Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,526cataloged exploits
36,593CVEs with public exploitation
24,695lab-tested
79,305 exploits
GitHub PoC
Reproduction of cve-2024-23897-jenkins_lfi_reproduction
CVE-2024-23897CRITICALunder attackransomware24 Jul 2026
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
GitHub PoC
kxom9ks/CVE-2024-27198-TeamCity
CVE-2024-27198CRITICALunder attackransomware24 Jul 2026
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISK
open
GitHub PoC1
最原始的
CVE-2026-43499HIGH24 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC
is an advanced security research framework designed to model, analyze, and demonstrate Local Privilege Escalation (LPE) mechanics associated with kernel-level race conditions and filesystem structure vulnerabilities (CVE-2026-64600 / RefluXFS)
CVE-2026-64600HIGH24 Jul 2026
xfs: resample the data fork mapping after cycling ILOCK
41RISK
open
GitHub PoC
kxom9ks/CVE-2024-27198
CVE-2024-27198CRITICALunder attackransomware24 Jul 2026
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISK
open
GitHub PoC1
PoC for CVE-2026-65650 - Elgg avatar upload DoS
CVE-2026-65650MEDIUM24 Jul 2026
Elgg before 7.0.0 does not check image dimensions to prevent denial of service via a large avatar upload.
33RISK
open
GitHub PoC
Security Advisory: Camaleon CMS - Authenticated RCE via `select_eval` Custom Field
CVE-2026-66748HIGH24 Jul 2026
Camaleon CMS 2.1.1 - 2.9.1 Authenticated RCE via select_eval Custom Field
41RISK
open
GitHub PoC
Proof of Concept for CVE-2026-9198 - IBM Langflow Unauthenticated RCE via Auto-Login Bypass
CVE-2026-9198CRITICALunder attack24 Jul 2026
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RISK
open
GitHub PoC1
Flowise Windows RCE exploit for CVE-2026-58057. Bypasses environment variable validation via case-sensitive flaw. Uses node_options to inject arbitrary code through MCP stdio. Supports reverse shell, persistence, file upload, credential dumping. For authorized security testing only.
CVE-2026-58057LOW23 Jul 2026
Flowise - Custom MCP Environment Variable Denylist Bypass via Case Sensitivity
28RISK
open
GitHub PoC
CVE-2026-64600 - Draft - Check todo
CVE-2026-64600HIGH23 Jul 2026
xfs: resample the data fork mapping after cycling ILOCK
41RISK
open
GitHub PoC
Initialized & connected PostgreSQL to Metasploit. Reconnoitered 10.1.16.0/24 with Nmap and imported results. Enumerated hosts/services using SYN, SMB & LDAP scanners. Exploited DC10 via ZeroLogon (CVE-2020-1472), dumped AD NTLM hashes with Impacket, performed Pass-the-Hash, then gained a Meterpreter reverse shell.
CVE-2020-1472MEDIUMunder attackransomware23 Jul 2026
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC
Legacy HPE iMC vuln
CVE-2019-539223 Jul 2026
A disclosure of information vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than ve
23RISK
open
GitHub PoC
Security analysis and report of CVE-2024-6387 OpenSSH vulnerability, including vulnerability details, CVSS evaluation, and mitigation recommendations.
CVE-2024-6387HIGH23 Jul 2026
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC
CVE Reproduction: cve-2024-4577-phpcgi_rce_reproduction
CVE-2024-4577CRITICALunder attackransomware23 Jul 2026
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC1
CVE Reproduction: cve-2026-41940-cpanel_authbypass_reproduction
CVE-2026-41940CRITICALunder attackransomware23 Jul 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISK
open
GitHub PoC
CVE Reproduction: cve-2025-2783-chrome_sandbox_escape_reproduction
CVE-2025-2783HIGHunder attack23 Jul 2026
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allow
71RISK
open
GitHub PoC
CVE Reproduction: cve-2025-5777-citrixbleed2_reproduction
CVE-2025-5777CRITICALunder attackransomware23 Jul 2026
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-63030CRITICALunder attack23 Jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
GitHub PoC
Metabase CVE-2026-59827 Vulnerability Scanner
CVE-2026-59827CRITICAL23 Jul 2026
Metabase: Unsafe Deserialization of H2 Query Results
48RISK
open
GitHub PoC
finding by nvth
CVE-2026-59880HIGH23 Jul 2026
Immutable.js: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set
21RISK
open
VulnCheck XDB
info-leak
CVE-2025-5777CRITICALunder attackransomware23 Jul 2026
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware23 Jul 2026
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware23 Jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-33017CRITICALunder attack23 Jul 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-32432CRITICALunder attack23 Jul 2026
Craft CMS Allows Remote Code Execution
100RISK
open
GitHub PoC
GitHub Actions workflow sandbox (CVE-2026-48546 reproduction)
CVE-2026-48546HIGH23 Jul 2026
KanaDojo < 0.1.18 Sandbox Escape RCE via messages.cjs
41RISK
open
GitHub PoC
CVE-2026-41940 & CVE-2026-41948 — cPanel & WHM Auth Bypass
CVE-2026-41940CRITICALunder attackransomware23 Jul 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISK
open
GitHub PoC4
soralis0912/CVE-2026-43499-aristotle
CVE-2026-43499HIGH23 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC5
soralis0912/CVE-2026-43499-aristotle-apk
CVE-2026-43499HIGH23 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC5
CVE-2026-43499 exploit configuration for realme RMX3888 (Android 16) - 20 verified kernel offsets
CVE-2026-43499HIGH23 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
previouspage 42 / 2,644next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.