Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,386cataloged exploits
36,533CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,466Referência 23,104GitHub PoC 15,075VulnCheck XDB 8,883Nuclei 4,365Metasploit 3,493✓ verified onlyrecentpopularrisk
79,305 exploits
GitHub PoC
George0Papasotiriou/CVE-2026-9998-Insecure-Deserialization-in-Blockchain-Oracle
Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the rend
41RISK
open ↗GitHub PoC
Unauthenticated arbitrary file read in Flowise (< 2.2.4) via path traversal in getFileFromStorage (storageUtils.ts). Caused by un-sanitized file path combined with mass-assignment in PUT /api/v1/document-store/store/:id. Allows full compromise via /root/.flowise/encryption.key read. Distinct from CVE-2025-71338 (fixed in 2.2.4).
Flowise - Arbitrary File Write to Remote Code Execution via document-store API
48RISK
open ↗GitHub PoC
CVE-2026-12940 — Langflow OSS <=1.10.1 unauthenticated RCE via MCP stdio environment-variable injection (SHELLOPTS/PS4). Author PoC + source analysis + lab.
Langflow is affected by remote code execution due to multiple unauthenticated and insufficiently authorized API endpoints
48RISK
open ↗GitHub PoC★ 1
0xdak/CVE-2026-68771_exploit
ComfyUI 0.23.0 Unauthenticated RCE via LoadTrainingDataset Pickle Deserialization
48RISK
open ↗GitHub PoC
CVE-2026-52887 — NocoBase SQL injection -> PostgreSQL-superuser RCE (myInAppChannels:list filter, CVSS 10.0). Author PoC + source analysis + docker lab.
NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE
48RISK
open ↗VulnCheck XDB
initial-access
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open ↗GitHub PoC
CVE-2026-17583 - Draft
Thermo Fisher Applied Biosystems Genetic Analyzers Missing Support for Integrity Check
41RISK
open ↗GitHub PoC★ 2
CVE-2026-16232 (Check Point SmartConsole authentication bypass) PoC - unauth to admin; for authorized security testing
Authentication Bypass in the SmartConsole Login Process Using an Application Token
100RISK
open ↗GitHub PoC
CVE-2026-60004 — Gitea/Forgejo Diffpatch Git Hook RCE. Bare clone → post-index-change hook injection. CVSS 9.8 | CWE-94 | Gitea < 1.27.1
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
85RISK
open ↗VulnCheck XDB
initial-access
Kestra: Unauthenticated RCE via /configs path-suffix auth-filter bypass
63RISK
open ↗GitHub PoC
SQL injection in PyAthena via DefaultParameterFormatter (CVE-2026-65321)
PyAthena SQL Injection via DefaultParameterFormatter DELETE/CTAS
48RISK
open ↗GitHub PoC
Procjevt/CVE-2026-63030
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open ↗GitHub PoC
George0Papasotiriou/CVE-2026-11102-OAuth2-Implicit-Grant-Fragment-Hijacking
Inappropriate implementation in Isolated Web Apps in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to e
41RISK
open ↗GitHub PoC
wpsqli full SQLi extractor + dumper for CVE-2026-60137
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RISK
open ↗GitHub PoC
Code injection (RCE) in datamodel-code-generator via unvalidated customBasePath (CVE-2026-63720)
datamodel-code-generator Code Injection via Unvalidated customBasePath Schema Field
41RISK
open ↗GitHub PoC
George0Papasotiriou/CVE-2026-11105-Stack-Buffer-Overflow-in-Custom-Base64-Decoder
Insufficient validation of untrusted input in WebUI in Google Chrome prior to 149.0.7827.53 allowed a remote attacker wh
33RISK
open ↗GitHub PoC★ 2
CVE-2026-64531 (OVSwrap) PoC - Linux kernel Open vSwitch LPE; for patch validation and security research
net: openvswitch: reject oversized nested action attrs
41RISK
open ↗GitHub PoC
George0Papasotiriou/CVE-2026-11104-Python-SSTI-via-Jinja2-attr-Filter-Bypass
Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the ren
33RISK
open ↗GitHub PoC
George0Papasotiriou/CVE-2026-11106-DNS-Zone-Transfer-AXFR-Information-Disclosure
Inappropriate implementation in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-or
33RISK
open ↗GitHub PoC★ 1
Bu laboratuvar ortamını sıfırdan kendim oluşturdum. Next.js uygulaması içerisinde giriş, ana sayfa ve admin sayfalarını hazırladım. Middleware ile yetkilendirme mekanizmasını kurduktan sonra Burp Suite kullanarak CVE-2025-29927 zafiyetini kontrollü ortamda gösterdim.
Authorization Bypass in Next.js Middleware
85RISK
open ↗GitHub PoC★ 9
CVE-2026-64531 (OVSwrap) PoC - Linux kernel Open vSwitch LPE; for patch validation and security research
net: openvswitch: reject oversized nested action attrs
41RISK
open ↗GitHub PoC★ 1
Found a 0-Day in Ghidra: Shared Project File Became a Code Execution Vector
Ghidra Swift Demangler Analyzer Arbitrary Code Execution via Project State
41RISK
open ↗GitHub PoC★ 101
Proof-of-concept exploit chain (CVE-2026-47301) for Microsoft Configuration Manager (SCCM), combining a broken access, CAB arbitrary-write path traversal, certificate verification bypass, and DLL hijacking to achieve SYSTEM-level code execution.
Configuration Manager Elevation of Privilege Vulnerability
41RISK
open ↗GitHub PoC
George0Papasotiriou/CVE-2026-9090-Modbus-TCP-Write-to-Read-Only-Coils-via-Function-Code-Spoofing
CVE-2026-9090
48RISK
open ↗VulnCheck XDB
remote-with-credentials
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
85RISK
open ↗VulnCheck XDB
initial-access
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
85RISK
open ↗GitHub PoC★ 2
CVE-2026-66066 (KindaRails2Shell) PoC - Rails Active Storage/libvips arbitrary file read to RCE; for authorized security testing
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
68RISK
open ↗GitHub PoC
Path traversal (Tar Slip) in Cornac via _extract_archive (CVE-2026-43637)
Cornac < 2.6.0 Path Traversal via _extract_archive() in download.py
41RISK
open ↗GitHub PoC
DharmarajPS/pdfjs-cve-2024-4367-poc
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.