Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,460Referência 22,832GitHub PoC 14,991VulnCheck XDB 8,829Nuclei 4,357Metasploit 3,489✓ verified onlyrecentpopularrisk
14,991 exploits
GitHub PoC
yuimamur/CVE-2024-4367-hands-on-01
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISK
open ↗GitHub PoC
PoC and analysis of CVE-2021-41773
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open ↗GitHub PoC
yuimamur/CVE-2024-4367-hands-on
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISK
open ↗GitHub PoC
A Python-based static patch analysis tool for studying the root cause and remediation of CVE-2021-41773 (Apache HTTP Server Path Traversal) by comparing the vulnerable Apache HTTP Server 2.4.49 source code with the patched 2.4.51 implementation.
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open ↗GitHub PoC★ 1
CVE-2026-65008
Grav before 2.0.7 Remote Code Execution via Blueprint dynamicData
48RISK
open ↗GitHub PoC
Procjevt/CVE-2026-58138
Orkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script Evaluators
63RISK
open ↗GitHub PoC
CVE-2026-63030 + CVE-2026-60137+poc
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open ↗GitHub PoC★ 2
PoC, IOCs, and detection logic for the SharePoint /_trust WS-Federation BinaryFormatter deserialization chain. Lab reconstruction covering unauthenticated RCE, in-process machine key theft, and the artifacts each variant leaves behind. SharePoint 2016, 2019, and Subscription Edition. CVE-2026-50522, CVE-2026-45659, CVE-2026-56164, CVE-2026-58644.
Microsoft SharePoint Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 4
CVE-2026-43499 research port for Galaxy S24 Ultra SM-S928U1 DZF2 (in progress)
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open ↗GitHub PoC
Security Advisory: Unauthenticated Path Traversal Allows Arbitrary File Read (TinyWeb)
TinyWeb 0.0.8 Path Traversal via URL Path Component
41RISK
open ↗GitHub PoC
Docker-based isolated proof-of-concept lab for analysing CVE-2021-44228 (Log4Shell) for the COMP6441 Security Engineering project.
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open ↗GitHub PoC
SAML Single Sign On <= 5.4.4 - Unauthenticated Authentication Bypass via SAMLResponse Parameter
SAML Single Sign On <= 5.4.4 - Unauthenticated Authentication Bypass via SAMLResponse Parameter
48RISK
open ↗GitHub PoC★ 3
CVE-2026-58480 / CVE-2026-15158 — Unauthenticated RCE in Blocksy Companion Pro < 2.1.47 (300K+ installs). Pre-auth arbitrary file upload via double-extension bypass.
Blocksy Companion Pro < 2.1.47 Unauthenticated File Upload via save_attachments
48RISK
open ↗GitHub PoC★ 6
A C-based Linux security utility for detecting, safely verifying (Proof of Concept), and mitigating CVE-2026-64600 (RefluXFS). It provides kernel vulnerability assessment, XFS reflink detection, a safe race-condition PoC, and layered mitigation using SystemTap and XFS hardening.
xfs: resample the data fork mapping after cycling ILOCK
41RISK
open ↗GitHub PoC★ 1
soralis0912/CVE-2026-43499-warhol-root
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open ↗GitHub PoC
Slidev presentation for Certighost (CVE-2026-54121), with Mermaid diagrams and exported assets.
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RISK
open ↗GitHub PoC
Adding --insecure to skip ssl
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RISK
open ↗GitHub PoC
Security Advisory: Unauthenticated Memory Leak Leads To Memory Exhaustion (TinyWeb)
TinyWeb 0.0.8 Memory Leak DoS via HTTP Request Handling
41RISK
open ↗GitHub PoC
Security Advisory: HTTP Request Smuggling Enables Front-End Access Control Bypass (rouille)
Rouille 0.3.3 - 3.6.2 HTTP Request Smuggling via proxy Header Injection
33RISK
open ↗GitHub PoC
Security Advisory: HTTP Response Splitting via Unvalidated Response Header Values (rouille)
Rouille 0.4.0 - 3.6.2 HTTP Response Splitting via Header Injection
33RISK
open ↗GitHub PoC
Security Advisory: Unauthenticated NULL Pointer Dereference Crashes the Server (TinyWeb)
TinyWeb 0.0.8 Null Pointer Dereference DoS via Malformed HTTP Request
41RISK
open ↗GitHub PoC★ 3
WPForms Pro <= 1.10.1.1 - Unauthenticated Arbitrary File Write via Chunked Upload Init/Finalize Ordering
WPForms Pro <= 1.10.1.1 - Unauthenticated Arbitrary File Write via Chunked Upload Init/Finalize Ordering
41RISK
open ↗GitHub PoC★ 3
Critical authentication bypass exploit for cPanel/WHM CVE-2026-41940. Leverages CRLF injection in cpsrvd daemon to gain root WHM access without credentials. Includes version detection, verbose logging, proxy support, JSON reporting, and post-exploitation account enumeration. For authorized security testing only.
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISK
open ↗GitHub PoC
Security Advisory: HTTP Request Smuggling via Unparsed Transfer-Encoding Values (tiny_http)
tiny-http 0.12.0 HTTP Request Smuggling via Transfer-Encoding Handling
33RISK
open ↗GitHub PoC
Security Advisory: Unchecked Room Lookup Leads to Server Crash (Let's Chat)
Let's Chat 0.4.0 - 0.4.8 Denial of Service via Null Dereference in Room Lookup
41RISK
open ↗GitHub PoC★ 23
基于内核漏洞CVE-2026-43499的本地提权适配,集成嵌入式 KernelSU.CVE-2026-43499+KernelSU越狱模式
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open ↗GitHub PoC
Security Advisory: Remote Denial of Service via Reachable Assertion in URL Prefix Handling (rouille)
Rouille 0.1.6 - 3.6.2 Reachable Assertion DoS via remove_prefix percent-encoding
41RISK
open ↗GitHub PoC
Security Advisory: Insufficient Access Controls Allow for Unauthorized File Downloads (Let's Chat)
Let's Chat 0.3.0 - 0.4.8 Broken Access Control File Disclosure via GET /files route
33RISK
open ↗GitHub PoC
Security Advisory: Insufficient Access Controls Allow for Unauthorized Room Deletion (Let's Chat)
Let's Chat 0.3.0 - 0.4.8 Improper Authorization via DELETE /rooms/:room
33RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.