Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,460Referência 22,832GitHub PoC 14,991VulnCheck XDB 8,829Nuclei 4,357Metasploit 3,489✓ verified onlyrecentpopularrisk
14,991 exploits
GitHub PoC★ 1
Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RISK
open ↗GitHub PoC
Microsoft SharePoint CVE-2026-50522
Microsoft SharePoint Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC
Isolated regression and security-control lab for CVE-2026-59891 in @sigstore/oci
Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry
48RISK
open ↗GitHub PoC★ 3
CVE-2026-53264 - Draft or Todo
net/sched: act_api: use RCU with deferred freeing for action lifecycle
41RISK
open ↗GitHub PoC
IoT Security research conducted during my internship at IIIT Allahabad, leading to CVE-2026-65893, CVE-2026-65894, and the CERT-In Vulnerability Note CIVN-2026-0380.
Arbitrary Code Execution Vulnerability in CP PLUS EZ-P21 IP Camera
41RISK
open ↗GitHub PoC
0xdak/CVE-2025-71389_exploit
Cal.com before 5.9.9 Remote Code Execution via RSC
48RISK
open ↗GitHub PoC★ 3
Exploit code for CVE-2026-55040, it can create auth header for any validate account.
Microsoft SharePoint Server Security Feature Bypass Vulnerability
100RISK
open ↗GitHub PoC
CyberVinner/CP-PLUS-EZ-P21-CVE-2026-65893-65894
Arbitrary Code Execution Vulnerability in CP PLUS EZ-P21 IP Camera
41RISK
open ↗GitHub PoC
Proof of Concept for CVE-2026-65761 - EasyStore Pro Unauthenticated SQL Injection via `filter_sortby`
Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1
63RISK
open ↗GitHub PoC
bha-vin/CVE-2026-64600-Exploit
xfs: resample the data fork mapping after cycling ILOCK
41RISK
open ↗GitHub PoC
letsr00t/RefluxFS_CVE-2026-64600
xfs: resample the data fork mapping after cycling ILOCK
41RISK
open ↗GitHub PoC★ 1
CVE-2026-8206: Kirki Customizer Framework - Unauthenticated Account Takeover (CVSS 9.8)
Kirki 6.0.0 - 6.0.6 - Unauthenticated Privilege Escalation via 'handle_forgot_password'
48RISK
open ↗GitHub PoC★ 4
Fastjson 1.2.83 RCE 靶场环境 (CVE-2026-16723)
Remote Code Execution in fastjson 1.2.68–1.2.83
53RISK
open ↗GitHub PoC★ 11
A proof-of-concept script to exploit CVE-2026-16232, an authentication bypass via the SmartConsole login process using an application token.
Authentication Bypass in the SmartConsole Login Process Using an Application Token
100RISK
open ↗GitHub PoC
Perl Image::WebP library. Unofficial. CVE-2026-58586
Image::WebP versions before 0.3.0 for Perl bundle a vulnerable version of libwebp
28RISK
open ↗GitHub PoC★ 1
CVE-2026-15013
SAML Single Sign On <= 5.4.3 - Unauthenticated Authentication Bypass via 'SAMLResponse' Parameter Signature Algorithm Confusion
48RISK
open ↗GitHub PoC
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Microsoft SharePoint Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC
CVE-2026-57973 is a medium-severity (CVSS 6.3) TOCTOU race condition flaw in Windows Subsystem for Linux (WSL2). It allows a local, low-privileged attacker to bypass security boundaries and perform unauthorized kernel-level tampering on the host machine without user interaction.
Windows Subsystem for Linux (WSL2) Kernel Tampering Vulnerability
13RISK
open ↗GitHub PoC★ 1
CVE-2026-65008
Grav before 2.0.7 Remote Code Execution via Blueprint dynamicData
48RISK
open ↗GitHub PoC★ 35
nginx heap buffer overflow PoC — CVE-2026-42533 pre-auth RCE via two-pass capture clobbering. Crash confirmed on Ubuntu 24.04.
NGINX Map directive and Regex matching vulnerability
48RISK
open ↗GitHub PoC★ 3
A POC for the recently discovered Qualys bug on COW with XFS
xfs: resample the data fork mapping after cycling ILOCK
41RISK
open ↗GitHub PoC
The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission callback, leaving every route in one of its API namespaces reachable without authentication and allowing unauthenticated attackers to read customer booking data and modify other users' bookings.
BookingPress Pro < 5.7.3 - Unauthenticated Customer PII Disclosure and Booking Tampering via Permission Callback Bug
41RISK
open ↗GitHub PoC★ 10
CVE-2026-54121 (Certighost) AD CS DC-impersonation PoC. Patched SAN handling + MAQ-safe account reuse.
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RISK
open ↗GitHub PoC★ 1
CVE-2026-43499: Linux kernel futex PI use-after-free research package
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open ↗GitHub PoC
A Python-based static patch analysis tool for studying the root cause and remediation of CVE-2021-41773 (Apache HTTP Server Path Traversal) by comparing the vulnerable Apache HTTP Server 2.4.49 source code with the patched 2.4.51 implementation.
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open ↗GitHub PoC★ 1
soralis0912/CVE-2026-43499-pmg110-root
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open ↗GitHub PoC★ 12
Unprivileged user to root on macOS Sonoma, Sequoia, and Tahoe. Patched in macOS 26.6 / 15.7.8 / 14.8.8.
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonom
41RISK
open ↗GitHub PoC
CVE-2026-63030 + CVE-2026-60137+poc
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.