Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,386cataloged exploits
36,533CVEs with public exploitation
24,695lab-tested
79,305 exploits
GitHub PoC
0xdak/CVE-2026-59243_exploit
CVE-2026-59243CRITICAL04 Aug 2026
Apache Airflow FAB provider: FAB auth manager: JWT signature verification disabled by default for Azure AD OAuth (`verify_signature` defaults to `False`)
48RISK
open
GitHub PoC
webshellseo8/CVE-2026-12720-Proof-of-Concept
CVE-2026-12720HIGH04 Aug 2026
Kirki < 6.0.13 - Unauthenticated PHP Object Injection
41RISK
open
GitHub PoC
0xdak/CVE-2026-14483_exploit
CVE-2026-14483CRITICAL04 Aug 2026
Realtyna Organic IDX plugin + WPL Real Estate <= 5.2.0 - Unauthenticated Arbitrary File Upload via 'files[file]' Parameter via Public I/O 'set_property' Command
63RISK
open
GitHub PoC
George0Papasotiriou/CVE-2026-11111-TOCTOU-in-File-Permission-Check-Before-Open
CVE-2026-11111HIGH04 Aug 2026
Out of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform an out of bound
41RISK
open
GitHub PoC1
Apache HTTP Server 2.4.x mod_lua Buffer Overflow (CVE-2021-44790) - Advanced exploitation framework with fingerprinting, multi-stage scanning, plugin architecture, professional reporting, screenshot capture, SQLite database, and 95%+ confidence detection. Author: Sudeepa Wanigarathna.
CVE-2021-4479004 Aug 2026
Possible buffer overflow when parsing multipart content in mod_lua of Apache HTTP Server 2.4.51 and earlier
45RISK
open
GitHub PoC
George0Papasotiriou/CVE-2026-11120-Command-Injection-via-Git-URL-in-CI-CD-Pipeline
CVE-2026-11120CRITICAL04 Aug 2026
Insufficient validation of untrusted input in Enterprise Reporting in Google Chrome prior to 149.0.7827.53 allowed a rem
48RISK
open
VulnCheck XDB
initial-access
CVE-2026-63030CRITICALunder attack04 Aug 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
GitHub PoC
George0Papasotiriou/CVE-2026-11115-Database-Connection-String-Injection-via-Env-Variable
CVE-2026-11115HIGH04 Aug 2026
Use after free in Updater in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to perform OS-leve
41RISK
open
GitHub PoC
CVE-2026-13934
CVE-2026-13934CRITICAL04 Aug 2026
Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 150.0.7871.47 allowed a remote a
48RISK
open
GitHub PoC
0xdak/CVE-2025-32463_exploit
CVE-2025-32463CRITICALunder attack04 Aug 2026
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack04 Aug 2026
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
GitHub PoC
🚨 Threat intel & incident response research on SharePoint "ToolShell" RCE zero-day (CVE-2025-53770). 🕵️‍♂️ Covers root-cause deserialization flaws, attack timelines, risk metrics, and defensive EDR validation playbooks. 🛡️
CVE-2025-53770CRITICALunder attackransomware04 Aug 2026
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-63030CRITICALunder attack04 Aug 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-63030CRITICALunder attack04 Aug 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
GitHub PoC
CVE-2026-13934
CVE-2026-13934CRITICAL04 Aug 2026
Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 150.0.7871.47 allowed a remote a
48RISK
open
GitHub PoC
CVE-2026-18577 - Draft
CVE-2026-18577HIGHunder attack04 Aug 2026
Incomplete patch leads to administrative account takeover
98RISK
open
GitHub PoC
Shams-Ul-Mehmood/CVE-2021-41773-Exploit
CVE-2021-41773HIGHunder attackransomware04 Aug 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
George0Papasotiriou/CVE-2026-11109-Bluetooth-Classic-KNOB-Attack-Key-Negotiation-of-Bluetooth-
CVE-2026-11109MEDIUM04 Aug 2026
Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data v
33RISK
open
GitHub PoC
George0Papasotiriou/CVE-2026-11110-AES-GCM-Nonce-Reuse-Leading-to-Key-Recovery
CVE-2026-11110MEDIUM04 Aug 2026
Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data v
33RISK
open
GitHub PoC
George0Papasotiriou/CVE-2026-11119-Padding-Oracle-Attack-on-CBC-Mode-Encryption
CVE-2026-11119CRITICAL04 Aug 2026
Inappropriate implementation in GPU in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had
48RISK
open
GitHub PoC1
Gitea diffpatch RCE (CVE-2026-60004) PoC - repo-write to RCE as Gitea service account
CVE-2026-60004CRITICAL04 Aug 2026
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
85RISK
open
GitHub PoC10
GhostLock (CVE-2026-43499) exploit adapted for Honor AAK-AN00 (MagicOS 10, kernel 6.6.89-android15) 声明,由于 AI 过于弱智 导致大量 token 被消耗 这导致资金严重不足在短时间内将不会更新 下次更新最早两天后
CVE-2026-43499HIGH04 Aug 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC3
CVE-2026-43499 x86 Exploit
CVE-2026-43499HIGH04 Aug 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC
CVE-2026-60004 — Gitea <= 1.27.0 Pre-Auth RCE
CVE-2026-60004CRITICAL04 Aug 2026
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
85RISK
open
GitHub PoC
George0Papasotiriou/CVE-2026-11118-HTTP-2-Rapid-Reset-DDoS
CVE-2026-11118HIGH04 Aug 2026
Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code ins
41RISK
open
GitHub PoC1
showmeyourhands/CVE-2026-52102-PoC
CVE-2026-52102CRITICAL04 Aug 2026
An OS command injection vulnerability in the openmediavault-md plugin of OpenMediaVault v8.0.4-1 allows attackers to exe
48RISK
open
GitHub PoC2
Security research project
CVE-2026-58048CRITICAL04 Aug 2026
Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.
48RISK
open
GitHub PoC
George0Papasotiriou/CVE-2026-11113-SMTP-Header-Injection-in-Contact-Form
CVE-2026-11113CRITICAL04 Aug 2026
Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker wh
48RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware04 Aug 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
George0Papasotiriou/CVE-2026-11112-XXE-via-SVG-Image-Upload
CVE-2026-11112CRITICAL04 Aug 2026
Insufficient validation of untrusted input in Chromoting in Google Chrome on Linux prior to 149.0.7827.53 allowed a remo
48RISK
open
previouspage 28 / 2,644next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.