Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,386cataloged exploits
36,533CVEs with public exploitation
24,695lab-tested
79,305 exploits
GitHub PoC4
Proof of concept for CVE-2026-18649, a remote denial of service vulnerability in GStreamer's H.264 RTP depayloader (rtph264depay).
CVE-2026-18649HIGH06 Aug 2026
Gst-plugins-good: gst-plugins-good: unbounded memory growth in rtph264depay and rtph265depay rtp depayloaders
41RISK
open
GitHub PoC
扫出你实际装的 Apache Shiro 模块与版本,逐条判定官方 26 条 CVE 里哪些真的落在你身上。按「CVE × 模块」判定,零依赖单 jar。 CVE-2026-49268
CVE-2026-49268HIGH06 Aug 2026
Apache Shiro: LDAP DN Injection in DefaultLdapRealm
41RISK
open
GitHub PoC
The Joomla extension PhocaCommander is vulnerable to Path Traversal in the file upload action - CVSS 6.1
CVE-2026-66492MEDIUM06 Aug 2026
Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3
33RISK
open
GitHub PoC2
CVE-2026-56164 is a critical missing-authentication vulnerability affecting on-premises Microsoft SharePoint Server. It allows unauthenticated, remote attackers to elevate privileges over a network.
CVE-2026-56164MEDIUMunder attack06 Aug 2026
Microsoft SharePoint Server Elevation of Privilege Vulnerability
68RISK
open
GitHub PoC
tfawnies/CVE-2026-64633
CVE-2026-64633CRITICAL06 Aug 2026
A vulnerability allowing remote unauthenticated code execution on the agent host.
48RISK
open
GitHub PoC1
woshidashabi1126/CVE-2026-70553-PoC
CVE-2026-70553CRITICAL06 Aug 2026
MaxSite CMS Unauthenticated RCE via Install Endpoint
48RISK
open
GitHub PoC1
Hunt-Benito/e-is-for-exploit-cve-2026-17543-php-pgsql-sql-injection-backslash-breakout
CVE-2026-17543HIGH06 Aug 2026
SQL injection in ext-pgsql via E'...' backslash breakout
41RISK
open
GitHub PoC1
CVE-2026-0163 Exploit
CVE-2026-0163CRITICAL06 Aug 2026
In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could lead to rem
48RISK
open
GitHub PoC1
Security research: Trezor Safe calldata confirmation-binding bypass vulnerability analysis. Educational proof-of-concept for hardware wallet transaction display verification.
CVE-2026-65058MEDIUM06 Aug 2026
Trezor Safe improper security check in on-device display
13RISK
open
VulnCheck XDB
initial-access
CVE-2024-2961HIGH06 Aug 2026
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4
78RISK
open
GitHub PoC5
👾 CVE-2026-58048 – cPanel Root SQL Execution Toolkit (CVSS 9.4) | Full Red/Blue Team Toolkit suite for unpatched cPanel & WHM 11.x. 2 tools: Safe Checker (audit/reporting), Weaponized (reverse shell, persistence, UDF RCE, deployment, file read/write, database operations, mass scan). w/Python. 🦾 Use Ethically, Stay Legal <3
CVE-2026-58048CRITICAL06 Aug 2026
Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.
48RISK
open
GitHub PoC
CVE-2022-31626, CVE-2024-2961, CVE-2019-6977, PHP security research
CVE-2019-697706 Aug 2026
gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch funct
45RISK
open
GitHub PoC58
Microsoft SharePoint JWT Authentication Bypass (CVE-2026-55040)
CVE-2026-55040CRITICALunder attack06 Aug 2026
Microsoft SharePoint Server Security Feature Bypass Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-55040CRITICALunder attack06 Aug 2026
Microsoft SharePoint Server Security Feature Bypass Vulnerability
100RISK
open
GitHub PoC
Read-only N-able N-central CVE-2026-18556/CVE-2026-18577 post-exploitation IoC hunter for Windows endpoints
CVE-2026-18556HIGHunder attack06 Aug 2026
Unauthenticated administrative account takeover
83RISK
open
GitHub PoC
Notepad++ CVE-2026-52886 — session.xml backupFilePath starts_with() path traversal (GHSA-rqfm-pw34-r7j6)
CVE-2026-52886MEDIUM06 Aug 2026
Notepad++: session.xml backupFilePath starts_with Bypass
33RISK
open
GitHub PoC1
Joomla RSFiles 未授权文件上传CVE-2026-57827检测&利用脚本
CVE-2026-57827CRITICAL06 Aug 2026
Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12
63RISK
open
GitHub PoC
查出 Spring Boot 内嵌 Tomcat 的真实版本(pom 里没有),并对每条 2026 年 CVE 同时给出 ASF 官方评级与 GitHub 评级、触发条件、以及这条会不会进 Dependabot 告警 CVE-2026-41293
CVE-2026-41293CRITICAL06 Aug 2026
Apache Tomcat: HTTP/2 request headers not validated
48RISK
open
GitHub PoC
The Joomla extension PhocaCommander is vulnerable to Path Traversal in delete, copy, move actions - CVSS 6.4
CVE-2026-66493MEDIUM06 Aug 2026
Joomla Extension - phoca.cz - Path traversal vulnerability in Phoca Commander 1.0.0-6.1.3
33RISK
open
GitHub PoC
Shams-Ul-Mehmood/CVE-2018-7600-Drupalgeddon2-RCE
CVE-2018-7600CRITICALunder attackransomware06 Aug 2026
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
GitHub PoC
CVE-2026-67598 — Emlog Pro: disabled TLS certificate validation in AI assistant (MITM → API-key theft). CWE-295, CVSS 9.1. Reported by @IlhomjonR.
CVE-2026-67598CRITICAL06 Aug 2026
Emlog Pro 2.6.23 TLS Certificate Validation Disabled in ai.php
48RISK
open
GitHub PoC
The Joomla extension PhocaCommander is vulnerable to Path Traversal in the getSource function - CVSS 8.2
CVE-2026-66491HIGH06 Aug 2026
Joomla Extension - phoca.cz - Arbitrary File Read in Phoca Commander 1.0.0-6.1.3
41RISK
open
GitHub PoC
0xdak/CVE-2026-69098_exploit
CVE-2026-69098CRITICAL06 Aug 2026
kotaemon 0.12.0 Unauthenticated Remote Code Execution via Insecure Deserialization
48RISK
open
GitHub PoC
hasan8babiker/CVE-2024-6387
CVE-2024-6387HIGH06 Aug 2026
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC
lucastran05/CVE-2021-41773
CVE-2021-41773HIGHunder attackransomware05 Aug 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
Python script to bypass Azure APIM signup when UI is disabled, this is different from the CVE-2025-66390 as it does not require you to setup anything cross tenant.
CVE-2025-66390CRITICAL05 Aug 2026
In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/password Basic Authentication)
48RISK
open
GitHub PoC
0xdak/CVE-2026-44024_exploit
CVE-2026-44024CRITICAL05 Aug 2026
Fluentd: Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
48RISK
open
GitHub PoC1
Craft CMS CVE-2025-32432 command runner adapted from Nicolas Bourras and Orange Cyberdefense research
CVE-2025-32432CRITICALunder attack05 Aug 2026
Craft CMS Allows Remote Code Execution
100RISK
open
GitHub PoC
minwunn/wp2shell-CVE-2026-63030
CVE-2026-63030CRITICALunder attack05 Aug 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
GitHub PoC
Dungsocool/CVE-2023-6553
CVE-2023-6553CRITICAL05 Aug 2026
Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
85RISK
open
previouspage 26 / 2,644next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.