Top PoC Exploits

CVEs with public GitHub / ExploitDB proof-of-concept code, enriched with CISA KEV, EPSS scores, and article mentions. Updated daily.

CVE-2026-41940 CRITICAL · 9.8 KEV PoC × 20 EPSS 98%

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

webpros · 2026-04-29

CVE-2026-41089 CRITICAL · 9.8 PoC × 20 EPSS 72%

Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.

microsoft · 2026-05-12

CVE-2026-63030 CRITICAL · 9.8 KEV PoC × 20 EPSS 38%

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.

wordpress · 2026-07-17

CVE-2026-48907 CRITICAL · 9.8 KEV PoC × 15 EPSS 80%

A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.

widgetfactorylimited · 2026-06-05

CVE-2026-9082 CRITICAL · 9.8 KEV PoC × 11 EPSS 84%

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6.0 before 10.6.9, from 11.0.0 before 11.

drupal · 2026-05-20

CVE-2026-45321 CRITICAL · 9.6 KEV PoC × 10 EPSS 2%

On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publis

beproduct, guardrailsai, christianalares · 2026-05-12

CVE-2026-23918 HIGH · 8.8 PoC × 10 EPSS 45%

Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

apache software foundation · 2026-05-04

CVE-2026-0257 CRITICAL · 9.1 KEV PoC × 9 EPSS 86%

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues.

siemens, paloaltonetworks · 2026-05-13

CVE-2026-0300 CRITICAL · 9.8 KEV PoC × 8 EPSS 32%

A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially

palo alto networks · 2026-05-06

CVE-2026-48908 CRITICAL · 9.8 KEV PoC × 7 EPSS 1%

A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

ollyo · 2026-06-20

CVE-2026-8181 CRITICAL · 9.8 PoC × 7 EPSS 14%

The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass in versions 3.4.0 to 3.4.1.1. This is due to incorrect return-value handling in the `is_mainwp_authenticated()` function when val

burstbv · 2026-05-14

CVE-2026-50751 CRITICAL · 9.3 KEV PoC × 7 EPSS 70%

A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

checkpoint · 2026-06-08

CVE-2026-41096 CRITICAL · 9.8 PoC × 6 EPSS 1%

Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code over a network.

microsoft · 2026-05-12

CVE-2026-0073 HIGH · 8.8 PoC × 6 EPSS 0%

In adbd_tls_verify_cert of auth.cpp, there is a possible bypass of wireless ADB mutual authentication due to a logic error in the code. This could lead to remote (proximal/adjacent) code execution as the shell user with no additional execution privileges needed. User interaction

google · 2026-05-04

CVE-2026-43284 HIGH · 8.8 PoC × 6 EPSS 93%

In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP marks such skbs with SKBFL_SHARED_FRAG after skb_splice_from_iter(), so later paths th

linux · 2026-05-08

CVE-2026-15409 CRITICAL · 10.0 KEV PoC × 5 EPSS 16%

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.

sonicwall · 2026-07-14

CVE-2026-8732 CRITICAL · 9.8 PoC × 5 EPSS 19%

The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator Account Creation in all versions up to, and including, 6.1.0. This is due to the wpgmp_temp_access_ajax AJAX action being registered with wp_ajax_nopriv_ and protected only by a nonce che

flippercode · 2026-05-29

CVE-2026-42208 CRITICAL · 9.8 KEV PoC × 5 EPSS 86%

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query used during proxy API key checks mixed the caller-supplied key value into the query text instead of passing it as a separate param

berriai · 2026-05-08

CVE-2026-4480 CRITICAL · 9.0 PoC × 5 EPSS 12%

A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta characters. A remote attacker could exploit this

samba, redhat · 2026-05-26

CVE-2026-42167 HIGH · 8.1 PoC × 5 EPSS 4%

mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER requests with an expansion such as %U, and the SQL backend allows commands (e.g., COPY TO PROGRAM).

proftpd · 2026-04-28

CVE-2026-20182 CRITICAL · 10.0 KEV PoC × 4 EPSS 88%

May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026. This new advisory is for a new vulnerability in the control connection handshaking. The section of this advisory

cisco · 2026-05-14

CVE-2026-10520 CRITICAL · 10.0 KEV PoC × 4 EPSS 99%

An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution

ivanti · 2026-06-09

CVE-2026-5118 CRITICAL · 9.8 PoC × 4 EPSS 0%

The Divi Form Builder plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.2. This is due to the plugin accepting a user-controlled 'role' parameter from POST data during user registration without validating it against the form's config

divi engine · 2026-05-21

CVE-2026-49777 CRITICAL · 10.0 PoC × 3 EPSS 1%

Improper Validation of Specified Quantity in Input vulnerability in ShapedPlugin, LLC Product Slider Pro for WooCommerce allows Malicious Software Implanted. This issue affects Product Slider Pro for WooCommerce: from n/a before 3.5.4.

shapedplugin, llc · 2026-06-05

CVE-2026-20253 CRITICAL · 9.8 KEV PoC × 3 EPSS 88%

In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint. The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authenticat

splunk · 2026-06-10

CVE-2026-48172 CRITICAL · 9.8 KEV PoC × 3 EPSS 18%

LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE "cpanel_jsonapi_func=redisAble" /var/cpanel/logs /usr/local/cpanel/logs/ 2>/dev/null in Bash.

litespeedtech · 2026-05-21

CVE-2026-56290 CRITICAL · 9.8 KEV PoC × 3 EPSS 18%

Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

joomlack · 2026-06-29

CVE-2026-56291 CRITICAL · 9.8 KEV PoC × 3 EPSS 8%

Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

balbooa · 2026-07-09

CVE-2026-53753 CRITICAL · 9.8 PoC × 3 EPSS 0%

Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.7, the _safe_eval_expression() function in the computed fields feature uses an AST validator that only blocks attributes starting with underscore. Python generator and frame object attributes (gi_frame, f

kidocode · 2026-06-23

CVE-2026-8206 CRITICAL · 9.8 PoC × 3 EPSS 1%

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions 6.0.0 to 6.0.6. This is due to the plugin accepting an arbitrary email address when a username is used in the password r

themeum · 2026-06-02

CVE-2026-6279 CRITICAL · 9.8 PoC × 3 EPSS 2%

The Avada Builder (fusion-builder) plugin for WordPress is vulnerable to Unauthenticated Remote Code Execution via PHP Function Injection in versions up to and including 3.15.2. This is due to the `wp_conditional_tags` case in `Fusion_Builder_Conditional_Render_Helper::get_value(

themefusion · 2026-05-21

CVE-2026-20896 CRITICAL · 9.8 PoC × 3 EPSS 0%

Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled.

· 2026-07-03

CVE-2026-48611 CRITICAL · 9.8 PoC × 3 EPSS 2%

Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access in default installations.

· 2026-06-12

CVE-2026-45185 CRITICAL · 9.8 PoC × 3 EPSS 1%

Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a CHUNKING transfer, followed by a final cleartext byte on the same TCP connection.

exim · 2026-05-12

CVE-2026-42271 HIGH · 8.8 KEV PoC × 3 EPSS 80%

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server before saving it — POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list — accepted a full s

berriai · 2026-05-08

CVE-2026-41091 HIGH · 7.8 KEV PoC × 3 EPSS 8%

Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.

microsoft · 2026-05-20

CVE-2026-20245 HIGH · 7.8 KEV PoC × 3 EPSS 25%

A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an authenticated, local attacker to execute arbitrary commands a

cisco · 2026-06-04

CVE-2026-13768 CRITICAL · 10.0 PoC × 2 EPSS 0%

Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user to invoke an IoTHub Registry Manager function which returns connection information for all Gardyn Home Kit and Studio devices. Access to this key also allows a malicious user to exe

· 2026-07-03

CVE-2026-39938 CRITICAL · 9.8 PoC × 2 EPSS 0%

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have unauthenticated LFI through graph_theme and rrdtool IPC serialization hardening. This issue has been resolved in version 1.2.31.

cacti · 2026-06-24

CVE-2026-11551 CRITICAL · 9.8 PoC × 2 EPSS 0%

The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.29. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticate

· 2026-06-20

CVE-2026-45247 CRITICAL · 9.8 KEV PoC × 2 EPSS 27%

Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie. Attackers can exploit

mirasvit · 2026-05-26

CVE-2026-7515 CRITICAL · 9.8 PoC × 2 EPSS 0%

The BetterDocs Pro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.8.0 via the `doc_style` parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execut

· 2026-06-19

CVE-2026-35273 CRITICAL · 9.8 KEV PoC × 2 EPSS 92%

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP t

oracle · 2026-06-11

CVE-2026-35904 CRITICAL · 9.8 PoC × 2 EPSS 0%

Incorrect access control in the web management interface of T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, and T7281 v1.0.03 allows unauthorized attackers to enable the Telnet service via sending a crafted request to a vulnerable CGI component.

n/a · 2026-06-04

CVE-2026-11561 CRITICAL · 9.8 PoC × 2 EPSS 0%

Improper neutralization of special elements used in an expression language statement ('expression language injection') vulnerability in Soagen Informatics Technologies Software and Consulting Inc. Apinizer allows Code Injection. This issue affects Apinizer: from 2026.04.0 before

· 2026-06-11

CVE-2026-58138 CRITICAL · 9.8 PoC × 2 EPSS 0%

Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary OS commands by submitting inline workflow definitions containing malicious JavaScript or Python expressions to the workflow API

· 2026-06-30

CVE-2026-56782 CRITICAL · 9.8 PoC × 2 EPSS 3%

Gorse before 0.5.10 contains an authentication bypass vulnerability in the /api/dump and /api/restore endpoints that allows unauthenticated attackers to access protected functionality when admin_api_key is empty, which is the default configuration. Remote attackers can exfiltrate

· 2026-06-29

CVE-2026-57517 CRITICAL · 9.8 PoC × 2 EPSS 0%

Control Web Panel before 0.9.8.1225 contains a blind SQL injection vulnerability that allows unauthenticated remote attackers to execute arbitrary SQL queries by submitting unsanitized input through the userRes POST parameter at the user endpoint. Attackers can exploit MySQL root

· 2026-07-01

CVE-2026-10580 CRITICAL · 9.8 PoC × 2 EPSS 2%

The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to and including 1.9.4. This is due to a logic conflation in HippooPermissions::get_user_permissions(), which returns the

hippooo · 2026-06-05

CVE-2026-5076 CRITICAL · 9.8 PoC × 2 EPSS 0%

The ARMember Premium plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 7.3.1. The plugin stores a plaintext copy of the password reset key in the `arm_reset_password_key` user meta field when a user requests a passwor

armember · 2026-06-02

CVE-2026-25089 CRITICAL · 9.8 PoC × 2 EPSS 36%

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.

fortinet · 2026-06-09

CVE-2026-4885 CRITICAL · 9.8 PoC × 2 EPSS 0%

The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'pafe_ajax_form_builder' function in all versions up to, and including, 7.1.70. The plugin uses an incomplete extension blacklist that only

piotnet · 2026-05-19

CVE-2026-48939 CRITICAL · 9.8 KEV PoC × 2 EPSS 1%

A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

joomlic · 2026-06-20

CVE-2026-46817 CRITICAL · 9.8 PoC × 2 EPSS 1%

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Pay

oracle · 2026-05-28

CVE-2026-8037 CRITICAL · 9.6 PoC × 2 EPSS 43%

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints

progress software · 2026-06-04

CVE-2026-7482 CRITICAL · 9.1 PoC × 2 EPSS 1%

Ollama before 0.17.1 contains a heap out-of-bounds read vulnerability in the GGUF model loader. The /api/create endpoint accepts an attacker-supplied GGUF file in which the declared tensor offset and size exceed the file's actual length; during quantization in fs/ggml/gguf.go and

ollama · 2026-05-04

CVE-2026-40047 CRITICAL · 9.1 PoC × 2 EPSS 1%

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Camel Docling component. The camel-docling component invokes the external `docling` command-line tool by assembling an argument list in DoclingProducer and executing it thr

apache · 2026-07-06

CVE-2026-11645 HIGH · 8.8 KEV PoC × 2 EPSS 1%

Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

google · 2026-06-09

CVE-2026-20230 HIGH · 8.6 KEV PoC × 2 EPSS 41%

A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected devi

cisco · 2026-06-03

CVE-2026-54420 HIGH · 8.5 KEV PoC × 2 EPSS 1%

LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS, as exploited in the wild in May 2026.

litespeedtech · 2026-06-14

Top PoC Exploits

CVEs with public exploit code on GitHub / ExploitDB, enriched with KEV and EPSS.

With PoC (30d)

PoC + KEV

PoC + EPSS ≥ 0.9

Ransomware use

Loading exploits…