Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,386cataloged exploits
36,533CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,466Referência 23,104GitHub PoC 15,075VulnCheck XDB 8,883Nuclei 4,365Metasploit 3,493✓ verified onlyrecentpopularrisk
79,305 exploits
GitHub PoC★ 8
CVE-2026-64638: WordPress Pre-auth XSS → RCE (XSS2Shell) PoC
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.
Via a specially crafted malici
68RISK
open ↗GitHub PoC★ 1
MR-LeonardoGomes/XSS2Shell-CVE-2026-64638
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.
Via a specially crafted malici
68RISK
open ↗GitHub PoC
teamcity teamcity-CVE-2026-63077 exploitation pcap
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent pollin
100RISK
open ↗GitHub PoC★ 1
Zapscape (CVE-2026-64561) KVM/x86 shadow MMU UAF guest-to-host escape PoC mirror — V4bel/@v4bel, MIT; for authorized security testing
KVM: x86: Check for invalid/obsolete root *after* making MMU pages available
41RISK
open ↗GitHub PoC
Dungsocool/CVE-2026-64638
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.
Via a specially crafted malici
68RISK
open ↗GitHub PoC★ 2
CVE-2026-60004 — Gitea Pre-Auth RCE via diffpatch hook injection
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
85RISK
open ↗GitHub PoC
PoC for CVE-2026-18953 — arbitrary file write (CWE-22) in awslabs.aws-transform-mcp-server's get_resource tool via the savePath parameter
Improper limitation of a pathname to a restricted directory in aws-transform-mcp-server
33RISK
open ↗GitHub PoC
mohwahyudi/poc-CVE-2026-64638-
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.
Via a specially crafted malici
68RISK
open ↗VulnCheck XDB
initial-access
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
85RISK
open ↗GitHub PoC
CVE-2026-63077 — Unauthenticated Remote Code Execution in JetBrains TeamCity via agent polling protocol deserialization. CVSS 9.8 CRITICAL. Mass exploitation tool with interactive shell, multi-threading, and real-time result logging.
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent pollin
100RISK
open ↗GitHub PoC★ 1
🛡️ CVE-2026-64638 - WordPress Security Assessment Suite (CVSS 8.9) | WordPress 4.7.0-7.0.2 pentest toolkit. Includes vulnerability assessment & advanced analysis modules. 🐍 Safe Check & Exploit, 2 mode. Advanced Blue&Red Team Best 2026-64638 Toolkit, Authorized use only. Stay Legal <3zd
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.
Via a specially crafted malici
68RISK
open ↗GitHub PoC★ 1
XSS2Shell (CVE-2026-64638) WordPress pre-auth XSS to RCE PoC mirror — WordSec, MIT; for authorized security testing
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.
Via a specially crafted malici
68RISK
open ↗GitHub PoC
Saku0512/CVE-2026-71557-poc
go-git: Malicious reference names may modify files outside the reference storage
33RISK
open ↗GitHub PoC★ 1
CVE-2026-64638 (XSS2shell) POC.
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.
Via a specially crafted malici
68RISK
open ↗GitHub PoC★ 5
WordPress Pre-Auth RCE Exploit + Scanner + WAF Bypass | CVE-2026-63030 + CVE-2026-60137 | Go + Python + Metasploit modules + Docker lab
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open ↗GitHub PoC★ 1
A Linux kernel local privilege escalation affecting the XFS filesystem copy-on-write (CoW) path.
xfs: resample the data fork mapping after cycling ILOCK
41RISK
open ↗GitHub PoC
Linux 内核升级指南 - 修复 CVE-2026-64561
KVM: x86: Check for invalid/obsolete root *after* making MMU pages available
41RISK
open ↗GitHub PoC
Hands-on homelab simulating the Log4Shell (CVE-2021-44228) vulnerability. Deploy Docker containers to build a vulnerable target and attacker machine, execute the exploit, and implement security mitigations. Perfect for learning offensive security and application hardening.
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open ↗GitHub PoC★ 1
PoC for CVE-2026-71554 - h2 duplicate Host header request smuggling primitive (fixed in 4.4.1)
h2: Duplicate Host header could facilitate request smuggling
33RISK
open ↗GitHub PoC
Shams-Ul-Mehmood/CVE-2021-3156-Project
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open ↗GitHub PoC
Reproducer for CVE-2026-64640 — Apache Polaris Iceberg REST register/register-view vends storage credentials and reads an attacker-chosen metadata location before validating allowedLocations (confused-deputy cross-tenant read). Affected ≤ 1.6.0, fixed in 1.7.0.
Apache Polaris: register endpoint reads attacker-controlled storage location before allowed-locations validation
33RISK
open ↗GitHub PoC★ 53
XSS2Shell (CVE-2026-64638) WordPress pre-auth XSS to RCE chain — PoC exploit + defensive audit tool + nuclei template
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.
Via a specially crafted malici
68RISK
open ↗GitHub PoC
Hunt-Benito/one-multiply-too-many-cve-2026-70638-llama-cpp-android-jni-integer-overflow
llama.cpp b1886–b7445 Integer Overflow via new_1batch() in llama-android.cpp
41RISK
open ↗GitHub PoC★ 1
CVE-2026-44613
Apache Zeppelin: Cross-site request forgery in REST and WebSocket request handling
33RISK
open ↗GitHub PoC
PoC funcional de CVE-2026-64638 (XSS2Shell): cadena pre-auth XSS a RCE en WordPress Core. Laboratorio Docker + servidor atacante Python + análisis técnico y mitigación.
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.
Via a specially crafted malici
68RISK
open ↗GitHub PoC
CVE-2026-64638
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.
Via a specially crafted malici
68RISK
open ↗VulnCheck XDB
initial-access
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISK
open ↗VulnCheck XDB
initial-access
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.