Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,460Referência 22,832GitHub PoC 14,991VulnCheck XDB 8,829Nuclei 4,357Metasploit 3,489✓ verified onlyrecentpopularrisk
14,991 exploits
GitHub PoC★ 2
PoC, IOCs, and detection logic for the SharePoint /_trust WS-Federation BinaryFormatter deserialization chain. Lab reconstruction covering unauthenticated RCE, in-process machine key theft, and the artifacts each variant leaves behind. SharePoint 2016, 2019, and Subscription Edition. CVE-2026-50522, CVE-2026-45659, CVE-2026-56164, CVE-2026-58644.
Microsoft SharePoint Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC
Security Advisory: Remote Denial of Service via Reachable Assertion in URL Prefix Handling (rouille)
Rouille 0.1.6 - 3.6.2 Reachable Assertion DoS via remove_prefix percent-encoding
41RISK
open ↗GitHub PoC
SAML Single Sign On <= 5.4.4 - Unauthenticated Authentication Bypass via SAMLResponse Parameter
SAML Single Sign On <= 5.4.4 - Unauthenticated Authentication Bypass via SAMLResponse Parameter
48RISK
open ↗GitHub PoC
Technical analysis and Proof-of-Concept for CVE-2026-60206, a critical Oracle WebLogic Server SAML authentication bypass vulnerability.
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
48RISK
open ↗GitHub PoC★ 40
CVE-2026-50522 PoC
Microsoft SharePoint Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 27
👻 CVE-2026-54121 - Best CertiGhost AD CS Multi-Exploit Framework | Advanced toolkit with rogue DC/LDAP servers, certificate abuse, PKINIT hash extraction. Features: detect safe check, exploit full multi-threaded. 🛡️ CVSS 8.8 High - Use Ethically, Stay Legal. 🔒
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RISK
open ↗GitHub PoC★ 3
Technical analysis, root cause breakdown, and non-destructive detection methodology for CVE-2026-63030.
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open ↗GitHub PoC
CVE-2026-54121 - Draft
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RISK
open ↗GitHub PoC★ 2
CVE-2026-54121
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RISK
open ↗GitHub PoC★ 2
Technical analysis and advisory for CVE-2026-48908: Unauthenticated Arbitrary File Upload to RCE in JoomShaper SP Page Builder.
Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2
68RISK
open ↗GitHub PoC★ 2
7-Zip XZ Decoder Heap Buffer Overflow - Full analysis, root cause, PoC, and RCE exploitation roadmap
7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability
41RISK
open ↗GitHub PoC
Security Advisory for CVE-2026-51565
Cross-site scripting (XSS) vulnerability in Modules/Docs/DocsController.php in Milk admin <=0.9.8 allows remote attacker
33RISK
open ↗GitHub PoC
Manage BitLocker encrypted drives on Windows. Extract recovery keys, check encryption status, and apply security mitigations for CVE-2026-45585.
Windows BitLocker Security Feature Bypass Vulnerability
33RISK
open ↗GitHub PoC★ 5
CVE-2026-43499 per-boot root exploit — core logic (arm64 Android GKI 6.6)
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open ↗GitHub PoC
Auth Bypass in inetutils-telnetd
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open ↗GitHub PoC★ 17
(CVE-2026-43499)内核漏洞利用程序,适用于未解锁 Bootloader 的一加15T.
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open ↗GitHub PoC
CVE-2026-61946: Unauthenticated IDOR in Easy Appointments <= 3.12.27
WordPress Easy Appointments plugin <= 3.12.27 - Insecure Direct Object References (IDOR) vulnerability
33RISK
open ↗GitHub PoC
CVE-2026-54900, CVE-2026-54902 - Draft
Oj: Negative-Size memcpy in Oj::Parser create_id Attribute Handling
33RISK
open ↗GitHub PoC
CVE-2026-12960 - Improper Export of Android Application Components in the ASUS Router app (com.asus.aihome). PoC, exploit APK, video, and vendor report. Fixed in 1.0.0.9.74.
An Improper Export of Android Application Components vulnerability in ASUS Router App allows a third-party application o
33RISK
open ↗GitHub PoC
Security Advisory for CVE-2026-51564
An issue in the redirect parameter in Milk admin <=0.9.8 allows remote attackers to redirect users to arbitrary external
33RISK
open ↗GitHub PoC★ 1
CypherHippie/CVE-2026-66804
Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability
41RISK
open ↗GitHub PoC★ 1
PoC for CVE-2026-65694 — Microweber CMS (<=2.0.20) unauthenticated path traversal → arbitrary file read (.env / secrets)
Microweber CMS 2.0.20 Path Traversal via ServeStaticFileController
56RISK
open ↗GitHub PoC
Manage BitLocker encrypted drives on Windows 10 and 11. Extract recovery keys, check encryption status, and apply security mitigations for CVE-2026-45585.
Windows BitLocker Security Feature Bypass Vulnerability
33RISK
open ↗GitHub PoC
kxom9ks/CVE-2024-27198
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISK
open ↗GitHub PoC
Security Advisory: Infinite Loop DoS in facil.io MIME Parser (Partial Boundary)
facil.io 0.6.0 - 0.7.6 Infinite Loop DoS via Multipart MIME Body Parser
41RISK
open ↗GitHub PoC
Pedit COW – Linux Kernel Local Privilege Escalation (CVE-2026-46331)
net/sched: fix pedit partial COW leading to page cache corruption
41RISK
open ↗GitHub PoC
EasyStore Joomla Pre-Auth SQL Injection via filter_sortby Direction (CVE-2026-65761, CVSS 9.3)
Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1
63RISK
open ↗GitHub PoC★ 33
cve cve-2026-60206 weblogic saml exploit poc vulnerability oracle scanner security
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
48RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.