Top PoC Exploits

CVEs with public exploit code on GitHub / ExploitDB, enriched with KEV and EPSS.

With PoC (30d)

PoC + KEV

PoC + EPSS ≥ 0.9

Ransomware use

CVE-2026-63030 CRITICAL · 9.8 PoC × 20 KEV EPSS 97%

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker

wordpress Jul 17, 2026 View attack flow
CVE-2026-18963 CRITICAL · 9.1 PoC × 12 EPSS 3%

A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to

Aug 18, 2026 1 mention View attack flow
CVE-2026-60004 CRITICAL · 9.8 PoC × 11 KEV EPSS 87%

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

gitea Aug 26, 2026 7 mentions View attack flow
CVE-2026-60137 MEDIUM · 5.9 PoC × 10 KEV EPSS 78%

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input

wordpress Jul 17, 2026 View attack flow
CVE-2026-48908 CRITICAL · 9.8 PoC × 9 KEV EPSS 15%

A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

ollyo Jun 20, 2026 View attack flow
CVE-2026-72898 CRITICAL · 10.0 PoC × 8 KEV EPSS 94%

Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.

metabase Aug 10, 2026 1 mention View attack flow
CVE-2026-16723 CRITICAL · 9.0 PoC × 7 EPSS 16%

A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget

Jul 23, 2026 View attack flow
CVE-2026-15409 CRITICAL · 10.0 PoC × 6 KEV RANSOMWARE EPSS 84%

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended

sonicwall Jul 14, 2026 8 mentions View attack flow
CVE-2026-82329 CRITICAL · 9.8 PoC × 6 KEV EPSS 8%

JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.

jfrog Aug 28, 2026 9 mentions View attack flow
CVE-2026-10520 CRITICAL · 10.0 PoC × 5 KEV EPSS 100%

An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution

ivanti Jun 9, 2026 View attack flow
CVE-2026-9198 CRITICAL · 9.8 PoC × 5 KEV EPSS 57%

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full

langflow Jul 17, 2026 1 mention View attack flow
CVE-2026-50522 CRITICAL · 9.8 PoC × 5 KEV EPSS 85%

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

microsoft Jul 14, 2026 1 mention View attack flow
CVE-2026-63077 CRITICAL · 9.8 PoC × 5 KEV EPSS 87%

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

jetbrains Jul 27, 2026 5 mentions View attack flow
CVE-2026-19478 CRITICAL · 9.4 PoC × 5 EPSS 6%

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated

gitlab Aug 17, 2026 14 mentions View attack flow
CVE-2026-73570 HIGH · 8.9 PoC × 5 KEV EPSS 32%

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted i

synacor Aug 13, 2026 6 mentions View attack flow
CVE-2026-60206 CRITICAL · 9.9 PoC × 4 EPSS 1%

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerab

oracle Jul 21, 2026 View attack flow
CVE-2026-20896 CRITICAL · 9.8 PoC × 4 EPSS 3%

Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are ena

Jul 3, 2026 2 mentions View attack flow
CVE-2026-20253 CRITICAL · 9.8 PoC × 4 KEV EPSS 97%

In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint. The vulnerability exists becau

splunk Jun 10, 2026 View attack flow
CVE-2026-56290 CRITICAL · 9.8 PoC × 4 KEV EPSS 30%

Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading exe

joomlack Jun 29, 2026 View attack flow
CVE-2026-57827 CRITICAL · 9.8 PoC × 4 EPSS 2%

Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12 - The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files

rsjoomla Jul 11, 2026 View attack flow
CVE-2026-61511 CRITICAL · 9.8 PoC × 4 EPSS 71%

vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execut

Jul 27, 2026 View attack flow
CVE-2026-64564 CRITICAL · 9.8 PoC × 4 EPSS 1%

In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_asconf() caches the transport the ASCONF chunk is processed against in a

Aug 4, 2026 3 mentions View attack flow
CVE-2026-56291 CRITICAL · 9.8 PoC × 4 KEV EPSS 15%

Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executa

balbooa Jul 9, 2026 View attack flow
CVE-2026-68820 HIGH · 7.0 PoC × 4 KEV EPSS 6%

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

microsoft Aug 11, 2026 14 mentions View attack flow
CVE-2026-82222 CRITICAL · 10.0 PoC × 3 EPSS 0%

Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection. This issue affects GiveWP: from n/a through 4.16.7.1.

Aug 28, 2026 3 mentions View attack flow
CVE-2026-65400 CRITICAL · 9.8 PoC × 3 KEV EPSS 10%

An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen

apple Aug 6, 2026 4 mentions View attack flow
CVE-2026-53753 CRITICAL · 9.8 PoC × 3 EPSS 3%

Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.7, the _safe_eval_expression() function in the computed fields feature uses an AST validator that only blocks attributes starting with underscor

kidocode Jun 23, 2026 View attack flow
CVE-2026-58138 CRITICAL · 9.8 PoC × 3 EPSS 9%

Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary OS commands by submitting inline workflow definitions containing mal

Jun 30, 2026 View attack flow
CVE-2026-48611 CRITICAL · 9.8 PoC × 3 EPSS 4%

Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access in default installations.

Jun 12, 2026 View attack flow
CVE-2026-48939 CRITICAL · 9.8 PoC × 3 KEV EPSS 20%

A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

joomlic Jun 20, 2026 View attack flow