[PoC] Public PoC Available

79 CVEs with public exploit code on GitHub

These vulnerabilities have public proof-of-concept exploit code on GitHub, sourced from nomi-sec/PoC-in-GitHub. The data is automatically filtered to remove audit tools, scanners, advisories, and empty placeholder repos. Treat all linked code as untrusted - see each CVE's PoC References section for the full safety warning.

CVE-2026-10520

Jun 9, 2026

Critical (10.0)

An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution...

Read Advisory

CVE-2026-25089

Jun 9, 2026

Critical (9.8)

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox ...

Read Advisory

CVE-2026-50751

Jun 8, 2026

Critical (9.3)

A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a...

Read Advisory

CVE-2026-20245

Jun 4, 2026

High (7.8)

A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBo...

Read Advisory

CVE-2025-48595

Jun 1, 2026

High (8.4)

In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. Us...

Read Advisory

CVE-2026-44590

May 27, 2026

Critical (9.3)

Sherlock hunts down social media accounts by username across social networks. Prior to 0.16.1, the GitHub Actions workflow validate_modified_targets.yml is vulnerable to command injection via the pull...

Read Advisory

CVE-2026-45247

May 26, 2026

Critical (9.8)

Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code execution by supplying a...

Read Advisory

CVE-2026-48172

May 21, 2026

Critical (10.0)

LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE "cpanel_jsonap...

Read Advisory

CVE-2026-41091

May 20, 2026

High (7.8)

Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally....

Read Advisory

CVE-2026-9082

May 20, 2026

Medium (6.5)

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.1...

Read Advisory

CVE-2026-20182

May 14, 2026

Critical (10.0)

May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026. This new advisory is for a new vu...

Read Advisory

CVE-2026-42945

May 13, 2026

Critical (9.2)

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an ...

Read Advisory

CVE-2026-0257

May 13, 2026

Critical (9.1)

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized V...

Read Advisory

CVE-2026-45321

May 12, 2026

Critical (9.6)

On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate G...

Read Advisory

CVE-2026-42208

May 8, 2026

Critical (9.8)

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query used during proxy API key checks mixed the caller-...

Read Advisory

CVE-2026-42271

May 8, 2026

High (8.8)

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server before saving it — POST ...

Read Advisory

CVE-2026-0300

May 6, 2026

Critical (9.3)

A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code wi...

Read Advisory

CVE-2026-42778

May 1, 2026

Critical (9.8)

The fix for CVE-2026-41409 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description: The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was inco...

Read Advisory

CVE-2026-42779

May 1, 2026

Critical (9.8)

The fix for CVE-2026-41635 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description: Apache MINA's AbstractIoBuffer.resolveClass() contains two branches, one...

Read Advisory

CVE-2026-41940

Apr 29, 2026

Critical (9.8)

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel....

Read Advisory

CVE-2026-42167

Apr 28, 2026

High (8.1)

mod_sql in ProFTPD before 1.3.10rc1 allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER requests with an expansion such as %U, and the SQL bac...

Read Advisory

CVE-2026-33453

Apr 27, 2026

Critical (10.0)

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Apache Camel Camel-Coap component. Apache Camel's camel-coap component is vulnerable to Camel message h...

Read Advisory

CVE-2026-40897

Apr 24, 2026

High (8.8)

Math.js is an extensive math library for JavaScript and Node.js. From 13.1.1 to before 15.2.0, a vulnerability allowed executing arbitrary JavaScript via the expression parser of mathjs. You can be af...

Read Advisory

CVE-2026-31431

Apr 22, 2026

High (7.8)

Copy Fail (CVE-2026-31431) is an in-place AEAD memory bug in the Linux kernel's algif_aead crypto interface, allowing local low-privileged attackers to corrupt memory and execute arbitrary code at kernel level. The fix reverts commit 72548b093ee3 (except for associated-data copying) to restore out-of-place operation. Disclosed by Theori/Xint as Copy Fail; actively exploited in the wild and listed in CISA KEV.

Read Advisory

CVE-2026-40487

Apr 18, 2026

High (8.9)

Postiz is an AI social media scheduling tool. Prior to version 2.21.6, a file upload validation bypass allows any authenticated user to upload arbitrary HTML, SVG, or other executable file types to th...

Read Advisory

CVE-2026-37749

Apr 17, 2026

Critical (9.8)

A SQL injection vulnerability in CodeAstro Simple Attendance Management System v1.0 allows remote unauthenticated attackers to bypass authentication via the username parameter in index.php....

Read Advisory

CVE-2026-20180

Apr 15, 2026

Critical (9.9)

A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit...

Read Advisory

CVE-2026-39808

Apr 14, 2026

Critical (9.8)

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code ...

Read Advisory

CVE-2026-33825

Apr 14, 2026

High (7.8)

Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally....

Read Advisory

CVE-2026-32201

Apr 14, 2026

Medium (6.5)

Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network....

Read Advisory

CVE-2026-32202

Apr 14, 2026

Medium (4.3)

Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network....

Read Advisory

CVE-2026-5059

Apr 11, 2026

Critical (9.8)

aws-mcp-server AWS CLI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of aws-mcp-server. Authenti...

Read Advisory

CVE-2026-40175

Apr 10, 2026

Critical (10.0)

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0, the Axios library is vulnerable to a specific "Gadget" attack chain that allows Prototype Pollution in any third-part...

Read Advisory

CVE-2026-39987

Apr 9, 2026

Critical (9.8)

marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint /terminal/ws lacks authentication validation, allowing an unauthenticate...

Read Advisory

CVE-2026-34197

Apr 7, 2026

High (8.8)

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bri...

Read Advisory

CVE-2025-54328

Apr 6, 2026

Critical (10.0)

An issue was discovered in SMS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 9110, W920, W930, W1000, Mod...

Read Advisory

CVE-2026-35616

Apr 4, 2026

Critical (9.8)

A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests....

Read Advisory

CVE-2026-34156

Mar 31, 2026

Critical (9.9)

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.28, NocoBase's Workflow Script Node executes user-supplied JavaScr...

Read Advisory

CVE-2026-33032

Mar 30, 2026

Critical (9.8)

Nginx UI is a web user interface for the Nginx web server. In versions 2.3.5 and prior, the nginx-ui MCP (Model Context Protocol) integration exposes two HTTP endpoints: /mcp and /mcp_message. While /...

Read Advisory

CVE-2026-22738

Mar 27, 2026

Critical (9.8)

In Spring AI, a SpEL injection vulnerability exists in SimpleVectorStore when a user-supplied value is used as a filter expression key. A malicious actor could exploit this to execute arbitrary code. ...

Read Advisory

CVE-2026-33937

Mar 27, 2026

Critical (9.8)

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `Handlebars.compile()` accepts a pre-parsed AST object in addition to a template string....

Read Advisory

CVE-2026-27876

Mar 27, 2026

Critical (9.1)

A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impact (RCE). This is enabled by a feature in Grafana (OSS), so all users are always ...

Read Advisory

CVE-2026-26830

Mar 25, 2026

Critical (9.8)

pdf-image (npm package) through version 2.0.0 allows OS command injection via the pdfFilePath parameter. The constructGetInfoCommand and constructConvertCommandForPage functions use util.format() to i...

Read Advisory

CVE-2026-29187

Mar 25, 2026

High (8.1)

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, a Blind SQL Injection vulnerability exists in the Patient Search func...

Read Advisory

CVE-2026-33186

Mar 20, 2026

Critical (9.1)

gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go serve...

Read Advisory

CVE-2026-32255

Mar 19, 2026

High (8.6)

Kan is an open-source project management tool. In versions 0.5.4 and below, the /api/download/attatchment endpoint has no authentication and no URL validation. The Attachment Download endpoint accepts...

Read Advisory

CVE-2026-32731

Mar 18, 2026

Critical (9.9)

ApostropheCMS is an open-source content management framework. Prior to version 3.5.3 of `@apostrophecms/import-export`, The `extract()` function in `gzip.js` constructs file-write paths using `fs.crea...

Read Advisory

CVE-2026-32321

Mar 18, 2026

High (8.8)

ClipBucket v5 is an open source video sharing platform. An authenticated time-based blind SQL injection vulnerability exists in ClipBucket prior to 5.5.3 #80 within the `actions/ajax.php` endpoint. Du...

Read Advisory

CVE-2026-3891

Mar 13, 2026

Critical (9.8)

The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check and missing file type validation in the 'lkn_pix_for_woocommerce_c6_save_settings' ...

Read Advisory

CVE-2026-3909

Mar 13, 2026

High (8.8)

Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)...

Read Advisory

CVE-2026-32096

Mar 11, 2026

Critical (9.3)

Plunk is an open-source email platform built on top of AWS SES. Prior to 0.7.0, a Server-Side Request Forgery (SSRF) vulnerability existed in the SNS webhook handler. An unauthenticated attacker could...

Read Advisory

CVE-2026-3288

Mar 9, 2026

High (8.8)

A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/rewrite-target` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary co...

Read Advisory

CVE-2026-0848

Mar 5, 2026

Critical (10.0)

NLTK versions <=3.9.2 are vulnerable to arbitrary code execution due to improper input validation in the StanfordSegmenter module. The module dynamically loads external Java .jar files without verific...

Read Advisory

CVE-2026-27944

Mar 5, 2026

Critical (9.8)

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.3, the /api/backup endpoint is accessible without authentication and discloses the encryption keys required to decrypt t...

Read Advisory

CVE-2026-20079

Mar 4, 2026

Critical (10.0)

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an a...

Read Advisory

CVE-2026-20131

Mar 4, 2026

Critical (10.0)

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root o...

Read Advisory

CVE-2026-0847

Mar 4, 2026

High (8.6)

A vulnerability in NLTK versions up to and including 3.9.2 allows arbitrary file read via path traversal in multiple CorpusReader classes, including WordListCorpusReader, TaggedCorpusReader, and Brack...

Read Advisory

CVE-2026-28289

Mar 3, 2026

Critical (10.0)

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A patch bypass vulnerability for CVE-2026-27636 in FreeScout 1.8.206 and earlier allows any authenticated user with f...

Read Advisory

CVE-2026-3395

Mar 1, 2026

High (7.3)

A flaw has been found in MaxSite CMS up to 109.1. This impacts the function eval of the file application/maxsite/admin/plugins/editor_markitup/preview-ajax.php of the component MarkItUp Preview AJAX E...

Read Advisory

CVE-2026-2749

Feb 27, 2026

Critical (9.9)

Vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centroen Open Ticket modules).This issue affects Centreon Open Tickets on Central Server: from all before 25.10.3, 24.10.8, ...

Read Advisory

CVE-2026-27966

Feb 26, 2026

Critical (9.8)

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.8.0, the CSV Agent node in Langflow hardcodes `allow_dangerous_code=True`, which automatically exposes...

Read Advisory

CVE-2026-20127

Feb 25, 2026

Critical (10.0)

A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, r...

Read Advisory

CVE-2025-62878

Feb 25, 2026

Critical (9.9)

A malicious user can manipulate the parameters.pathPattern to create PersistentVolumes in arbitrary locations on the host node, potentially overwriting sensitive files or gaining access to unintended ...

Read Advisory

CVE-2026-21902

Feb 25, 2026

Critical (9.8)

An Incorrect Permission Assignment for Critical Resource vulnerability in the On-Box Anomaly detection framework of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated, network-b...

Read Advisory

CVE-2026-27574

Feb 21, 2026

Critical (9.9)

OneUptime is a solution for monitoring and managing online services. In versions 9.5.13 and below, custom JavaScript monitor feature uses Node.js's node:vm module (explicitly documented as not a secur...

Read Advisory

CVE-2026-27470

Feb 21, 2026

High (8.8)

ZoneMinder is a free, open source closed-circuit television software application. In versions 1.36.37 and below and 1.37.61 through 1.38.0, there is a second-order SQL Injection vulnerability in the w...

Read Advisory

CVE-2026-1405

Feb 19, 2026

Critical (9.8)

The Slider Future plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'slider_future_handle_image_upload' function in all versions up to, and includ...

Read Advisory

CVE-2026-25242

Feb 19, 2026

Critical (9.8)

Gogs is an open source self-hosted Git service. Versions 0.13.4 and below expose unauthenticated file upload endpoints by default. When the global RequireSigninView setting is disabled (default), any ...

Read Advisory

CVE-2025-65791

Feb 18, 2026

Critical (9.8)

ZoneMinder v1.36.34 is vulnerable to Command Injection in web/views/image.php. The application passes unsanitized user input directly to the exec() function....

Read Advisory

CVE-2026-27174

Feb 18, 2026

Critical (9.8)

MajorDoMo (aka Major Domestic Module) allows unauthenticated remote code execution via the admin panel's PHP console feature. An include order bug in modules/panel.class.php causes execution to contin...

Read Advisory

CVE-2025-70830

Feb 17, 2026

Critical (9.9)

A Server-Side Template Injection (SSTI) vulnerability in the Freemarker template engine of Datart v1.0.0-rc.3 allows authenticated attackers to execute arbitrary code via injecting crafted Freemarker ...

Read Advisory

CVE-2024-55270

Feb 17, 2026

High (8.8)

phpgurukul Student Management System 1.0 is vulnerable to SQL Injection in studentms/admin/search.php via the searchdata parameter....

Read Advisory

CVE-2025-70828

Feb 17, 2026

High (8.8)

An issue in Datart v1.0.0-rc.3 allows attackers to execute arbitrary code via the url parameter in the JDBC configuration...

Read Advisory

CVE-2025-65717

Feb 16, 2026

Critical (9.1)

An issue in Visual Studio Code Extensions Live Server v5.7.9 allows attackers to exfiltrate files via user interaction with a crafted HTML page....

Read Advisory

CVE-2026-1357

Feb 11, 2026

Critical (9.8)

The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Upload in versions up to and including 0.9.123. This is due to improper...

Read Advisory

CVE-2025-34291

Dec 5, 2025

Critical (9.4)

Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with all...

Read Advisory

CVE-2024-21182

Jul 16, 2024

High (7.5)

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerabilit...

Read Advisory

CVE-2022-0492

Mar 3, 2022

High (7.8)

A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_a...

Read Advisory

CVE-2008-4250

Oct 23, 2008

Critical (10.0)

The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a craft...

Read Advisory

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.