Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,438cataloged exploits
36,583CVEs with public exploitation
24,695lab-tested
79,305 exploits
VulnCheck XDB
initial-access
CVE-2026-50522CRITICALunder attack28 Jul 2026
Microsoft SharePoint Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
IoT Security research conducted during my internship at IIIT Allahabad, leading to CVE-2026-65893, CVE-2026-65894, and the CERT-In Vulnerability Note CIVN-2026-0380.
CVE-2026-65893HIGH28 Jul 2026
Arbitrary Code Execution Vulnerability in CP PLUS EZ-P21 IP Camera
41RISK
open
VulnCheck XDB
initial-access
CVE-2020-7961CRITICALunder attack28 Jul 2026
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-16232CRITICALunder attack28 Jul 2026
Authentication Bypass in the SmartConsole Login Process Using an Application Token
100RISK
open
GitHub PoC6
Security research on Liferay CE 7.0.3 GA4: pre-auth RCE as root (CVE-2020-7961 class) reproduced end-to-end, plus 16 more findings — 8+ with no known CVE. Agentic loop-hunt: 25 generators, 22 judges, 9 live validators on Docker. Evidence trail + one-go checker included.
CVE-2020-7961CRITICALunder attack28 Jul 2026
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-61511CRITICAL28 Jul 2026
vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php
85RISK
open
GitHub PoC
CVE-2026-61511 - Draft or Todo
CVE-2026-61511CRITICAL28 Jul 2026
vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php
85RISK
open
VulnCheck XDB
initial-access
CVE-2026-9198CRITICALunder attack28 Jul 2026
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RISK
open
GitHub PoC
Simulated a real-world attack (CVE-2011-2523) against a vulnerable host, then cross-checked detection coverage against an existing Wazuh/Suricata/Zeek SOC — uncovering and fixing 5 real monitoring pipeline bugs along the way.
CVE-2011-252328 Jul 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open
GitHub PoC4
KSU installer for supported Samsung Galaxy firmware with CVE-2026-43499
CVE-2026-43499HIGH28 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC
letsr00t/RefluxFS_CVE-2026-64600
CVE-2026-64600HIGH28 Jul 2026
xfs: resample the data fork mapping after cycling ILOCK
41RISK
open
GitHub PoC
Clickbait. The CVE is AI slop.
CVE-2026-5130228 Jul 2026
23RISK
open
GitHub PoC1
IBM Langflow OSS 1.0.0 through 1.10.0 contains a remote code execution [RCE]
CVE-2026-9198CRITICALunder attack28 Jul 2026
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RISK
open
GitHub PoC4
Fastjson 1.2.83 RCE 靶场环境 (CVE-2026-16723)
CVE-2026-16723CRITICAL28 Jul 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
53RISK
open
GitHub PoC11
A proof-of-concept script to exploit CVE-2026-16232, an authentication bypass via the SmartConsole login process using an application token.
CVE-2026-16232CRITICALunder attack28 Jul 2026
Authentication Bypass in the SmartConsole Login Process Using an Application Token
100RISK
open
GitHub PoC
CVE-2026-14856 TastyIgniter v4.3.0
CVE-2026-14856MEDIUM28 Jul 2026
Stored Cross-Site Scripting (XSS) in TastyIgniter Media Manager
33RISK
open
GitHub PoC3
Exploit code for CVE-2026-55040, it can create auth header for any validate account.
CVE-2026-55040CRITICALunder attack28 Jul 2026
Microsoft SharePoint Server Security Feature Bypass Vulnerability
100RISK
open
GitHub PoC1
Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.
CVE-2026-54121HIGH28 Jul 2026
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RISK
open
VulnCheck XDB
local
CVE-2025-21479HIGHunder attack28 Jul 2026
Incorrect Authorization in Graphics
71RISK
open
GitHub PoC
Isolated regression and security-control lab for CVE-2026-59891 in @sigstore/oci
CVE-2026-59891CRITICAL28 Jul 2026
Credential confusion in  @sigstore/oci  can leak registry credentials to an attacker-controlled registry
48RISK
open
GitHub PoC
bha-vin/CVE-2026-64600-Exploit
CVE-2026-64600HIGH28 Jul 2026
xfs: resample the data fork mapping after cycling ILOCK
41RISK
open
GitHub PoC10
KSU installer for supported firmware with CVE-2026-43499
CVE-2026-43499HIGH28 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC
Perl Image::WebP library. Unofficial. CVE-2026-58586
CVE-2026-58586CRITICAL28 Jul 2026
Image::WebP versions before 0.3.0 for Perl bundle a vulnerable version of libwebp
28RISK
open
GitHub PoC3
CVE-2026-53264 - Draft or Todo
CVE-2026-53264HIGH28 Jul 2026
net/sched: act_api: use RCU with deferred freeing for action lifecycle
41RISK
open
VulnCheck XDB
initial-access
CVE-2026-55040CRITICALunder attack28 Jul 2026
Microsoft SharePoint Server Security Feature Bypass Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-28987CRITICALunder attack28 Jul 2026
SolarWinds Web Help Desk Hardcoded Credential Vulnerability
100RISK
open
GitHub PoC
Microsoft SharePoint CVE-2026-50522
CVE-2026-50522CRITICALunder attack28 Jul 2026
Microsoft SharePoint Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-8206CRITICAL28 Jul 2026
Kirki 6.0.0 - 6.0.6 - Unauthenticated Privilege Escalation via 'handle_forgot_password'
48RISK
open
GitHub PoC1
CVE-2026-8206: Kirki Customizer Framework - Unauthenticated Account Takeover (CVSS 9.8)
CVE-2026-8206CRITICAL28 Jul 2026
Kirki 6.0.0 - 6.0.6 - Unauthenticated Privilege Escalation via 'handle_forgot_password'
48RISK
open
GitHub PoC
0xdak/CVE-2025-71389_exploit
CVE-2025-71389CRITICAL28 Jul 2026
Cal.com before 5.9.9 Remote Code Execution via RSC
48RISK
open
previouspage 37 / 2,644next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.