Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,452cataloged exploits
36,587CVEs with public exploitation
24,695lab-tested
79,305 exploits
GitHub PoC
IoT Security research conducted during my internship at IIIT Allahabad, leading to CVE-2026-65893, CVE-2026-65894, and the CERT-In Vulnerability Note CIVN-2026-0380.
CVE-2026-65893HIGH28 Jul 2026
Arbitrary Code Execution Vulnerability in CP PLUS EZ-P21 IP Camera
41RISK
open
GitHub PoC
CVE-2026-63030 + CVE-2026-60137+poc
CVE-2026-63030CRITICALunder attack27 Jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
GitHub PoC
yuimamur/CVE-2024-4367-hands-on
CVE-2024-4367MEDIUM27 Jul 2026
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISK
open
GitHub PoC
yuimamur/CVE-2024-4367-hands-on-01
CVE-2024-4367MEDIUM27 Jul 2026
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISK
open
GitHub PoC1
A poc for a vulnerability in ZTE File Manager (zte.com.cn.filer) which allows to read arbitrary files from other apps as the privileges of this file manager
CVE-2026-40000LOW27 Jul 2026
Path Traversal Vulnerability in ZTE Blade A75 5G
28RISK
open
GitHub PoC1
The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission callback, leaving every route in one of its API namespaces reachable without authentication and allowing unauthenticated attackers to read customer booking data and modify other users' bookings.
CVE-2026-9830HIGH27 Jul 2026
BookingPress Pro < 5.7.3 - Unauthenticated Customer PII Disclosure and Booking Tampering via Permission Callback Bug
41RISK
open
GitHub PoC
PoC and analysis of CVE-2021-41773
CVE-2021-41773HIGHunder attackransomware27 Jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware27 Jul 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
Procjevt/CVE-2026-58138
CVE-2026-58138CRITICAL27 Jul 2026
Orkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script Evaluators
63RISK
open
VulnCheck XDB
initial-access
CVE-2026-60137MEDIUMunder attack27 Jul 2026
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RISK
open
GitHub PoC
Phucc29/CVE-2025-55182
CVE-2025-55182CRITICALunder attackransomware27 Jul 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-63030CRITICALunder attack27 Jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
GitHub PoC12
Unprivileged user to root on macOS Sonoma, Sequoia, and Tahoe. Patched in macOS 26.6 / 15.7.8 / 14.8.8.
CVE-2026-39875HIGH27 Jul 2026
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonom
41RISK
open
GitHub PoC1
CVE-2026-15013
CVE-2026-15013CRITICAL27 Jul 2026
SAML Single Sign On <= 5.4.3 - Unauthenticated Authentication Bypass via 'SAMLResponse' Parameter Signature Algorithm Confusion
48RISK
open
GitHub PoC
jelasin/CVE-2026-42533
CVE-2026-42533CRITICAL27 Jul 2026
NGINX Map directive and Regex matching vulnerability
48RISK
open
GitHub PoC
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
CVE-2026-50522CRITICALunder attack27 Jul 2026
Microsoft SharePoint Remote Code Execution Vulnerability
100RISK
open
GitHub PoC35
nginx heap buffer overflow PoC — CVE-2026-42533 pre-auth RCE via two-pass capture clobbering. Crash confirmed on Ubuntu 24.04.
CVE-2026-42533CRITICAL27 Jul 2026
NGINX Map directive and Regex matching vulnerability
48RISK
open
GitHub PoC
CVE-2026-57973 is a medium-severity (CVSS 6.3) TOCTOU race condition flaw in Windows Subsystem for Linux (WSL2). It allows a local, low-privileged attacker to bypass security boundaries and perform unauthorized kernel-level tampering on the host machine without user interaction.
CVE-2026-57973MEDIUM27 Jul 2026
Windows Subsystem for Linux (WSL2) Kernel Tampering Vulnerability
13RISK
open
VulnCheck XDB
client-side
CVE-2023-52076HIGH27 Jul 2026
Remote Code Execution Vulnerability in Atril's EPUB ebook parsing
41RISK
open
GitHub PoC4
A POC for the recently discovered Qualys bug on COW with XFS
CVE-2026-64600HIGH27 Jul 2026
xfs: resample the data fork mapping after cycling ILOCK
41RISK
open
GitHub PoC2
Read-only WordPress security scanner for HestiaCP servers. Detects wp2shell compromise indicators (CVE-2026-63030 / CVE-2026-60137) across all hosted sites — per-user email reports, core file diff against clean WordPress, PHP/JS/htaccess/image analysis, and optional AI evaluation via Claude API.
CVE-2026-63030CRITICALunder attack27 Jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
GitHub PoC1
CVE-2026-43499: Linux kernel futex PI use-after-free research package
CVE-2026-43499HIGH27 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
VulnCheck XDB
initial-access
CVE-2026-63030CRITICALunder attack27 Jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
VulnCheck XDB
info-leak
CVE-2021-41773HIGHunder attackransomware27 Jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC10
CVE-2026-54121 (Certighost) AD CS DC-impersonation PoC. Patched SAN handling + MAQ-safe account reuse.
CVE-2026-54121HIGH27 Jul 2026
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RISK
open
GitHub PoC1
CVE-2026-65008
CVE-2026-65008CRITICAL27 Jul 2026
Grav before 2.0.7 Remote Code Execution via Blueprint dynamicData
48RISK
open
Metasploit600
JetBrains TeamCity Agent Polling Unauthenticated Remote Code Execution
CVE-2026-63077CRITICALunder attack27 Jul 2026
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent pollin
100RISK
open
GitHub PoC1
soralis0912/CVE-2026-43499-pmg110-root
CVE-2026-43499HIGH27 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC
Dungsocool/CVE-2026-60137_CVE-2026-63030
CVE-2026-60137MEDIUMunder attack27 Jul 2026
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RISK
open
GitHub PoC
A Python-based static patch analysis tool for studying the root cause and remediation of CVE-2021-41773 (Apache HTTP Server Path Traversal) by comparing the vulnerable Apache HTTP Server 2.4.49 source code with the patched 2.4.51 implementation.
CVE-2021-41773HIGHunder attackransomware27 Jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
previouspage 38 / 2,644next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.