Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,279cataloged exploits
36,463CVEs with public exploitation
24,695lab-tested
79,279 exploits
GitHub PoC
A scanner for CVE-2026-55040 and CVE-2026-63520, designed to determine whether the server is affected by these two CVEs.
CVE-2026-55040CRITICALunder attack27 Aug 2026
Microsoft SharePoint Server Security Feature Bypass Vulnerability
100RISK
open
VulnCheck XDB
info-leak
CVE-2026-72898CRITICALunder attack27 Aug 2026
Metabase SQL injection via password reset endpoint
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-14750CRITICALunder attack27 Aug 2026
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALunder attack27 Aug 2026
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-18963CRITICAL27 Aug 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open
VulnCheck XDB
initial-access
CVE-2021-27876HIGHunder attackransomware27 Aug 2026
An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires suc
91RISK
open
VulnCheck XDB
info-leak
CVE-2026-21962CRITICALunder attack27 Aug 2026
Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (compo
90RISK
open
VulnCheck XDB
local
CVE-2015-5287HIGHunder attack27 Aug 2026
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain perm
86RISK
open
VulnCheck XDB
initial-access
CVE-2026-19478CRITICAL27 Aug 2026
Improper Control of Generation of Code ('Code Injection') in GitLab
63RISK
open
GitHub PoC
Hunt-Benito/the-token-was-a-row-number-cve-2026-67602-phpipam-rest-api-authentication-bypass
CVE-2026-67602CRITICAL27 Aug 2026
phpIPAM < 1.8.2 Authentication Bypass via REST API Object Cache
48RISK
open
GitHub PoC1
CVE-2026-18431 - Draft or TODO
CVE-2026-18431CRITICAL27 Aug 2026
Avada <= 7.16 and Fusion Builder <= 3.16 - Unauthenticated Remote Code Execution via Arbitrary File Write
48RISK
open
GitHub PoC
For educational purposes
CVE-2026-65351MEDIUM27 Aug 2026
This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 26.6.1 and iPadOS
33RISK
open
GitHub PoC
Hack The Box Nexus machine write-up covering reconnaissance, Gitea credential discovery, Krayin CRM exploitation via CVE-2026-38526, initial access, and privilege escalation through a vulnerable Gitea template synchronization service.
CVE-2026-38526CRITICAL27 Aug 2026
An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x a
48RISK
open
GitHub PoC
CVE-2015-3246
CVE-2015-3246MEDIUMunder attack27 Aug 2026
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly mod
78RISK
open
GitHub PoC
CVE-2015-5287
CVE-2015-5287HIGHunder attack27 Aug 2026
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain perm
86RISK
open
Metasploit600
PaperCut NG/MF Unauthenticated RCE (CVE-2026-81578 + CVE-2026-82078)
CVE-2026-82078CRITICALunder attack27 Aug 2026
PaperCut MF/NG: Unsafe Dynamic Class Loading in Database Connector
93RISK
open
Metasploit600
PaperCut NG/MF Unauthenticated RCE (CVE-2026-81578 + CVE-2026-82078)
CVE-2026-81578HIGHunder attack27 Aug 2026
PaperCut MF/NG: Authentication Bypass
86RISK
open
GitHub PoC
Oracle WebLogic Console unauthenticated auth bypass + RCE exploit (CVE-2020-14882 / CVE-2020-14750)
CVE-2020-14882CRITICALunder attack27 Aug 2026
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-32475CRITICAL26 Aug 2026
WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability
63RISK
open
GitHub PoC
t3bik/CVE-2026-75898
CVE-2026-75898HIGH26 Aug 2026
RAGFlow < 0.26.3 - Server-Side Request Forgery via Agent Invoke Component
41RISK
open
GitHub PoC
Threat model and vulnerability analysis of Contec SolarView Compact (CVE-2022-29303)
CVE-2022-29303CRITICALunder attack26 Aug 2026
SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php.
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-1676326 Aug 2026
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISK
open
GitHub PoC
zenzue/CVE-2026-55040
CVE-2026-55040CRITICALunder attack26 Aug 2026
Microsoft SharePoint Server Security Feature Bypass Vulnerability
100RISK
open
GitHub PoC2
CVE-2026-19632 - TranslatePress One-Day PoC
CVE-2026-19632CRITICAL26 Aug 2026
TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure
48RISK
open
GitHub PoC
PostGIS SQL Injection GeoTools
CVE-2026-76904CRITICAL26 Aug 2026
GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers
63RISK
open
GitHub PoC
Poc CVE-2026-18080
CVE-2026-18080CRITICAL26 Aug 2026
ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce <= 1.17.8 - Unauthenticated Arbitrary File Upload via CRM Email Connect IMAP Attachment
48RISK
open
VulnCheck XDB
initial-access
CVE-2026-63520HIGH26 Aug 2026
Microsoft SharePoint Server Remote Code Execution Vulnerability
41RISK
open
VulnCheck XDB
local
CVE-2016-5195HIGHunder attack26 Aug 2026
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
GitHub PoC
KongQBin/CVE-2016-5195
CVE-2016-5195HIGHunder attack26 Aug 2026
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
VulnCheck XDB
initial-access
CVE-2026-73570HIGHunder attack26 Aug 2026
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp
98RISK
open
previouspage 6 / 2,643next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.