) PoC - Rails Active Storage/libvips arbitrary file read to RCE; for authorized security testing
CVE-2026-66066CRITICAL03 Aug 2026
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
68RISK
open
GitHub PoC2
CVE-2026-64531 (OVSwrap) PoC - Linux kernel Open vSwitch LPE; for patch validation and security research
CVE-2026-64531HIGH03 Aug 2026
net: openvswitch: reject oversized nested action attrs
41RISK
open
GitHub PoC
George0Papasotiriou/CVE-2026-6666-XPC-Service-NSKeyedUnarchiver-Deserialization-Attack-macOS-iOS-simulation-
CVE-2026-6666MEDIUM03 Aug 2026
PgBouncer crash in kill_pool_logins_server_error
33RISK
open
GitHub PoC
George0Papasotiriou/CVE-2026-9997-VPN-Split-Tunneling-Bypass-via-DHCP-Option-Injection
CVE-2026-9997HIGH03 Aug 2026
Use after free in Input in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the rende
41RISK
open
GitHub PoC3
Proof-of-Concept exploit for CVE-2026-15409 (SonicWall SMA 1000 RCE) via Erlang distribution over WebSocket. Achieves unauthenticated remote code execution as couchdb user.
CVE-2026-15409CRITICALunder attackransomware03 Aug 2026
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A
100RISK
open
GitHub PoC
0xdak/CVE-2026-69083_exploit
CVE-2026-69083CRITICAL03 Aug 2026
SiYuan before v3.7.3 SQL Injection via fullTextSearchAssetContent
48RISK
open
GitHub PoC
SQL injection in PyAthena via DefaultParameterFormatter (CVE-2026-65321)
CVE-2026-65321CRITICAL03 Aug 2026
PyAthena SQL Injection via DefaultParameterFormatter DELETE/CTAS
48RISK
open
GitHub PoC17
CVE-2026-60004 Pre-Auth RCE Exploit — Gitea <= 1.27.0 diffpatch git hook injection (CVSS 9.8)
CVE-2026-60004CRITICAL03 Aug 2026
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
85RISK
open
GitHub PoC
Path traversal (Tar Slip) in Cornac via _extract_archive (CVE-2026-43637)
CVE-2026-43637HIGH03 Aug 2026
Cornac < 2.6.0 Path Traversal via _extract_archive() in download.py
41RISK
open
GitHub PoC
CVE-2026-60004 — Gitea/Forgejo Diffpatch Git Hook RCE. Bare clone → post-index-change hook injection. CVSS 9.8 | CWE-94 | Gitea < 1.27.1
CVE-2026-60004CRITICAL03 Aug 2026
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
85RISK
open
GitHub PoC
OXDEV-77637 repro fixture: uv workspace whose transitive CVE (starlette 0.25.0 / CVE-2026-48710) is dropped when the lean clone omits workspace-member pyproject.toml. Tag: repro-OXDEV-77637
CVE-2026-48710MEDIUM03 Aug 2026
Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks
48RISK
open
GitHub PoC2
CVE-2026-16232 (Check Point SmartConsole authentication bypass) PoC - unauth to admin; for authorized security testing
CVE-2026-16232CRITICALunder attack03 Aug 2026
Authentication Bypass in the SmartConsole Login Process Using an Application Token
100RISK
open
GitHub PoC1
Bu laboratuvar ortamını sıfırdan kendim oluşturdum. Next.js uygulaması içerisinde giriş, ana sayfa ve admin sayfalarını hazırladım. Middleware ile yetkilendirme mekanizmasını kurduktan sonra Burp Suite kullanarak CVE-2025-29927 zafiyetini kontrollü ortamda gösterdim.
CVE-2025-29927CRITICAL03 Aug 2026
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC
fastjson vulnerability scanner - detect fastjson in JARs and Spring Boot fat-JARs, check exposure to CVE-2026-16723, and verify whether you already run the official patch 1.2.84. Zero-dependency offline CLI. fastjson 漏洞检测与排查工具:一条命令扫描依赖,支持 fat-JAR 与 shaded 依赖,并判定是否已升到官方补丁版本 1.2.84。
CVE-2026-16723CRITICAL03 Aug 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
53RISK
open
GitHub PoC
CVE-2026-52887 — NocoBase SQL injection -> PostgreSQL-superuser RCE (myInAppChannels:list filter, CVSS 10.0). Author PoC + source analysis + docker lab.
CVE-2026-52887CRITICAL03 Aug 2026
NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE
48RISK
open
GitHub PoC11
proof-of-concept scripts for 2 unauthenticated RCEs in Samba (CVE-2026-4408 & CVE-2026-4480) and local privilege escalation in TelnetD (CVE-2026-28372)
CVE-2026-4408CRITICAL03 Aug 2026
Samba: remote code execution in samr
48RISK
open
GitHub PoC3
CVE-2026-63223 PoC — CodeIgniter 4 is_image/mime_in File Upload RCE (CVSS 9.8). Unauthenticated remote code execution via unrestricted file upload bypass using image magic bytes. Fixed in v4.7.4.
CVE-2026-63223CRITICAL03 Aug 2026
CodeIgniter: Uploaded file extension validation bypass in is_image and mime_in rules
48RISK
open
GitHub PoC
Unauthenticated arbitrary file read in Flowise (< 2.2.4) via path traversal in getFileFromStorage (storageUtils.ts). Caused by un-sanitized file path combined with mass-assignment in PUT /api/v1/document-store/store/:id. Allows full compromise via /root/.flowise/encryption.key read. Distinct from CVE-2025-71338 (fixed in 2.2.4).
CVE-2025-71338CRITICAL03 Aug 2026
Flowise - Arbitrary File Write to Remote Code Execution via document-store API
48RISK
open
GitHub PoC
George0Papasotiriou/CVE-2026-11105-Stack-Buffer-Overflow-in-Custom-Base64-Decoder
CVE-2026-11105MEDIUM03 Aug 2026
Insufficient validation of untrusted input in WebUI in Google Chrome prior to 149.0.7827.53 allowed a remote attacker wh
33RISK
open
GitHub PoC
George0Papasotiriou/CVE-2026-9999-Serverless-Event-Injection-to-Code-Overwrite
CVE-2026-9999HIGH03 Aug 2026
Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to execu
41RISK
open
GitHub PoC
wpsqli full SQLi extractor + dumper for CVE-2026-60137
CVE-2026-60137MEDIUMunder attack03 Aug 2026
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RISK
open
GitHub PoC
George0Papasotiriou/CVE-2026-9998-Insecure-Deserialization-in-Blockchain-Oracle
CVE-2026-9998HIGH03 Aug 2026
Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the rend
41RISK
open
GitHub PoC
Procjevt/CVE-2026-63030
CVE-2026-63030CRITICALunder attack03 Aug 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
GitHub PoC2
GhostLock (CVE-2026-43499) kernel exploit port for REDMI K90 Pro Max Taiwan firmware (myron, WPMTWXM) — offsets, build guide, prebuilt binary
CVE-2026-43499HIGH03 Aug 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC1
CY376 Blue Team project — pfSense DMZ, Suricata IDS/IPS, and automated host hardening against CVE-2014-6271
CVE-2014-6271CRITICALunder attack03 Aug 2026
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC
CVE-2026-12940 — Langflow OSS <=1.10.1 unauthenticated RCE via MCP stdio environment-variable injection (SHELLOPTS/PS4). Author PoC + source analysis + lab.
CVE-2026-12940CRITICAL03 Aug 2026
Langflow is affected by remote code execution due to multiple unauthenticated and insufficiently authorized API endpoints
48RISK
open
GitHub PoC
sam00/POC-CVE-2026-54121-Certighost
CVE-2026-54121HIGH03 Aug 2026
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.