Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
14,991 exploits
GitHub PoC
finding by nvth
CVE-2026-59880HIGH23 Jul 2026
Immutable.js: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set
21RISK
open
GitHub PoC
CVE-2026-64600 - Draft - Check todo
CVE-2026-64600HIGH23 Jul 2026
xfs: resample the data fork mapping after cycling ILOCK
41RISK
open
GitHub PoC
Metabase CVE-2026-59827 Vulnerability Scanner
CVE-2026-59827CRITICAL23 Jul 2026
Metabase: Unsafe Deserialization of H2 Query Results
48RISK
open
GitHub PoC
FernandoCassioDev/CVE-2015-1328
CVE-2015-132823 Jul 2026
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RISK
open
GitHub PoC
GitHub Actions workflow sandbox for CVE-2026-45132 reproduction
CVE-2026-45132CRITICAL23 Jul 2026
CloudPirates Open Source Helm Charts: GitHub Actions workflow leaks PAT and SSH signing key via unsafe credential handling
48RISK
open
GitHub PoC1
Flowise Windows RCE exploit for CVE-2026-58057. Bypasses environment variable validation via case-sensitive flaw. Uses node_options to inject arbitrary code through MCP stdio. Supports reverse shell, persistence, file upload, credential dumping. For authorized security testing only.
CVE-2026-58057LOW23 Jul 2026
Flowise - Custom MCP Environment Variable Denylist Bypass via Case Sensitivity
28RISK
open
GitHub PoC
GitHub Actions workflow sandbox (CVE-2026-48546 reproduction)
CVE-2026-48546HIGH23 Jul 2026
KanaDojo < 0.1.18 Sandbox Escape RCE via messages.cjs
41RISK
open
GitHub PoC5
CVE-2026-43499 exploit configuration for realme RMX3888 (Android 16) - 20 verified kernel offsets
CVE-2026-43499HIGH23 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC
CVE-2026-42533 Nginx
CVE-2026-42533CRITICAL23 Jul 2026
NGINX Map directive and Regex matching vulnerability
48RISK
open
GitHub PoC
Dynamo2k1/CVE-2026-33017
CVE-2026-33017CRITICALunder attack23 Jul 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISK
open
GitHub PoC
Proof-of-concept and offensive security research analyzing CVE-2026-23744 (MCPJam Inspector Unauthenticated RCE, Patched in v1.4.3+).
CVE-2026-23744CRITICAL23 Jul 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISK
open
GitHub PoC
CVE Reproduction: cve-2026-63030_60137-wordpress_rce_reproduction
CVE-2026-63030CRITICALunder attack23 Jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
GitHub PoC
CVE-2026-41940 & CVE-2026-41948 — cPanel & WHM Auth Bypass
CVE-2026-41940CRITICALunder attackransomware23 Jul 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISK
open
GitHub PoC1
0xdak/CVE-2026-56121_exploit
CVE-2026-56121CRITICAL23 Jul 2026
Feast < 0.63.0 Unauthenticated RCE via ApplyFeatureView gRPC Deserialization
48RISK
open
GitHub PoC12
DavidCarliez/CVE-2026-66804-CrossDevice-LPE
CVE-2026-66804HIGH23 Jul 2026
Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability
41RISK
open
GitHub PoC
0xdak/CVE-2026-63766_exploit
CVE-2026-63766CRITICAL23 Jul 2026
GPT-SoVITS 20250606v2pro OS Command Injection via webui.py
48RISK
open
GitHub PoC
CVE Reproduction: cve-2026-0770-langflow_rce_reproduction
CVE-2026-0770CRITICALunder attack23 Jul 2026
Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
CVE Reproduction: cve-2025-55182-react2shell_reproduction
CVE-2025-55182CRITICALunder attackransomware23 Jul 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
ghostpels/CVE-2026-13001
CVE-2026-13001CRITICAL23 Jul 2026
Podlove Podcast Publisher <= 4.5.1 - Unauthenticated Arbitrary File Upload via podlove_image_cache_url Parameter
63RISK
open
GitHub PoC
CVE-2026-66374: Knot Resolver 6.3.0 DNS-over-QUIC heap overflow (RCE)
CVE-2026-66374HIGH23 Jul 2026
Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) rece
41RISK
open
GitHub PoC325
Certighost POC
CVE-2026-54121HIGH23 Jul 2026
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RISK
open
GitHub PoC
Tproot es una máquina de nivel Muy Fácil de DockerLabs centrada en la explotación manual del servicio vsftpd 2.3.4 (CVE-2011-2523).
CVE-2011-252323 Jul 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open
GitHub PoC
CVE Reproduction: cve-2025-2783-chrome_sandbox_escape_reproduction
CVE-2025-2783HIGHunder attack23 Jul 2026
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allow
71RISK
open
GitHub PoC
theeomega/CVE-2025-32432-POC
CVE-2025-32432CRITICALunder attack23 Jul 2026
Craft CMS Allows Remote Code Execution
100RISK
open
GitHub PoC
Security analysis and report of CVE-2024-6387 OpenSSH vulnerability, including vulnerability details, CVSS evaluation, and mitigation recommendations.
CVE-2024-6387HIGH23 Jul 2026
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC1
CVE Reproduction: cve-2026-41940-cpanel_authbypass_reproduction
CVE-2026-41940CRITICALunder attackransomware23 Jul 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISK
open
GitHub PoC
CVE Reproduction: cve-2025-5777-citrixbleed2_reproduction
CVE-2025-5777CRITICALunder attackransomware23 Jul 2026
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISK
open
GitHub PoC
CVE Reproduction: cve-2024-4577-phpcgi_rce_reproduction
CVE-2024-4577CRITICALunder attackransomware23 Jul 2026
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC1
CVE-2021-41773 Apache
CVE-2021-41773HIGHunder attackransomware23 Jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
Legacy HPE iMC vuln
CVE-2019-539223 Jul 2026
A disclosure of information vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than ve
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.