Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,386cataloged exploits
36,533CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,466Referência 23,104GitHub PoC 15,075VulnCheck XDB 8,883Nuclei 4,365Metasploit 3,493✓ verified onlyrecentpopularrisk
79,305 exploits
GitHub PoC★ 2
A flaw in Gitea Open Source Git Server’s approval‑gate logic allows a pull request that originates from a permanent fork to merge without satisfying the repository’s configured approval gates.
Permanent Fork PR Workflow Approval Gate Bypass
41RISK
open ↗GitHub PoC
CVE-2026-67595 — Embedded malicious JavaScript (spyware) in VaahCMS 2.0.0–2.3.4 official releases. CVSS 8.1. Advisory + detection.
VaahCMS 2.0.0 - 2.3.4 Malicious JavaScript Supply Chain via security-otp.blade.php
48RISK
open ↗GitHub PoC
CVE-2026-8239 is an Insecure Direct Object Reference (IDOR) vulnerability affecting Concrete CMS 9.5.0 and earlier.
Concrete CMS 9.5.0 and below is vulnerable to IDOR in '/ccm/frontend/conversations/get_rating'
33RISK
open ↗GitHub PoC★ 168
YellowKey BitLocker CVE-2026-45585 free open-source utility to extract, backup and view BitLocker recovery keys on Windows 10/11. BitLocker bypass vulnerability tool, remediation and mitigation. Tom's Hardware coverage. Check TPM status, protector types, encryption state. Download YellowKey free, portable, no install needed.
Windows BitLocker Security Feature Bypass Vulnerability
33RISK
open ↗GitHub PoC
Vulnerability research write-ups — CVE-2026-12478 (libsoup), Apple WebKit, Google VRP
Libsoup: incomplete fix for cve-2026-0716: out-of-bounds read in libsoup websocket frame processing (unmasked path)
33RISK
open ↗GitHub PoC
PD2229B的43499(ghostlock)可行性研究
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open ↗GitHub PoC
Read-only-by-default WordPress incident-response scanner for the “wp2shell” attack chain (CVE-2026-60137 / CVE-2026-63030): detects shadow-admin, database and filesystem IOCs, verifies core integrity, and exports evidence. Optional controlled account cleanup; does not remove malware.
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RISK
open ↗GitHub PoC
raihants/cve-2026-10702
JIT miscompilation in the JavaScript Engine: JIT component
33RISK
open ↗GitHub PoC
CVE-2026-8237 is an Insecure Direct Object Reference (IDOR) vulnerability caused by missing authorization checks in Concrete CMS 9.5.0 and earlier.
Concrete CMS 9.5.0 and below is vulnerable to IDOR in the`/ccm/frontend/conversations/message_detail` endpoint
48RISK
open ↗GitHub PoC
Consul Template's writeToFile helper opened an operator-supplied destination directly and followed linked path components, allowing rendered output to escape the intended directory and overwrite a preexisting file.
Consul-template is vulnerable to path redirection in writeToFile through symlink attack
33RISK
open ↗GitHub PoC★ 1
Standalone CVE-2026-43499 port for Galaxy A36 5G SM-A366W A366WVLS3AYG1 with KernelSU late-load
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open ↗GitHub PoC
System Vulnerability Checklist & Network Security Hardening project featuring reconnaissance, vsFTPd backdoor analysis (CVE-2011-2523), and active transport-layer mitigation using IPTables.
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open ↗VulnCheck XDB
denial-of-service
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISK
open ↗GitHub PoC
CVE-2026-14483 POC EXPLOIT BY MADEXPLOITS
Realtyna Organic IDX plugin + WPL Real Estate <= 5.2.0 - Unauthenticated Arbitrary File Upload via 'files[file]' Parameter via Public I/O 'set_property' Command
63RISK
open ↗GitHub PoC
Kestra Unauthenticated RCE Exploit (CVE-2026-53576)
Kestra: Unauthenticated RCE via /configs path-suffix auth-filter bypass
63RISK
open ↗GitHub PoC★ 1
Advanced CVE-2023-44487 HTTP/2 Rapid Reset vulnerability exploitation framework. Features multi-connection concurrent attacks, adaptive rate control, stealth mode with randomized headers, real-time metrics, and risk assessment reporting. For authorized penetration testing only. By Sudeepa Wanigarathna
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISK
open ↗GitHub PoC
RichardKabuto/CVE-2026-52370
A reflected cross-site scripting (XSS) vulnerability in the Forum posting function of O2OA v10 allows attackers to execu
13RISK
open ↗GitHub PoC
Full-lifecycle vulnerability management on a live Log4Shell (CVE-2021-44228) target — scan, manual exploitation, network detection, and remediation verification. Nessus, Suricata, Wireshark, Docker.
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open ↗GitHub PoC
My write-ups from CyberDefenders' Blue Team labs, solved using Wireshark. Covers TeamCity RCE (CVE-2024-27198), XSS session hijacking, and LLMNR/NBT-NS credential poisoning — each with step-by-step packet analysis, screenshots, and a full Wireshark filter/command reference. Personal SOC Analyst Tier 1 learning log.
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISK
open ↗VulnCheck XDB
initial-access
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open ↗GitHub PoC★ 1
MinhHK68/CVE-2026-13158
Everest Toolkit <= 1.2.3 - Admin+ Arbitrary File Upload
41RISK
open ↗GitHub PoC
aj2108/CVE-2026-9833
Tag Groups < 2.2.0 - Reflected XSS via 'tag_groups_task' Parameter
41RISK
open ↗GitHub PoC★ 1
CVE-2026-13152: Custom Fields Account Registration For WooCommerce Unauthenticated Privilege Escalation PoC & Advisory by Huynh Kien Minh (MinhHK).
Custom Fields Account Registration For WooCommerce < 1.4 - Unauthenticated Privilege Escalation
41RISK
open ↗GitHub PoC★ 1
Consul Template validated where a symlink pointed during template evaluation, but its later dependency fetch read the original path. Retargeting the link between those operations turned an in-sandbox file reference into an out-of-sandbox file disclosure.
Consul-template vulnerable to sandbox path bypass in file helper via a symlink attack
33RISK
open ↗GitHub PoC
YellowKey BitLocker CVE-2026-45585 - free open-source utility to extract, backup and view BitLocker recovery keys on Windows 10/11. BitLocker bypass vulnerability tool, remediation and mitigation. Tom's Hardware coverage. Check TPM status, protector types, encryption state. Download YellowKey free, portable, no install needed.
Windows BitLocker Security Feature Bypass Vulnerability
33RISK
open ↗GitHub PoC
MinhHK68/CVE-2026-13157
Theme Demo Import <= 1.1.3 - Admin+ Arbitrary File Upload
41RISK
open ↗GitHub PoC★ 1
Wolf CMS <= 0.8.3.1 - RCE via Arbitrary File Write
Wolf CMS 0.8.3.1 Authenticated RCE via FileManagerController File Upload
41RISK
open ↗GitHub PoC★ 1
PoC & checker for CVE-2026-15964 - unauthenticated password change in the WordPress plugin Single Sign On For TNG <= 2.0.0 (CVSS 9.8)
Single Sign On For TNG <= 2.0.0 - Unauthenticated Privilege Escalation via Unverified Password Change
48RISK
open ↗GitHub PoC★ 7
Root prototype for Galaxy S26 (SM-S942U) that is very much indev
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.