Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
14,991 exploits
GitHub PoC
Scan WordPress installations for wp2shell vulnerabilities (CVE-2026-63030 + CVE-2026-60137). Identifies full RCE and SQL injection risks across multiple sites with severity classification and CSV reporting.
CVE-2026-63030CRITICALunder attack22 Jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
GitHub PoC
PoC reproducer for CVE-2026-56139 (Apache Camel camel-undertow Rest DSL): the Rest DSL binding hard-codes muteException=false, so a configured muteException=true is ignored and an uncaught exception's full stack trace is returned to the client (CWE-209). Fixed in 4.14.8/4.18.3/4.21.0.
CVE-2026-56139MEDIUM22 Jul 2026
Apache Camel Undertow: The muteException consumer option defaulted to false, so a processing error returned the full Java stack trace in the HTTP response body, disclosing sensitive internal information to unauthenticated clients
33RISK
open
GitHub PoC1
ThorVG NULL pointer dereference via malformed SVG — AFL++ fuzzing writeup
CVE-2026-45729MEDIUM22 Jul 2026
ThorVG: Null pointer dereference in SVG loader causes crash via 6-byte malformed input
33RISK
open
GitHub PoC17
CVE-2026-43499 PoC Scanner
CVE-2026-43499HIGH22 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC1
CVE-2026-16540 — Simply Schedule Appointments < 1.6.12.6 Unauthenticated Appointment Data Disclosure and Mass Deletion
CVE-2026-16540HIGH22 Jul 2026
Simply Schedule Appointments < 1.6.12.6 - Unauthenticated Appointment Data Disclosure and Mass Deletion via purge Endpoint
41RISK
open
GitHub PoC12
CVE-2026-46331 and CVE-2026-43503
CVE-2026-46331HIGH22 Jul 2026
net/sched: fix pedit partial COW leading to page cache corruption
41RISK
open
GitHub PoC
PoC reproducer for CVE-2026-55993 (Apache Camel camel-atmosphere-websocket): the WebSocket consumer copies connection query parameters onto the Exchange unfiltered, so an injected CamelHttpUri drives a server-side request (SSRF) and leaks resolved property placeholders. Fixed in 4.14.8/4.18.3/4.21.0.
CVE-2026-55993HIGH22 Jul 2026
Apache Camel Atmosphere Websocket: The inbound consumer maps externally-supplied WebSocket query parameters into the Exchange without a HeaderFilterStrategy, allowing injection of Camel control headers - enabling influencing internal behaviour
41RISK
open
GitHub PoC
CVE-2026-58138 - Conductor (3.21.21..<3.30.2) unauthenticated RCE via INLINE GraalVM evaluator
CVE-2026-58138CRITICAL22 Jul 2026
Orkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script Evaluators
63RISK
open
GitHub PoC
This repository documents the process of identifying, analyzing, and gathering Open Source Intelligence (OSINT) on a specific security vulnerability detected during a target network scan.
CVE-2012-1823CRITICALunder attack22 Jul 2026
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RISK
open
GitHub PoC21
CVE-2026-64600
CVE-2026-64600HIGH22 Jul 2026
xfs: resample the data fork mapping after cycling ILOCK
41RISK
open
GitHub PoC
CVE-2026-63030 & CVE-2026-60137 Wp2shell Poc
CVE-2026-63030CRITICALunder attack22 Jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
GitHub PoC
Local web app for conducting a Check Point Trusted Access Review. This scanner is built specifically to look for configuration issues around CVE-2026-16232, CVE-2026-62144 , and CVE-2026-62145. This tool is not created or supported by Check Point and should be used at your own risk.
CVE-2026-16232CRITICALunder attack22 Jul 2026
Authentication Bypass in the SmartConsole Login Process Using an Application Token
100RISK
open
GitHub PoC
full javascript reproduction of CVE-2026-63030 (author_exclude, author__not_in and misalignment between validations and matches)
CVE-2026-63030CRITICALunder attack22 Jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
GitHub PoC1
Vulnerabilidad en NGINX
CVE-2026-42533CRITICAL22 Jul 2026
NGINX Map directive and Regex matching vulnerability
48RISK
open
GitHub PoC1
Scan Windows Domain Controllers for CVE-2026-41089 to detect unauthenticated remote code execution vulnerabilities in the Netlogon service.
CVE-2026-41089CRITICAL22 Jul 2026
Windows Netlogon Remote Code Execution Vulnerability
70RISK
open
GitHub PoC15
Pre-auth RCE PoC for WordPress core — chains CVE-2026-63030 (REST /batch/v1 route-confusion desync) with CVE-2026-60137 (author__not_in SQLi) into an unauthenticated shell. Authorized testing only.
CVE-2026-63030CRITICALunder attack22 Jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
GitHub PoC
CVE-2026-50522
CVE-2026-50522CRITICALunder attack22 Jul 2026
Microsoft SharePoint Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
Full ML-KEM-1024 key recovery from a partial Fujisaki-Okamoto comparison in wolfSSL (CVE-2026-6330 NEON, CVE-2026-10097 AVX2)
CVE-2026-6330MEDIUM22 Jul 2026
ML-KEM ARM64 NEON ciphertext comparison only compares half of the input
33RISK
open
GitHub PoC3
CVE-2026-14266 - XZ Heap Buffer Overflow PoC Generator for 7-Zip
CVE-2026-14266HIGH22 Jul 2026
7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability
41RISK
open
GitHub PoC
PoC reproducer for CVE-2026-55994 (Apache Camel camel-iggy): the consumer copies an Iggy message's user-headers onto the Exchange unfiltered, so an injected CamelHttpUri drives a server-side request (SSRF) and leaks resolved property placeholders. Fixed in 4.18.3/4.21.0.
CVE-2026-55994HIGH22 Jul 2026
Apache Camel Iggy: The inbound consumer maps externally-supplied Iggy message user-headers into the Exchange without a HeaderFilterStrategy, allowing injection of Camel control headers - enabling control over internal behaviour
41RISK
open
GitHub PoC
Mirrored from tegal1337/CVE-2022-0441
CVE-2022-044121 Jul 2026
MasterStudy LMS < 2.7.6 - Unauthenticated Admin Account Creation
60RISK
open
GitHub PoC
Drop-in fix for the unpatched MCP STDIO command-injection flaw (CVE-2026-30623 family)
CVE-2026-30623CRITICAL21 Jul 2026
LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functionality. The application
63RISK
open
GitHub PoC
danielissaq/-PaperCut-CVE-2023-27350-
CVE-2023-27350CRITICALunder attackransomware21 Jul 2026
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISK
open
GitHub PoC
WhatsWrongAndWhy/CVE-2021-3156
CVE-2021-3156HIGHunder attack21 Jul 2026
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC
WhatsWrongAndWhy/CVE-2017-7308
CVE-2017-730821 Jul 2026
The packet_set_ring function in net/packet/af_packet.c in the Linux kernel through 4.10.6 does not properly validate cer
43RISK
open
GitHub PoC
CVE-2026-60137Temporary Emergency Mitigation for CVE-2026-60137 & CVE-2026-63030 (wp2shell)
CVE-2026-60137MEDIUMunder attack21 Jul 2026
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RISK
open
GitHub PoC
CVE-2026-13233 (Drupal OpenAI Provider, SA-CONTRIB-2026-053): response-URL SSRF / local file read. Untrusted upstream, not the prompt. Safe reproducer + detections. Fixed in 1.1.1/1.2.2.
CVE-2026-13233LOW21 Jul 2026
OpenAI Provider - Moderately critical - Server-side Request Forgery - SA-CONTRIB-2026-053
28RISK
open
GitHub PoC27
Technical analysis and Proof-of-Concept (PoC) for CVE-2026-41089, a critical unauthenticated Remote Code Execution (RCE) vulnerability in the Windows Netlogon service affecting Domain Controllers.
CVE-2026-41089CRITICAL21 Jul 2026
Windows Netlogon Remote Code Execution Vulnerability
70RISK
open
GitHub PoC
CVE-2026-13156 Vulnerability Advisory & PoC — Discovered by Huynh Kien Minh (MinhHK).
CVE-2026-13156MEDIUM21 Jul 2026
MailerSend - Official SMTP Integration < 1.0.8 - Settings Deletion and Plugin Deactivation via CSRF
33RISK
open
GitHub PoC6
jaf0rk/CVE-2026-9973-exploit
CVE-2026-9973HIGH21 Jul 2026
Out of bounds write in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code i
41RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.