Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,460Referência 22,832GitHub PoC 14,991VulnCheck XDB 8,829Nuclei 4,357Metasploit 3,489✓ verified onlyrecentpopularrisk
14,989 exploits
GitHub PoC
webshellseo8/CVE-2026-50522-Proof-of-Concept
Microsoft SharePoint Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC
webshellseo8/CVE-2026-57811-Proof-of-Concept
WordPress Realtyna Organic IDX plugin plugin <= 5.2.0 - Remote Code Execution (RCE) vulnerability
28RISK
open ↗GitHub PoC★ 4
CVE-2026-60004
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
85RISK
open ↗GitHub PoC
manfredgabriel/cve-2021-41773-lab
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open ↗GitHub PoC★ 5
CVE-2026-58025 — MediaWiki Deserialization RCE via Log Entry Import. LogEntryBase::extractParams() unserialize() user-controlled log_params. CVSS 9.8 | CWE-502 | MediaWiki < 1.43.9, < 1.44.6, < 1.45.4, < 1.46.0
Remote Code Execution via Unsafe Deserialization in LogItem Import
33RISK
open ↗GitHub PoC
Reproducible SOC lab for CVE-2024-4577 detection and response
Argument Injection in PHP-CGI
100RISK
open ↗GitHub PoC
webshellseo8/CVE-2026-61511-POC
vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php
85RISK
open ↗GitHub PoC
Agent skill that audits a Rails codebase for CVE-2026-66066 (KindaRails2Shell) — Active Storage + libvips arbitrary file read / RCE, checking Rails and libvips versions and block-untrusted mitigations
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
68RISK
open ↗GitHub PoC★ 1
CVE-2026-66066
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
68RISK
open ↗GitHub PoC
CVE-2026-2586 — Eclipse GlassFish EL injection to RCE
An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user
48RISK
open ↗GitHub PoC★ 5
CVE-2026-49176 WalletService LPE — standalone PoC + Cobalt Strike BOF (SYSTEM command on interactive session)
Windows WalletService Elevation of Privilege Vulnerability
41RISK
open ↗GitHub PoC
Tracking OVSwrap (CVE-2026-64531), the Open vSwitch datapath netlink overflow
net: openvswitch: reject oversized nested action attrs
41RISK
open ↗GitHub PoC★ 23
PoC for CVE-2026-66066 in Ruby on Rails
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
68RISK
open ↗GitHub PoC
vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code
vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php
85RISK
open ↗GitHub PoC
Public technical advisory and reproduction evidence for CVE-2026-52134 affecting GOOSE replay handling in libiec61850 v1.6.
An issue in the parseGoosePayload() function (/goose/goose_receiver.c) of libiec61850 v1.6 allows attackers to bypass au
48RISK
open ↗GitHub PoC★ 1
Gitea Docker Image Authentication Bypass
Gitea Docker image trusts spoofable reverse-proxy headers by default
63RISK
open ↗GitHub PoC★ 9
CVE-2026-43813: CloudAttestation enforceEnvironment bypass
A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 26.6 and iPadOS 26.6, macO
41RISK
open ↗GitHub PoC★ 2
CVE-2026-45746, CVE-2026-45750, CVE-2026-53547 — three critical vulnerabilities in Termix: cross-tenant session hijacking, OS command injection, and account takeover
Termix Vulnerable to Arbitrary Command Execution via Session Hijacking
48RISK
open ↗GitHub PoC★ 1
Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RISK
open ↗GitHub PoC
Microsoft SharePoint CVE-2026-50522
Microsoft SharePoint Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 3
CVE-2026-53264 - Draft or Todo
net/sched: act_api: use RCU with deferred freeing for action lifecycle
41RISK
open ↗GitHub PoC
0xdak/CVE-2025-71389_exploit
Cal.com before 5.9.9 Remote Code Execution via RSC
48RISK
open ↗GitHub PoC
IoT Security research conducted during my internship at IIIT Allahabad, leading to CVE-2026-65893, CVE-2026-65894, and the CERT-In Vulnerability Note CIVN-2026-0380.
Arbitrary Code Execution Vulnerability in CP PLUS EZ-P21 IP Camera
41RISK
open ↗GitHub PoC
CyberVinner/CP-PLUS-EZ-P21-CVE-2026-65893-65894
Arbitrary Code Execution Vulnerability in CP PLUS EZ-P21 IP Camera
41RISK
open ↗GitHub PoC★ 4
KSU installer for supported Samsung Galaxy firmware with CVE-2026-43499
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open ↗GitHub PoC★ 1
CVE-2026-8206: Kirki Customizer Framework - Unauthenticated Account Takeover (CVSS 9.8)
Kirki 6.0.0 - 6.0.6 - Unauthenticated Privilege Escalation via 'handle_forgot_password'
48RISK
open ↗GitHub PoC★ 10
KSU installer for supported firmware with CVE-2026-43499
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open ↗GitHub PoC★ 3
Exploit code for CVE-2026-55040, it can create auth header for any validate account.
Microsoft SharePoint Server Security Feature Bypass Vulnerability
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.