CYBERSECURITYTRACKER
TRACKING3,014 stories541 vuln stories
Analyst view

Exploits

Public exploit and proof-of-concept entries from Exploit-DB, maintained by OffSec, linked to the Common Vulnerabilities and Exposures (CVE) identifiers they target. This page carries metadata and links only, and never hosts or mirrors exploit code: every entry links out to its Exploit-DB page.

46,636 tracked8,224 verified all-timeSource: Exploit-DB (OffSec)
Published within
EDBPublishedTitleTypePlatformVerifiedCVEs
EDB-52629 ↗2026-07-08Krayin CRM v2.2.x - Authenticated Remote Code ExecutionwebappsmultipleCVE-2026-38526
EDB-52628 ↗2026-07-08Atarim WordPress Plugin 4.2.2 - Sensitive Information ExposurewebappsmultipleCVE-2025-60188
EDB-52627 ↗2026-07-08Langflow 1.9.0 - RCEwebappsmultipleCVE-2026-33017
EDB-52626 ↗2026-07-08Joomla Page Builder CK 3.5.10 - Arbitrary File UploadwebappsmultipleCVE-2026-56290
EDB-52625 ↗2026-07-07MCPJam Inspector - Remote Code ExecutionwebappsmultipleCVE-2026-23744
EDB-52624 ↗2026-07-07ProtonVPN v4.4.1 - Unquoted Service Pathlocalwindows
EDB-52623 ↗2026-07-07Flowise 3.1.3 - arbitrary code executionwebappsmultipleCVE-2026-58057
EDB-52622 ↗2026-07-07Hydra - Stack Buffer OverflowremotelinuxCVE-2026-56766
EDB-52621 ↗2026-07-07Discuz! X5.0 - Authentication BypasswebappsmultipleCVE-2026-49952
EDB-52620 ↗2026-07-07Tenable Nessus 10.12.1 - SQL InjectionwebappsmultipleCVE-2026-57588
EDB-52619 ↗2026-07-07WordPress Bricks Builder Theme - RCEwebappsmultipleCVE-2024-25600
EDB-52618 ↗2026-07-07iOS Bluetooth PAN Exploit - Ethernet Gateway without Adapterremoteios
EDB-52617 ↗2026-07-06Joomla Extension 4.1.4 - PHP Object injectionwebappsphpCVE-2026-48909
EDB-52616 ↗2026-07-06Pulpy 0.1.1-Beta - Filesystem Sandbox BypasswebappsmultipleCVE-2026-44225
EDB-52615 ↗2026-07-06MEmu Android Emulator 9.2.7.0 - Local Privilege EscalationlocalwindowsCVE-2026-36213
EDB-52614 ↗2026-07-06KeepInMind 0.8.4.2 - Stored XSSwebappsmultipleCVE-2026-9271
EDB-52613 ↗2026-07-06KNX visualisering - Broken Access Controlwebappsmultiple
EDB-52612 ↗2026-07-06Windows Defender (MsMpEng.exe) - Race Conditionlocalwindows
EDB-52611 ↗2026-07-06WordPress Plugin WPZOOM Portfolio 1.4.21 - Reflected Cross-Site Scripting (XSS)webappsmultipleCVE-2026-49069
EDB-52610 ↗2026-06-08OpenEMR 7.0.2 - Arbitrary File ReadwebappsmultipleCVE-2026-24849
EDB-52609 ↗2026-06-05WordPress Contest Gallery 28.1.4 - Unauthenticated Blind SQL InjectionwebappsmultipleCVE-2026-3180
EDB-52608 ↗2026-06-01Drupal Core 10.5.5 - Error-Based SQL InjectionwebappsphpCVE-2026-9082
EDB-52607 ↗2026-06-01WordPress OrderConvo 14 - Path TraversalwebappsmultipleCVE-2025-10162
EDB-52606 ↗2026-05-30Notepad++ 8.9.6 - Arbitrary Code ExecutionremotewindowsCVE-2026-48778
EDB-52605 ↗2026-05-30YAMCS yamcs-core 5.12.7 - No Rate LimitingwebappsmultipleCVE-2026-44596
EDB-52604 ↗2026-05-30YAMCS yamcs-core 5.12.7 - User EnumerationwebappsmultipleCVE-2026-44595
EDB-52603 ↗2026-05-30YAMCS yamcs-core 5.12.7 - LDAP InjectionwebappsmultipleCVE-2026-42568
EDB-52601 ↗2026-05-29Microsoft - NTLMv2 Hash CaptureremotewindowsCVE-2026-32202
EDB-52600 ↗2026-05-29MikroORM 7.0.13 - SQL InjectionwebappsmultipleCVE-2026-44680
EDB-52598 ↗2026-05-29Prodigy Commerce 3.3.0 - Local File InclusionwebappsmultipleCVE-2026-0926
EDB-52597 ↗2026-05-29Langflow 1.3.0 - Remote Code ExecutionwebappsmultipleCVE-2026-0770
EDB-52596 ↗2026-05-29Quick Playground for WordPress 1.3.1 - Unauthenticated Remote Code ExecutionwebappsmultipleCVE-2026-1830
EDB-52595 ↗2026-05-29ImageMagick - Infinite Loop in the MIFF decoder can lead to CPU exhaustionlocalmultipleCVE-2026-46522
EDB-52594 ↗2026-05-29ZTE Routers - Unauthenticated Denial of ServicelocalmultipleCVE-2026-34473
EDB-52593 ↗2026-05-29ZTE ZXHN H188A V6 - Authentication BypasslocalmultipleCVE-2026-34472
EDB-52592 ↗2026-05-29ZTE H298A / H108N - Unauthenticated Credential ExposurelocalmultipleCVE-2026-34474
EDB-52591 ↗2026-05-29Linux Kernel - Local Privilege EscalationlocallinuxCVE-2026-43284CVE-2026-43500CVE-2026-46300
EDB-52590 ↗2026-05-29MixPHP Framework 2.2.17 - Unsafe Deserialization Remote Code ExecutionwebappsphpCVE-2026-42471
EDB-52589 ↗2026-05-29Wing FTP Server 8.1.3 - Authenticated Remote Code ExecutionremotemultipleCVE-2026-44403
EDB-52588 ↗2026-05-29CubeCart < 6.7.0 - Reflected Cross-Site Scripting (XSS) (Unauthenticated)webappsmultipleCVE-2026-44376
EDB-52587 ↗2026-05-29strongSwan 5.9.13 - libsimaka EAP-SIM/AKA heap buffer overflowremotemultipleCVE-2026-35330
EDB-52586 ↗2026-05-29strongSwan 5.9.13 - DoSdosmultipleCVE-2026-35333
EDB-52585 ↗2026-05-27Linux Kernel - Local Privilege EscalationlocallinuxCVE-2026-43284CVE-2026-43500
EDB-52584 ↗2026-05-27Casdoor 3.54.1 - Arbitrary File Write via Path TraversalwebappsgoCVE-2026-6815
EDB-52583 ↗2026-05-27EspoCRM 9.3.3 - SSRFwebappsmultipleCVE-2026-33534
EDB-52582 ↗2026-05-27scramble - Remote Code ExecutionwebappsphpCVE-2026-44262
EDB-52581 ↗2026-05-27MeiG Smart FORGE_SLT711 - OS Command InjectionhardwarelinuxCVE-2026-36356
EDB-52580 ↗2026-05-27Realtek rtl819x - Local PrivilegelocallinuxCVE-2026-36355
EDB-52579 ↗2026-05-27OpenCATS 0.9.7.4 - SQL Injectionwebappsmultiple
EDB-52578 ↗2026-05-26Grav CMS 2.0.0-beta.2 - Remote Code ExecutionwebappsphpCVE-2026-42607
EDB-52577 ↗2026-05-26Apache HTTP Server 2.4.66 - 'mod_http2' Double-Free Denial of ServicewebappsmultipleCVE-2026-23918
EDB-52576 ↗2026-05-26D-Link DSL2600U - 'rom-0' Admin Password Disclosurehardwaremultiple
EDB-52575 ↗2026-05-26Wordpress Temporary Login Plugin 1.0.0 - 'temp-login-token' Authentication Bypass to Account TakeoverwebappsmultipleCVE-2026-7567
EDB-52574 ↗2026-05-26cPanel - CRLF InjectionwebappsphpCVE-2026-41940
EDB-52573 ↗2026-05-26Linux Kernel 6.8 - Local Privilege Escalationlocallinux
EDB-52572 ↗2026-05-21Cockpit 359 - RCEwebappsmultipleCVE-2026-4631
EDB-52571 ↗2026-05-21BookStack 25.12.1 - Denial of Servicewebappsmultiple
EDB-52570 ↗2026-05-21Lenovo LegionSpace 1.7.11.2 - 'DAService' Unquoted Service Pathlocalwindows
EDB-52569 ↗2026-05-21solaredge - (CSRF-OOB-Injection)webappsmultiple
EDB-52568 ↗2026-05-21FUXA 1.2.9 - RCEwebappsmultipleCVE-2026-25895
EDB-52567 ↗2026-05-15Windows Snipping Tool - NTLMv2 Hash HijacklocalwindowsCVE-2026-33829
EDB-52566 ↗2026-05-15Remote Sunrise Helper for Windows 2026.14 - Unauthenticated File/Directory Listinglocalwindows
EDB-52565 ↗2026-05-15Remote Sunrise Helper for Windows 2026.14 - Remote Code Executionlocalwindows
EDB-52564 ↗2026-05-14WordPress Plugin Supsystic Contact Form 1.7.36 - SSTIwebappsmultipleCVE-2026-4257
EDB-52563 ↗2026-05-14Apache HertzBeat 1.8.0 - Remote Code Executionwebappsmultiple
EDB-52562 ↗2026-05-14ePati Antikor NGFW 2.0.1301 - Authentication BypasswebappsmultipleCVE-2026-2624
EDB-52561 ↗2026-05-14PJPROJECT 2.16 - Heap BufferoverflowwebappsmultipleCVE-2026-25994
EDB-52560 ↗2026-05-13Ninja Forms Uploads - Unauthenticated PHP File UploadwebappsmultipleCVE-2026-0740
EDB-52559 ↗2026-05-13glances 4.5.2 - command injectionwebappsmultipleCVE-2026-33641
EDB-52558 ↗2026-05-13coreruleset 4.21.0 - Firewall BypasswebappsmultipleCVE-2026-21876
EDB-52557 ↗2026-05-13Flowise < 3.0.5 - Missing Authentication for Critical FunctionwebappstypescriptCVE-2025-58434
EDB-52556 ↗2026-05-07telnetd 2.7 - Buffer OverflowremotemultipleCVE-2026-32746
EDB-52555 ↗2026-05-07Ghost CMS 6.19.0 - SQLiwebappsmultipleCVE-2026-26980
EDB-52554 ↗2026-05-07LuaJIT 2.1.1774638290 - Arbitrary Code Executionwebappsmultiple
EDB-52553 ↗2026-05-07Bludit CMS 3.18.4 - RCEwebappsmultipleCVE-2026-25099
EDB-52552 ↗2026-05-07NocoBase 2.0.27 - VM Sandbox EscapelocalmultipleCVE-2026-34156
EDB-52551 ↗2026-05-07ThingsBoard IoT Platform 4.2.0 - Server-Side Request Forgery (SSRF)webappsmultipleCVE-2025-34282
EDB-52550 ↗2026-05-04Linux Kernel proc_readdir_de() 6.18-rc5 - Local Privilege EscalationlocallinuxCVE-2025-40271
EDB-52549 ↗2026-05-04Linux nf_tables 6.19.3 - Local Privilege EscalationlocallinuxCVE-2026-23231
EDB-52548 ↗2026-05-04Linksys E1200 2.0.04 - Authenticated Stack Buffer Overflow (RCE)hardwaremultipleCVE-2025-60690
EDB-52547 ↗2026-05-04MindsDB 25.9.1.1 - Path TraversalwebappsmultipleCVE-2026-27483
EDB-52546 ↗2026-05-04Windows 11 24H2 - Local Privilege EscalationlocalwindowsCVE-2026-21250
EDB-52545 ↗2026-05-04Traccar GPS Tracking System 6.11.1 - Cross-Site WebSocket Hijacking (CSWSH)webappsmultipleCVE-2025-68930
EDB-52544 ↗2026-04-30FUXA 1.2.8 - Authentication Bypass + RCE ExploitwebappsmultipleCVE-2025-69985
EDB-52543 ↗2026-04-30Python-Multipart 0.0.22 - Path TraversalwebappspythonCVE-2026-24486
EDB-52542 ↗2026-04-30Google Chrome 145.0.7632.75 - CSSFontFeatureValuesMaplocalmultipleCVE-2026-2441
EDB-52541 ↗2026-04-30Windows 11 23H2 - Denial of Service (DoS)localwindowsCVE-2025-47987
EDB-52540 ↗2026-04-30Repetier-Server 1.4.10 - Path TraversalwebappsmultipleCVE-2026-26335
EDB-52539 ↗2026-04-30HUSTOJ Zip-Slip v26.01.24 - RCEwebappsmultipleCVE-2026-24479
EDB-52538 ↗2026-04-30BusyBox 1.37.0 - Path TraversalwebappsmultipleCVE-2026-26157
EDB-52537 ↗2026-04-30Windows 11 25H2 - Heap OverflowlocalwindowsCVE-2026-21244CVE-2026-21248
EDB-52536 ↗2026-04-30JUNG Smart Visu Server 1.1.1050 - DoswebappsmultipleCVE-2026-26235
EDB-52535 ↗2026-04-30SumatraPDF 3.5.2 - Remote Code ExecutionwebappsmultipleCVE-2026-25961
EDB-52534 ↗2026-04-30NiceGUI 3.6.1 - Path TraversalwebappsmultipleCVE-2026-25732
EDB-52533 ↗2026-04-30Frigate NVR 0.16.3 - Remote Code ExecutionwebappsmultipleCVE-2026-25643
EDB-52532 ↗2026-04-30Js2Py 0.74 - RCEwebappsmultipleCVE-2024-28397
EDB-52531 ↗2026-04-30Camaleon CMS v2.9.0 - Path TraversalwebappsmultipleCVE-2024-46987
EDB-52530 ↗2026-04-30Cybersecurity AI (CAI) Framework 0.5.10 - Command Injectionwebappsmultiple
EDB-52529 ↗2026-04-30Erugo 0.2.14 - Remote Code Execution (RCE)webappsmultipleCVE-2026-24897
EDB-52528 ↗2026-04-30deephas 1.0.7 - Prototype PollutionwebappsmultipleCVE-2026-25047
About this data

Entries come from the Exploit-DB metadata index, maintained by OffSec. This page tracks metadata and links only: the title, publication date, exploit type, target platform, Exploit-DB's own verification flag, and the CVE identifiers each entry references. It never hosts, mirrors, or links to exploit code directly; the EDB column links to the entry's page on Exploit-DB, where the metadata and any code live. A CVE this tracker follows is a link into the vulnerabilities table; an untracked CVE is shown as plain text. The Verified badge is Exploit-DB's flag, not a verification by this tracker. The published-date window filters the same way the vulnerabilities view does: a segment shows only entries published within it, and an entry with no publication date appears under All only.

Exploit-DB data is provided byExploit-DB (OffSec)and is licensed underGPL-2.0. There is also an Exploit-DB RSS feed.