Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,386cataloged exploits
36,533CVEs with public exploitation
24,695lab-tested
79,305 exploits
GitHub PoC19
Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)
CVE-2026-63077CRITICALunder attack07 Aug 2026
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent pollin
100RISK
open
GitHub PoC
Reproducible Docker lab for the Apache Tomcat JNDIRealm GSSAPI authentication bypass
CVE-2026-55957HIGH07 Aug 2026
Apache Tomcat: Authentication bypass with JNDIRealm and GSSAPI authenticated bind
41RISK
open
GitHub PoC1
CVE-2026-11961 — UserRegistration: WordPress User Registration <= 5.2.2 Privilege Escalation. Misconfigured Membership Roles → Unauthenticated Admin Creation → Site Compromise. CVSS 8.1
CVE-2026-11961HIGH07 Aug 2026
User Registration & Membership < 5.2.3 - Unauthenticated Privilege Escalation via Unbound members_data Membership ID
41RISK
open
GitHub PoC1
Guest-to-host KVM/x86 escape exploiting CVE-2026-64561, delivering a full PoC chain and analysis for security researchers.
CVE-2026-64561HIGH07 Aug 2026
KVM: x86: Check for invalid/obsolete root *after* making MMU pages available
41RISK
open
GitHub PoC
jackson-databind 2026 年 11 条安全公告自查:扫源码注解降噪,告诉你真中几条;逐条求交集给出真正到位的版本(2.18.9/2.21.5/3.1.5,不是 advisory 上最常见的 2.21.4) CVE-2026-54515 / CVE-2026-54512
CVE-2026-54515MEDIUM07 Aug 2026
jackson-databind: Case-insensitive deserialization bypasses per-property @JsonIgnoreProperties
33RISK
open
GitHub PoC
log4j 2025/2026 年 7 条「配置静默失效」CVE 自查:按 CVE×模块 判定 4 个模块,结构化解析 log4j2 配置做 applicability 降噪,并算出该升到哪个版本才一次到位(6 条写 2.25.4,但有一条要 2.25.5,而它 Dependabot 报不出来) CVE-2026-49844 / CVE-2026-34477
CVE-2026-49844MEDIUM07 Aug 2026
Apache Log4j API: Improper serialization of non-finite floating-point values in MapMessage.asJson()
33RISK
open
VulnCheck XDB
initial-access
CVE-2026-39987CRITICALunder attack07 Aug 2026
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-1676307 Aug 2026
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISK
open
GitHub PoC3
CVE-2026-64561
CVE-2026-64561HIGH07 Aug 2026
KVM: x86: Check for invalid/obsolete root *after* making MMU pages available
41RISK
open
VulnCheck XDB
initial-access
CVE-2026-63077CRITICALunder attack07 Aug 2026
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent pollin
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-50522CRITICALunder attack07 Aug 2026
Microsoft SharePoint Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
Giangdurian/CVE-2021-3129
CVE-2021-3129CRITICALunder attackransomware07 Aug 2026
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
GitHub PoC
Hands-on homelab simulating the Log4Shell (CVE-2021-44228) vulnerability. Deploy Docker containers to build a vulnerable target and attacker machine, execute the exploit, and implement security mitigations. Perfect for learning offensive security and application hardening.
CVE-2021-44228CRITICALunder attackransomware07 Aug 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC53
XSS2Shell (CVE-2026-64638) WordPress pre-auth XSS to RCE chain — PoC exploit + defensive audit tool + nuclei template
CVE-2026-64638HIGH07 Aug 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
68RISK
open
GitHub PoC
A simple PoC on the Remote Code Execution (RCE) Vulnerability of CraftCMS designated as CVE-2025-32432 written in Go
CVE-2025-32432CRITICALunder attack07 Aug 2026
Craft CMS Allows Remote Code Execution
100RISK
open
GitHub PoC1
PoC for CVE-2026-71554 - h2 duplicate Host header request smuggling primitive (fixed in 4.4.1)
CVE-2026-71554MEDIUM07 Aug 2026
h2: Duplicate Host header could facilitate request smuggling
33RISK
open
GitHub PoC
PoC funcional de CVE-2026-64638 (XSS2Shell): cadena pre-auth XSS a RCE en WordPress Core. Laboratorio Docker + servidor atacante Python + análisis técnico y mitigación.
CVE-2026-64638HIGH07 Aug 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
68RISK
open
GitHub PoC2
CVE-2026-64638
CVE-2026-64638HIGH07 Aug 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
68RISK
open
GitHub PoC
Wormable exploit for CVE-2026-57858
CVE-2026-57858CRITICAL07 Aug 2026
Cal.com Cal.diy 6.2.0 Stored XSS via BookingPageTagManager Analytics Tracking ID
48RISK
open
GitHub PoC6
SCTPhantom (CVE-2026-64564) SCTP ASCONF DEL-IP UAF LPE PoC (Debian 13 6.12.95) — community PoC mirror, MIT; for authorized security testing
CVE-2026-64564CRITICAL07 Aug 2026
sctp: don't free the ASCONF's own transport in DEL-IP processing
48RISK
open
GitHub PoC
Hunt-Benito/go-without-bounds-cve-2026-67822-stack-overflow-in-tenda-w6-s-wifissidset
CVE-2026-67822CRITICAL07 Aug 2026
Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The fu
48RISK
open
GitHub PoC
Exploit KVM/x86 guest-to-host escape CVE-2026-64561 with Zapscape, a proof-of-concept demonstrating hypervisor vulnerability.
CVE-2026-64561HIGH07 Aug 2026
KVM: x86: Check for invalid/obsolete root *after* making MMU pages available
41RISK
open
GitHub PoC
Maintained Python 3 port of the original FUEL CMS CVE-2018-16763 proof-of-concept.
CVE-2018-1676307 Aug 2026
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISK
open
GitHub PoC3
Template Nuclei para detecção não-intrusiva do XSS2Shell, um parser differential pré-autenticado no WordPress Core que permite injeção de elementos DOM na página de login, servindo de base para uma cadeia de XSS → RCE.
CVE-2026-64638HIGH07 Aug 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
68RISK
open
GitHub PoC1
CVE-2026-64638
CVE-2026-64638HIGH07 Aug 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
68RISK
open
GitHub PoC1
ZSecur1ty/XSS2Shell-CVE-2026-64638
CVE-2026-64638HIGH07 Aug 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
68RISK
open
GitHub PoC6
Wordpress Pre-auth XSS to RCE exploit PoC (xss2shell & CVE-2026-64638)
CVE-2026-64638HIGH07 Aug 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
68RISK
open
GitHub PoC7
ghostlock + tcp-zerocopy hybrid CVE-2026-43499 adaptation for samsung kernel
CVE-2026-43499HIGH07 Aug 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC1
CVE-2026-70559
CVE-2026-70559HIGH07 Aug 2026
Dinky Unauthenticated System Configuration and Credential Disclosure via GET /api/sysConfig/getAll
41RISK
open
GitHub PoC2
Generic kernel live patch for the KVM/x86 shadow-MMU use-after-free (Zapscape, CVE-2026-64561)
CVE-2026-64561HIGH07 Aug 2026
KVM: x86: Check for invalid/obsolete root *after* making MMU pages available
41RISK
open
previouspage 25 / 2,644next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.