Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,794cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,459Referência 22,721GitHub PoC 14,946VulnCheck XDB 8,829Nuclei 4,350Metasploit 3,489✓ verified onlyrecentpopularrisk
14,946 exploits
GitHub PoC
PoC for CVE-2026-73847 - emlog AI Assistant CSRF to SQL execution to admin takeover (CVSS 6.8)
Emlog: Missing CSRF protection in AI Assistant execute_tool leads to full database compromise and admin account takeover
33RISK
open ↗GitHub PoC
Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator
Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator
48RISK
open ↗GitHub PoC
eh-amish/Windows-Defender-Security-Auditor-CVE-2026-50656-
Microsoft Defender Elevation of Privilege Vulnerability
46RISK
open ↗GitHub PoC
PoC: Shiori JWT CheckToken never re-validates account state (CVE-2026-71206, High 8.2)
shiori - JWT CheckToken Never Re-Validates Account State, Allowing Stale-Privilege Access After Deletion or Demotion
41RISK
open ↗GitHub PoC★ 1
CVE-2026-73678 — MindsDB Minds Platform unauthenticated RCE via scratchpad exec (CVSS 10.0). Verified end-to-end with real LLM
MindsDB Minds Platform v26.1.0 Unauthenticated RCE via scratchpad exec()
48RISK
open ↗GitHub PoC
POC of CVE-2026-51031 for arbitrary local file read
FlareSolverr before version 3.4.7 contains a server-side request forgery (SSRF) vulnerability in the /v1 API endpoint. T
41RISK
open ↗GitHub PoC
PoC: Grafana Editor role deletes protected contact points (CVE-2026-72585, Medium 6.5)
23RISK
open ↗GitHub PoC
PoC: changedetection.io unauthenticated OpenAPI schema disclosure (CVE-2026-71203, Medium 5.3)
changedetection.io - Missing Authentication on /api/v1/full-spec Discloses Full OpenAPI Schema
33RISK
open ↗GitHub PoC
a-mansilla/CVE-2020-6418
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corru
100RISK
open ↗GitHub PoC
Simple script to achieve safe and non-desruptive active detection of CVE-2026-72898 (SQLi in Metabase)
Metabase SQL injection via password reset endpoint
100RISK
open ↗GitHub PoC
PoC for CVE-2026-73519 - WolfStack hardcoded cluster secret leads to unauthenticated RCE (CVSS 9.8)
WolfStack < 25.9.2 Hard-coded Secret Authentication Bypass via X-WolfStack-Secret
48RISK
open ↗GitHub PoC★ 3
One-Day POC | GeoServer Unauthenticated SQL injection to complete RCE
GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers
63RISK
open ↗GitHub PoC★ 1
This repository contains a conceptual patch demonstrating the mitigation for CVE-2026-68820, a critical Use-After-Free (UAF) vulnerability in the Windows Ancillary Function Driver for WinSock (`afd.sys`).
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
71RISK
open ↗GitHub PoC★ 2
CVE-2026-43499 (GhostLock) rt_mutex stack-UAF privilege escalation research on Honor BVL-AN16 (Magic6 Pro, SM8650, kernel 6.1.128). Includes analysis docs, reverse-engineering scripts, disassembly artifacts, and exploit source with honor-BVL-AN16 target adaptation.
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open ↗GitHub PoC
CVE-2026-17544: PHP bcmath OOB write → universal memory-only RCE & disable_functions/open_basedir bypass. Offset-free runtime resolver. Verified on PHP 8.4.x / 8.5.x.
Out-of-bounds write in bccomp() via crafted operand and scale
41RISK
open ↗GitHub PoC
DuyDuongDuyDuong/CVE-2024-4577-Exploitation-AsyncRAT-Deployment-DFIR-Investigation
Argument Injection in PHP-CGI
100RISK
open ↗GitHub PoC
Python StateMachine 3.0.0 < 3.2.0 RCE via unsafe SCXML <data expr> evaluation and Python eval() injection.
Python StateMachine 3.0.0 < 3.2.0 RCE via SCXML eval() Injection
48RISK
open ↗GitHub PoC
CVE-2026-58231 Detection & Confirmation Script
Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)
48RISK
open ↗GitHub PoC
An explanation and PoC to exploit CVE-2026-20896 Authentication Bypass Vulnerability on Gitea. Being able to steal session tokens for valid users in the Gitea instance.
Gitea Docker image trusts spoofable reverse-proxy headers by default
63RISK
open ↗GitHub PoC
Username Enumeration via Authentication Timing Side-Channel in PaperCut NG
PaperCut NG/MF: User enumeration via timing attack
33RISK
open ↗GitHub PoC
Full root in kernel domain with selinux permissive **MOVED TO THIS REPO https://github.com/CamsShaft/IonStack-S22 WILL DELETE THIS ONE SOON**
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open ↗GitHub PoC
Responsible disclosure write-ups for CVE-2026-8793 - PaperCut NG 25.0.11
PaperCut NG/MF: Insufficient brute-force protection
33RISK
open ↗GitHub PoC
ghostpels/CVE-2026-13610
KiviCare < 4.5.2 - Unauthenticated Privilege Escalation via Registration
41RISK
open ↗GitHub PoC★ 3
One-command Docker lab reproducing CVE-2026-71362 (Adobe Commerce / Magento Open Source customer-session identity-switch account takeover, APSB26-92, CVSS 9.1) with a PoC and an A/B/A official-patch negative control. For authorized security research and education.
Adobe Commerce | Incorrect Authorization (CWE-863)
68RISK
open ↗GitHub PoC
CVE-2026-43499 research port for Galaxy Z Fold4 SM-F936W F936WVLU1AVGA (in progress)
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open ↗GitHub PoC
Hunt-Benito/bring-your-own-key-cve-2026-73678-unauthenticated-rce-in-mindsdb-cowork
MindsDB Minds Platform v26.1.0 Unauthenticated RCE via scratchpad exec()
48RISK
open ↗GitHub PoC
CVE-2026-64638 adalah kerentanan Pre-Auth Reflected Cross-Site Scripting (XSS) di WordPress yang ditemukan pada tahun 2026. Kerentanan ini memungkinkan penyerang untuk menyisipkan kode JavaScript berbahaya ke halaman login WordPress (/wp-login.php) tanpa perlu autentikasi terlebih dahulu.
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.
Via a specially crafted malici
68RISK
open ↗GitHub PoC
uproot <= 5.7.4 code injection via unsafe Python source generation from ROOT TStreamerInfo metadata.
uproot 5.7.4 and prior Code Injection via TStreamerInfo Metadata
41RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.