Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,324cataloged exploits
36,054CVEs with public exploitation
24,695lab-tested
14,424 exploits
GitHub PoC
Safely detect Veeam Service Provider Console auth bypass CVE-2026-58073
CVE-2026-58073CRITICAL25 Aug 2026
A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent an
48RISK
open
GitHub PoC2
CVE-2026-15469 — Hard-coded RSA-512 mesh group private key in TP-Link Deco XE75/XE5300/WE10800 (CWE-321). Advisory, analysis & PoC methodology (EN/KO).
CVE-2026-15469HIGH25 Aug 2026
Hard-coded Mesh Group Private Key in TP-Link Deco XE75, XE5300, and WE10800
41RISK
open
GitHub PoC
PoC, Dockerfile playground and root cause from patch diff analysis.
CVE-2026-18963CRITICAL25 Aug 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open
GitHub PoC
Use cve-2026-36425 killer edr,360 can killer
CVE-2026-36425MEDIUM25 Aug 2026
An issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier in IOCTL handler 0x2420031. Any local user
33RISK
open
GitHub PoC
Nuclei template to discover Keycloak reset-credentials endpoints related to CVE-2026-18963 exposure validation.
CVE-2026-18963CRITICAL25 Aug 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open
GitHub PoC1
PoC for CVE-2026-32475: Elementor Pro <=4.2.1 unauthenticated file upload to RCE. Stdlib-only Python.
CVE-2026-32475CRITICAL25 Aug 2026
WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability
48RISK
open
GitHub PoC
TP-Link Archer BE800 V1 — VPN Key Injection RCE
CVE-2026-16348HIGH25 Aug 2026
Command Injection Vulnerability in VPN connection of Archer BE800
41RISK
open
GitHub PoC12
This repo is poc of cve-2026-18963. Please use it on legal products (lab, local,...).
CVE-2026-18963CRITICAL25 Aug 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open
GitHub PoC1
CVE-2026-56705 - Adminer < 5.4.3 unauthenticated RCE via MSSQL PDO DSN injection (ODBC TraceFile arbitrary file write). PoC, Docker lab and negative test included.
CVE-2026-56705CRITICAL25 Aug 2026
Adminer before 5.4.3 Remote Code Execution via MSSQL PDO DSN Injection
48RISK
open
GitHub PoC1
PoC for CVE-2026-73570 (Zimbra SMTP Command Injection)
CVE-2026-73570HIGHunder attack25 Aug 2026
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp
71RISK
open
GitHub PoC1
Firefox content->parent srcdoc forge (N-day, bug 2040160): forged PDocumentChannel with SrcdocData on a non-about:srcdoc URI -> attacker HTML served at victim origin (UXSS), via mojo-port send-path injection from a compromised content process
CVE-2026-12295CRITICAL25 Aug 2026
Sandbox escape in the DOM: Navigation component
48RISK
open
GitHub PoC
CVE-2026-68820 — Mass Exploit Framework Edition.
CVE-2026-68820HIGHunder attack25 Aug 2026
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
71RISK
open
GitHub PoC
Este repositorio contiene una demostración educativa de la mitigación y detección para **CVE-2026-72530**, una vulnerabilidad crítica de **Code Injection y Sandbox Escape** en TrueConf Server.
CVE-2026-72530CRITICALunder attack25 Aug 2026
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4
78RISK
open
GitHub PoC
CVE-2026-17532 Docker Lab.
CVE-2026-17532MEDIUM25 Aug 2026
Seraphinite Accelerator <= 2.29.18 - Reflected Cross-Site Scripting
48RISK
open
GitHub PoC2
CVE-2026-77806漏洞检测代码
CVE-2026-77806CRITICAL24 Aug 2026
SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August
48RISK
open
GitHub PoC
CVE-2026-73570 PoC
CVE-2026-73570HIGHunder attack24 Aug 2026
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp
71RISK
open
GitHub PoC
Reproducer for CVE-2026-66906 (Apache Camel camel-azure-storage-blob downloadBlobToFile path traversal) — Camel Spring Boot + Camel Quarkus
CVE-2026-66906CRITICAL24 Aug 2026
Apache Camel: Camel-Azure-Storage-Blob: the downloadBlobToFile operation built the local download target from the remote blob name without constraining it to the configured fileDir
48RISK
open
GitHub PoC
Patch: Heap overflow in SSL-VPN (Fortinet FortiOS)
CVE-2026-12087CRITICAL24 Aug 2026
Socket versions before 2.041 for Perl have an out-of-bounds heap read
48RISK
open
GitHub PoC
Reproducer for CVE-2026-60093 (Apache Camel camel-azure-storage-datalake downloadToFile path traversal) — Camel Spring Boot + Camel Quarkus
CVE-2026-60093MEDIUM24 Aug 2026
Apache Camel: Camel-Azure-Storage-DataLake: the downloadToFile operation built the local download target from the remote path name without constraining it to the configured fileDir
33RISK
open
GitHub PoC
imbas007/RCE-CVE-2026-10520-CVE-2026-10523
CVE-2026-10520CRITICAL24 Aug 2026
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote
85RISK
open
GitHub PoC
Reproducer for CVE-2026-66907 (Apache Camel camel-google-storage downloadFileName path traversal) — Camel Spring Boot + Camel Quarkus
CVE-2026-66907HIGH24 Aug 2026
Apache Camel: Camel-Google-Storage: the consumer appended the remote object name to the configured downloadFileName directory without constraining the result
41RISK
open
GitHub PoC
Reproducer for CVE-2026-63039 (Apache InLong AuditAlertRule MyBatis ORDER BY SQL injection via orderField/orderType)
CVE-2026-63039CRITICAL24 Aug 2026
Apache InLong: SQL Injection via Unvalidated MyBatis Dollar-Sign Interpolation in AuditAlertRuleService
48RISK
open
GitHub PoC1
Firefox content-to-parent IPDL privilege escalation (N-day, bug 2054416): forged PDocumentChannel with RemoteTypeOverride -> privilegedabout process placement, via mojo-port send-path injection from a compromised content process
CVE-2026-74939HIGH24 Aug 2026
Privilege escalation in the DOM: Navigation component
41RISK
open
GitHub PoC
Reproducer for CVE-2026-66908 (Apache Camel camel-platform-http-main JWT iss/aud not validated) — standalone camel-main
CVE-2026-66908HIGH24 Aug 2026
Apache Camel: Camel-platform-http-main: when JWT authentication was configured with a keystore but no issuer or audience, the iss and aud claims were never validated, so any unexpired token signed by a trusted key was accepted
41RISK
open
GitHub PoC
Reproducer for CVE-2026-63621 (Apache Camel camel-knative structured CloudEvent header injection) — Camel Spring Boot + Camel Quarkus
CVE-2026-63621MEDIUM24 Aug 2026
Apache Camel: Camel-Knative: CloudEvent extension fields received in structured content mode were mapped onto message headers without applying any header filter strategy
33RISK
open
GitHub PoC
h00die/POC-CVE-2026-19626
CVE-2026-19626CRITICAL24 Aug 2026
Remote Code Execution
48RISK
open
GitHub PoC
minh3102011/CVE-2026-18963_analyst
CVE-2026-18963CRITICAL24 Aug 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open
GitHub PoC2
T0w0T/POC-CVE-2026-18963
CVE-2026-18963CRITICAL24 Aug 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open
GitHub PoC11
CVE-2026-18963
CVE-2026-18963CRITICAL24 Aug 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open
GitHub PoC
Reproducer for CVE-2026-28672 (Apache Ranger UnixUserGroupBuilder OS command injection via username in the unixusersync module)
CVE-2026-28672CRITICAL24 Aug 2026
Apache Ranger: OS Command Injection via Username in UnixUserGroupBuilder
48RISK
open
page 1 / 481next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.