Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,386cataloged exploits
36,533CVEs with public exploitation
24,695lab-tested
79,305 exploits
GitHub PoC2
CVE-2026-45746, CVE-2026-45750, CVE-2026-53547 — three critical vulnerabilities in Termix: cross-tenant session hijacking, OS command injection, and account takeover
CVE-2026-45746CRITICAL29 Jul 2026
Termix Vulnerable to Arbitrary Command Execution via Session Hijacking
48RISK
open
GitHub PoC15
CVE-2026-57827 — RSFiles! Joomla Component Unauthenticated File Upload RCE. Split-controller upload bypass. CVSS 9.8 | CWE-434 | com_rsfiles < 1.17.12
CVE-2026-57827CRITICAL29 Jul 2026
Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12
63RISK
open
VulnCheck XDB
info-leak
CVE-2021-41773HIGHunder attackransomware29 Jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
Public technical advisory and reproduction evidence for CVE-2026-52134 affecting GOOSE replay handling in libiec61850 v1.6.
CVE-2026-52134CRITICAL29 Jul 2026
An issue in the parseGoosePayload() function (/goose/goose_receiver.c) of libiec61850 v1.6 allows attackers to bypass au
48RISK
open
GitHub PoC
CVE-2026-2586 — Eclipse GlassFish EL injection to RCE
CVE-2026-2586CRITICAL29 Jul 2026
An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user
48RISK
open
GitHub PoC
Agent skill that audits a Rails codebase for CVE-2026-66066 (KindaRails2Shell) — Active Storage + libvips arbitrary file read / RCE, checking Rails and libvips versions and block-untrusted mitigations
CVE-2026-66066CRITICAL29 Jul 2026
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
68RISK
open
GitHub PoC1
CVE-2026-43499 exploit adapter for MT6985 MediaTek Dimensity 9300 (vivo PD2241)
CVE-2026-43499HIGH29 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC23
PoC for CVE-2026-66066 in Ruby on Rails
CVE-2026-66066CRITICAL29 Jul 2026
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
68RISK
open
GitHub PoC
webshellseo8/CVE-2026-50522-Proof-of-Concept
CVE-2026-50522CRITICALunder attack29 Jul 2026
Microsoft SharePoint Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
Nuclio Dashboard (NOP mode) accepts unauthenticated POST /api/functions. The spec.handler field isn't path-validated, so ../../../../tmp/x.txt:handler escapes the build tempdir via path.Join, letting an attacker write arbitrary content to any path as root. (CVE-2026-52832, ≤1.15.27)
CVE-2026-52832MEDIUM29 Jul 2026
Nuclio: Unauthenticated path traversal in spec.handler allows arbitrary file write in Dashboard container
33RISK
open
GitHub PoC
webshellseo8/CVE-2026-57811-Proof-of-Concept
CVE-2026-57811CRITICAL29 Jul 2026
WordPress Realtyna Organic IDX plugin plugin <= 5.2.0 - Remote Code Execution (RCE) vulnerability
28RISK
open
GitHub PoC5
CVE-2026-61511 – vBulletin Pre-Auth RCE (CVSS 9.8). Vuln 5.x/6.x (unpatched). Multi-exploit via Endpoint Pool, AJAX, PHPFuck WAF bypass. Full toolkit: reverse shell, proxy, persistence, webshell, database operations, firewall control, log management, mass scanning. 2 versions: multi-exploit & safe-check. Python 3.8+ Use Ethically, Stay Legal. 🔒
CVE-2026-61511CRITICAL29 Jul 2026
vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php
85RISK
open
GitHub PoC1
Pravin761/CVE-2026-54107
CVE-2026-54107HIGH29 Jul 2026
Windows Win32k Elevation of Privilege Vulnerability
41RISK
open
GitHub PoC5
CVE-2026-49176 WalletService LPE — standalone PoC + Cobalt Strike BOF (SYSTEM command on interactive session)
CVE-2026-49176HIGH29 Jul 2026
Windows WalletService Elevation of Privilege Vulnerability
41RISK
open
GitHub PoC
webshellseo8/CVE-2026-61511-POC
CVE-2026-61511CRITICAL29 Jul 2026
vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php
85RISK
open
GitHub PoC
vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code
CVE-2026-61511CRITICAL29 Jul 2026
vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php
85RISK
open
GitHub PoC9
CVE-2026-43813: CloudAttestation enforceEnvironment bypass
CVE-2026-43813HIGH29 Jul 2026
A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 26.6 and iPadOS 26.6, macO
41RISK
open
GitHub PoC1
Gitea Docker Image Authentication Bypass
CVE-2026-20896CRITICAL29 Jul 2026
Gitea Docker image trusts spoofable reverse-proxy headers by default
63RISK
open
VulnCheck XDB
initial-access
CVE-2024-36104CRITICAL29 Jul 2026
Apache OFBiz: Path traversal leading to a RCE
85RISK
open
GitHub PoC
Tracking OVSwrap (CVE-2026-64531), the Open vSwitch datapath netlink overflow
CVE-2026-64531HIGH29 Jul 2026
net: openvswitch: reject oversized nested action attrs
41RISK
open
GitHub PoC
manfredgabriel/cve-2021-41773-lab
CVE-2021-41773HIGHunder attackransomware29 Jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-66066CRITICAL29 Jul 2026
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
68RISK
open
GitHub PoC5
CVE-2026-58025 — MediaWiki Deserialization RCE via Log Entry Import. LogEntryBase::extractParams() unserialize() user-controlled log_params. CVSS 9.8 | CWE-502 | MediaWiki < 1.43.9, < 1.44.6, < 1.45.4, < 1.46.0
CVE-2026-58025MEDIUM29 Jul 2026
Remote Code Execution via Unsafe Deserialization in LogItem Import
33RISK
open
GitHub PoC
CamilleGR/CVE-2026-73292
CVE-2026-73292HIGH29 Jul 2026
Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation
41RISK
open
GitHub PoC1
CVE-2026-66066
CVE-2026-66066CRITICAL29 Jul 2026
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
68RISK
open
Metasploit300
Ruby on Rails Active Storage Vips Arbitrary File Read and Remote Code Execution
CVE-2026-66066CRITICAL29 Jul 2026
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
68RISK
open
Metasploit300
Ruby on Rails Active Storage Vips Arbitrary File Read and Remote Code Execution
CVE-2025-24293CRITICAL29 Jul 2026
# Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of pote
63RISK
open
VulnCheck XDB
initial-access
CVE-2026-9198CRITICALunder attack28 Jul 2026
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RISK
open
GitHub PoC
Proof of Concept for CVE-2026-65761 - EasyStore Pro Unauthenticated SQL Injection via `filter_sortby`
CVE-2026-65761CRITICAL28 Jul 2026
Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1
63RISK
open
GitHub PoC6
Security research on Liferay CE 7.0.3 GA4: pre-auth RCE as root (CVE-2020-7961 class) reproduced end-to-end, plus 16 more findings — 8+ with no known CVE. Agentic loop-hunt: 25 generators, 22 judges, 9 live validators on Docker. Evidence trail + one-go checker included.
CVE-2020-7961CRITICALunder attack28 Jul 2026
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RISK
open
previouspage 36 / 2,644next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.