Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,275cataloged exploits
36,462CVEs with public exploitation
24,695lab-tested
79,278 exploits
GitHub PoC1
D-Link DIR-825M formDiskFormat stack overflow + command injection RCE PoC (CVE-2026-82592); for authorized security testing
CVE-2026-82592CRITICAL01 Sep 2026
D-Link DIR-825M Disk Formatting Handler Endpoint formDiskFormat sub_46725C stack-based overflow
48RISK
open
VulnCheck XDB
local
CVE-2021-3493HIGHunder attack01 Sep 2026
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware01 Sep 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-9198CRITICALunder attack31 Aug 2026
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RISK
open
GitHub PoC1
Metasploit modules, Python PoCs and throwaway Docker labs for four platform CVEs: Keycloak (CVE-2026-18963), Apache NiFi (CVE-2026-39816), HashiCorp Vault (CVE-2026-5006), HashiCorp Nomad (CVE-2026-7474).
CVE-2026-18963CRITICAL31 Aug 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open
VulnCheck XDB
initial-access
CVE-2026-60004CRITICAL31 Aug 2026
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
85RISK
open
GitHub PoC
GiveWP <= 4.16.7.1 Unauthenticated PHP Object Injection → RCE
CVE-2026-82222CRITICAL31 Aug 2026
WordPress GiveWP plugin <= 4.16.7.1 - Remote Code Execution (RCE) vulnerability
48RISK
open
GitHub PoC
Reflected XSS via search GET Parameter in Phoca Download
CVE-2026-76569MEDIUM31 Aug 2026
Joomla Extension - phoca.cz - Reflected XSS via the search GET parameter in Phoca Download 5.0.0-6.1.4
33RISK
open
GitHub PoC
Weak-RNG stream-sweep research (CVE-2026-71851 class): PRNG schemes x seeds -> BIP39 -> victim set membership
CVE-2026-71851CRITICAL31 Aug 2026
crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain
48RISK
open
VulnCheck XDB
initial-access
CVE-2026-18963CRITICAL31 Aug 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open
VulnCheck XDB
initial-access
CVE-2026-82222CRITICAL30 Aug 2026
WordPress GiveWP plugin <= 4.16.7.1 - Remote Code Execution (RCE) vulnerability
48RISK
open
GitHub PoC1
Automated PoC for CVE-2026-48611 — phpBB OAuth login_link authentication bypass
CVE-2026-48611CRITICAL30 Aug 2026
Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or
63RISK
open
GitHub PoC15
Authorized Docker lab and clean PoC for validating CVE-2026-82222 RCE in GiveWP 4.16.5.1 and the 4.16.7.2 fix.
CVE-2026-82222CRITICAL30 Aug 2026
WordPress GiveWP plugin <= 4.16.7.1 - Remote Code Execution (RCE) vulnerability
48RISK
open
GitHub PoC
CitrixBleed Exploit Tool - CVE-2025-5777 & CVE-2026-8452. Unauthenticated remote memory read from Citrix NetScaler ADC & Gateway. Steal admin session tokens, extract nsroot hashes, dump secrets, and bypass MFA. Python 3 exploit with full memory parsing.
CVE-2026-8452HIGHunder attack30 Aug 2026
Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service
71RISK
open
VulnCheck XDB
initial-access
CVE-2026-42945CRITICAL30 Aug 2026
NGINX ngx_http_rewrite_module vulnerability
60RISK
open
VulnCheck XDB
initial-access
CVE-2026-82222CRITICAL30 Aug 2026
WordPress GiveWP plugin <= 4.16.7.1 - Remote Code Execution (RCE) vulnerability
48RISK
open
GitHub PoC
PoC CVE-2026-18741
CVE-2026-18741MEDIUM30 Aug 2026
Worksuite SaaS version prior to 6.0.14 Stored XSS via Asset Management Location and Description Fields
33RISK
open
GitHub PoC
🫖 Direct single-target Gitea CVE-2026-60004 RCE validation PoC
CVE-2026-60004CRITICAL30 Aug 2026
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
85RISK
open
GitHub PoC
🫖 Contract-correlated discovery and authorized validation tool for Gitea CVE-2026-60004
CVE-2026-60004CRITICAL30 Aug 2026
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
85RISK
open
GitHub PoC
Safe passive detector for identifying WPMU DEV Dashboard versions affected by CVE-2026-76581.
CVE-2026-76581CRITICAL30 Aug 2026
WPMU DEV Dashboard <= 5.0.1 - Authentication Bypass to Administrator via SSO HMAC Canonicalization Confusion
48RISK
open
GitHub PoC1
CVE-2026-80724 PoC + full write-up — Linux kernel ptp/vmclock read-only mapping becomes writable (VM_MAYWRITE). Discovered, reported & fixed by Abdifatah Suruur (suruurism)
CVE-2026-80724HIGH30 Aug 2026
ptp: vmclock: prevent read-only mappings from becoming writable
41RISK
open
GitHub PoC
joaovicdev/EXPLOIT-CVE-2026-56121
CVE-2026-56121CRITICAL30 Aug 2026
Feast < 0.63.0 Unauthenticated RCE via ApplyFeatureView gRPC Deserialization
48RISK
open
GitHub PoC
CVE-2026-76581
CVE-2026-76581CRITICAL30 Aug 2026
WPMU DEV Dashboard <= 5.0.1 - Authentication Bypass to Administrator via SSO HMAC Canonicalization Confusion
48RISK
open
GitHub PoC
Balboa form Command Injection POC
CVE-2026-67363HIGH30 Aug 2026
Joomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4.3.2
41RISK
open
GitHub PoC1
FastGPT Community Edition NoSQL Injection PoC (CVE-2026-79483)
CVE-2026-79483MEDIUM30 Aug 2026
FastGPT Community Edition 4.10.0 through 4.14.0 are vulnerable to a NoSQL injection in the POST /api/core/chat/getHistor
33RISK
open
GitHub PoC
CVE-2026-45833 ChromaDB
CVE-2026-45833CRITICAL30 Aug 2026
A code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows an authenticated attacke
48RISK
open
VulnCheck XDB
initial-access
CVE-2025-6440CRITICAL30 Aug 2026
WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload
60RISK
open
GitHub PoC2
Offensive Research & Exploit Development. Vulnerability research, PoC development, and offensive tooling for financial infrastructure.
CVE-2026-78903LOW30 Aug 2026
Incomplete cleanup in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromise
28RISK
open
VulnCheck XDB
initial-access
CVE-2026-60004CRITICAL30 Aug 2026
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
85RISK
open
VulnCheck XDB
initial-access
CVE-2026-48611CRITICAL30 Aug 2026
Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or
63RISK
open
previouspage 3 / 2,643next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.