Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,302cataloged exploits
36,463CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,465Referência 23,051GitHub PoC 15,049VulnCheck XDB 8,883Nuclei 4,361Metasploit 3,493✓ verified onlyrecentpopularrisk
79,304 exploits
GitHub PoC★ 2
PoC for CVE-2026-73570 (Zimbra SMTP Command Injection)
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp
98RISK
open ↗VulnCheck XDB
initial-access
SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August
63RISK
open ↗VulnCheck XDB
remote-with-credentials
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
85RISK
open ↗GitHub PoC
CVE-2026-17532 Docker Lab.
Seraphinite Accelerator <= 2.29.18 - Reflected Cross-Site Scripting
48RISK
open ↗GitHub PoC★ 13
This repo is poc of cve-2026-18963. Please use it on legal products (lab, local,...).
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open ↗VulnCheck XDB
initial-access
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0
100RISK
open ↗GitHub PoC★ 1
Use cve-2026-36425 killer edr,360 can killer
An issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier in IOCTL handler 0x2420031. Any local user
33RISK
open ↗VulnCheck XDB
initial-access
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open ↗GitHub PoC★ 2
CVE-2026-56705 - Adminer < 5.4.3 unauthenticated RCE via MSSQL PDO DSN injection (ODBC TraceFile arbitrary file write). PoC, Docker lab and negative test included.
Adminer before 5.4.3 Remote Code Execution via MSSQL PDO DSN Injection
48RISK
open ↗Exploit-DB
CVE-2026-42167 - ProFTPD mod_sql post-authentication SQLi - RCE
mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where th
56RISK
open ↗VulnCheck XDB
initial-access
TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the langtype paramet
23RISK
open ↗GitHub PoC
CVE-2026-68820 — Mass Exploit Framework Edition.
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
71RISK
open ↗GitHub PoC
Nuclei template to discover Keycloak reset-credentials endpoints related to CVE-2026-18963 exposure validation.
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open ↗VulnCheck XDB
initial-access
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open ↗GitHub PoC
Safely detect Veeam Service Provider Console auth bypass CVE-2026-58073
A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent an
48RISK
open ↗VulnCheck XDB
client-side
Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the render
71RISK
open ↗GitHub PoC★ 3
PoC for CVE-2026-32475: Elementor Pro <=4.2.1 unauthenticated file upload to RCE. Stdlib-only Python.
WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability
63RISK
open ↗GitHub PoC
CVE-2021-41773 Apache HTTP Server 2.4.49 Path Traversal to RCE Exploit
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open ↗GitHub PoC★ 2
CVE-2026-15469 — Hard-coded RSA-512 mesh group private key in TP-Link Deco XE75/XE5300/WE10800 (CWE-321). Advisory, analysis & PoC methodology (EN/KO).
Hard-coded Mesh Group Private Key in TP-Link Deco XE75, XE5300, and WE10800
41RISK
open ↗GitHub PoC
CVE-2026-60004 es una vulnerabilidad crítica (CVSS 9.8) en Gitea que permite ejecución remota de código sin autenticación mediante el endpoint `/api/v1/repos/{owner}/{repo}/diffpatch`.
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
85RISK
open ↗GitHub PoC
A fuel CMS exploit based on Python for RCE mentioned in CVE-2018-16763.
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISK
open ↗GitHub PoC
TP-Link Archer BE800 V1 — VPN Key Injection RCE
Command Injection Vulnerability in VPN connection of Archer BE800
41RISK
open ↗GitHub PoC★ 1
Firefox content->parent srcdoc forge (N-day, bug 2040160): forged PDocumentChannel with SrcdocData on a non-about:srcdoc URI -> attacker HTML served at victim origin (UXSS), via mojo-port send-path injection from a compromised content process
Sandbox escape in the DOM: Navigation component
48RISK
open ↗GitHub PoC★ 15
CVE 1-day in http.sys
Windows HTTP.sys Elevation of Privilege Vulnerability
41RISK
open ↗GitHub PoC
PoC, Dockerfile playground and root cause from patch diff analysis.
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open ↗GitHub PoC★ 84
CVE-2026-75604 Next.js Windows RCE poc
Next.js: Unauthenticated Remote Code Execution on windows-hosted servers
48RISK
open ↗GitHub PoC
Exploit for CVE-2026-18963 by BlackHatExploitation
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.