Exploits
Public exploit and proof-of-concept entries from Exploit-DB, maintained by OffSec, linked to the Common Vulnerabilities and Exposures (CVE) identifiers they target. This page carries metadata and links only, and never hosts or mirrors exploit code: every entry links out to its Exploit-DB page.
| EDB | Published | Title | Type | Platform | Verified | CVEs |
|---|---|---|---|---|---|---|
| EDB-52629 ↗ | 2026-07-08 | Krayin CRM v2.2.x - Authenticated Remote Code Execution | webapps | multiple | — | CVE-2026-38526 |
| EDB-52628 ↗ | 2026-07-08 | Atarim WordPress Plugin 4.2.2 - Sensitive Information Exposure | webapps | multiple | — | CVE-2025-60188 |
| EDB-52627 ↗ | 2026-07-08 | Langflow 1.9.0 - RCE | webapps | multiple | — | CVE-2026-33017 |
| EDB-52626 ↗ | 2026-07-08 | Joomla Page Builder CK 3.5.10 - Arbitrary File Upload | webapps | multiple | — | CVE-2026-56290 |
| EDB-52625 ↗ | 2026-07-07 | MCPJam Inspector - Remote Code Execution | webapps | multiple | — | CVE-2026-23744 |
| EDB-52624 ↗ | 2026-07-07 | ProtonVPN v4.4.1 - Unquoted Service Path | local | windows | — | — |
| EDB-52623 ↗ | 2026-07-07 | Flowise 3.1.3 - arbitrary code execution | webapps | multiple | — | CVE-2026-58057 |
| EDB-52622 ↗ | 2026-07-07 | Hydra - Stack Buffer Overflow | remote | linux | — | CVE-2026-56766 |
| EDB-52621 ↗ | 2026-07-07 | Discuz! X5.0 - Authentication Bypass | webapps | multiple | — | CVE-2026-49952 |
| EDB-52620 ↗ | 2026-07-07 | Tenable Nessus 10.12.1 - SQL Injection | webapps | multiple | — | CVE-2026-57588 |
| EDB-52619 ↗ | 2026-07-07 | WordPress Bricks Builder Theme - RCE | webapps | multiple | — | CVE-2024-25600 |
| EDB-52618 ↗ | 2026-07-07 | iOS Bluetooth PAN Exploit - Ethernet Gateway without Adapter | remote | ios | — | — |
| EDB-52617 ↗ | 2026-07-06 | Joomla Extension 4.1.4 - PHP Object injection | webapps | php | — | CVE-2026-48909 |
| EDB-52616 ↗ | 2026-07-06 | Pulpy 0.1.1-Beta - Filesystem Sandbox Bypass | webapps | multiple | — | CVE-2026-44225 |
| EDB-52615 ↗ | 2026-07-06 | MEmu Android Emulator 9.2.7.0 - Local Privilege Escalation | local | windows | — | CVE-2026-36213 |
| EDB-52614 ↗ | 2026-07-06 | KeepInMind 0.8.4.2 - Stored XSS | webapps | multiple | — | CVE-2026-9271 |
| EDB-52613 ↗ | 2026-07-06 | KNX visualisering - Broken Access Control | webapps | multiple | — | — |
| EDB-52612 ↗ | 2026-07-06 | Windows Defender (MsMpEng.exe) - Race Condition | local | windows | — | — |
| EDB-52611 ↗ | 2026-07-06 | WordPress Plugin WPZOOM Portfolio 1.4.21 - Reflected Cross-Site Scripting (XSS) | webapps | multiple | — | CVE-2026-49069 |
| EDB-52610 ↗ | 2026-06-08 | OpenEMR 7.0.2 - Arbitrary File Read | webapps | multiple | — | CVE-2026-24849 |
| EDB-52609 ↗ | 2026-06-05 | WordPress Contest Gallery 28.1.4 - Unauthenticated Blind SQL Injection | webapps | multiple | — | CVE-2026-3180 |
| EDB-52608 ↗ | 2026-06-01 | Drupal Core 10.5.5 - Error-Based SQL Injection | webapps | php | — | CVE-2026-9082 |
| EDB-52607 ↗ | 2026-06-01 | WordPress OrderConvo 14 - Path Traversal | webapps | multiple | — | CVE-2025-10162 |
| EDB-52606 ↗ | 2026-05-30 | Notepad++ 8.9.6 - Arbitrary Code Execution | remote | windows | — | CVE-2026-48778 |
| EDB-52605 ↗ | 2026-05-30 | YAMCS yamcs-core 5.12.7 - No Rate Limiting | webapps | multiple | — | CVE-2026-44596 |
| EDB-52604 ↗ | 2026-05-30 | YAMCS yamcs-core 5.12.7 - User Enumeration | webapps | multiple | — | CVE-2026-44595 |
| EDB-52603 ↗ | 2026-05-30 | YAMCS yamcs-core 5.12.7 - LDAP Injection | webapps | multiple | — | CVE-2026-42568 |
| EDB-52601 ↗ | 2026-05-29 | Microsoft - NTLMv2 Hash Capture | remote | windows | — | CVE-2026-32202 |
| EDB-52600 ↗ | 2026-05-29 | MikroORM 7.0.13 - SQL Injection | webapps | multiple | — | CVE-2026-44680 |
| EDB-52598 ↗ | 2026-05-29 | Prodigy Commerce 3.3.0 - Local File Inclusion | webapps | multiple | — | CVE-2026-0926 |
| EDB-52597 ↗ | 2026-05-29 | Langflow 1.3.0 - Remote Code Execution | webapps | multiple | — | CVE-2026-0770 |
| EDB-52596 ↗ | 2026-05-29 | Quick Playground for WordPress 1.3.1 - Unauthenticated Remote Code Execution | webapps | multiple | — | CVE-2026-1830 |
| EDB-52595 ↗ | 2026-05-29 | ImageMagick - Infinite Loop in the MIFF decoder can lead to CPU exhaustion | local | multiple | — | CVE-2026-46522 |
| EDB-52594 ↗ | 2026-05-29 | ZTE Routers - Unauthenticated Denial of Service | local | multiple | — | CVE-2026-34473 |
| EDB-52593 ↗ | 2026-05-29 | ZTE ZXHN H188A V6 - Authentication Bypass | local | multiple | — | CVE-2026-34472 |
| EDB-52592 ↗ | 2026-05-29 | ZTE H298A / H108N - Unauthenticated Credential Exposure | local | multiple | — | CVE-2026-34474 |
| EDB-52591 ↗ | 2026-05-29 | Linux Kernel - Local Privilege Escalation | local | linux | — | CVE-2026-43284CVE-2026-43500CVE-2026-46300 |
| EDB-52590 ↗ | 2026-05-29 | MixPHP Framework 2.2.17 - Unsafe Deserialization Remote Code Execution | webapps | php | — | CVE-2026-42471 |
| EDB-52589 ↗ | 2026-05-29 | Wing FTP Server 8.1.3 - Authenticated Remote Code Execution | remote | multiple | — | CVE-2026-44403 |
| EDB-52588 ↗ | 2026-05-29 | CubeCart < 6.7.0 - Reflected Cross-Site Scripting (XSS) (Unauthenticated) | webapps | multiple | — | CVE-2026-44376 |
| EDB-52587 ↗ | 2026-05-29 | strongSwan 5.9.13 - libsimaka EAP-SIM/AKA heap buffer overflow | remote | multiple | — | CVE-2026-35330 |
| EDB-52586 ↗ | 2026-05-29 | strongSwan 5.9.13 - DoS | dos | multiple | — | CVE-2026-35333 |
| EDB-52585 ↗ | 2026-05-27 | Linux Kernel - Local Privilege Escalation | local | linux | — | CVE-2026-43284CVE-2026-43500 |
| EDB-52584 ↗ | 2026-05-27 | Casdoor 3.54.1 - Arbitrary File Write via Path Traversal | webapps | go | — | CVE-2026-6815 |
| EDB-52583 ↗ | 2026-05-27 | EspoCRM 9.3.3 - SSRF | webapps | multiple | — | CVE-2026-33534 |
| EDB-52582 ↗ | 2026-05-27 | scramble - Remote Code Execution | webapps | php | — | CVE-2026-44262 |
| EDB-52581 ↗ | 2026-05-27 | MeiG Smart FORGE_SLT711 - OS Command Injection | hardware | linux | — | CVE-2026-36356 |
| EDB-52580 ↗ | 2026-05-27 | Realtek rtl819x - Local Privilege | local | linux | — | CVE-2026-36355 |
| EDB-52579 ↗ | 2026-05-27 | OpenCATS 0.9.7.4 - SQL Injection | webapps | multiple | — | — |
| EDB-52578 ↗ | 2026-05-26 | Grav CMS 2.0.0-beta.2 - Remote Code Execution | webapps | php | — | CVE-2026-42607 |
| EDB-52577 ↗ | 2026-05-26 | Apache HTTP Server 2.4.66 - 'mod_http2' Double-Free Denial of Service | webapps | multiple | — | CVE-2026-23918 |
| EDB-52576 ↗ | 2026-05-26 | D-Link DSL2600U - 'rom-0' Admin Password Disclosure | hardware | multiple | — | — |
| EDB-52575 ↗ | 2026-05-26 | Wordpress Temporary Login Plugin 1.0.0 - 'temp-login-token' Authentication Bypass to Account Takeover | webapps | multiple | — | CVE-2026-7567 |
| EDB-52574 ↗ | 2026-05-26 | cPanel - CRLF Injection | webapps | php | — | CVE-2026-41940 |
| EDB-52573 ↗ | 2026-05-26 | Linux Kernel 6.8 - Local Privilege Escalation | local | linux | — | — |
| EDB-52572 ↗ | 2026-05-21 | Cockpit 359 - RCE | webapps | multiple | — | CVE-2026-4631 |
| EDB-52571 ↗ | 2026-05-21 | BookStack 25.12.1 - Denial of Service | webapps | multiple | — | — |
| EDB-52570 ↗ | 2026-05-21 | Lenovo LegionSpace 1.7.11.2 - 'DAService' Unquoted Service Path | local | windows | — | — |
| EDB-52569 ↗ | 2026-05-21 | solaredge - (CSRF-OOB-Injection) | webapps | multiple | — | — |
| EDB-52568 ↗ | 2026-05-21 | FUXA 1.2.9 - RCE | webapps | multiple | — | CVE-2026-25895 |
| EDB-52567 ↗ | 2026-05-15 | Windows Snipping Tool - NTLMv2 Hash Hijack | local | windows | — | CVE-2026-33829 |
| EDB-52566 ↗ | 2026-05-15 | Remote Sunrise Helper for Windows 2026.14 - Unauthenticated File/Directory Listing | local | windows | — | — |
| EDB-52565 ↗ | 2026-05-15 | Remote Sunrise Helper for Windows 2026.14 - Remote Code Execution | local | windows | — | — |
| EDB-52564 ↗ | 2026-05-14 | WordPress Plugin Supsystic Contact Form 1.7.36 - SSTI | webapps | multiple | — | CVE-2026-4257 |
| EDB-52563 ↗ | 2026-05-14 | Apache HertzBeat 1.8.0 - Remote Code Execution | webapps | multiple | — | — |
| EDB-52562 ↗ | 2026-05-14 | ePati Antikor NGFW 2.0.1301 - Authentication Bypass | webapps | multiple | — | CVE-2026-2624 |
| EDB-52561 ↗ | 2026-05-14 | PJPROJECT 2.16 - Heap Bufferoverflow | webapps | multiple | — | CVE-2026-25994 |
| EDB-52560 ↗ | 2026-05-13 | Ninja Forms Uploads - Unauthenticated PHP File Upload | webapps | multiple | — | CVE-2026-0740 |
| EDB-52559 ↗ | 2026-05-13 | glances 4.5.2 - command injection | webapps | multiple | — | CVE-2026-33641 |
| EDB-52558 ↗ | 2026-05-13 | coreruleset 4.21.0 - Firewall Bypass | webapps | multiple | — | CVE-2026-21876 |
| EDB-52557 ↗ | 2026-05-13 | Flowise < 3.0.5 - Missing Authentication for Critical Function | webapps | typescript | — | CVE-2025-58434 |
| EDB-52556 ↗ | 2026-05-07 | telnetd 2.7 - Buffer Overflow | remote | multiple | — | CVE-2026-32746 |
| EDB-52555 ↗ | 2026-05-07 | Ghost CMS 6.19.0 - SQLi | webapps | multiple | — | CVE-2026-26980 |
| EDB-52554 ↗ | 2026-05-07 | LuaJIT 2.1.1774638290 - Arbitrary Code Execution | webapps | multiple | — | — |
| EDB-52553 ↗ | 2026-05-07 | Bludit CMS 3.18.4 - RCE | webapps | multiple | — | CVE-2026-25099 |
| EDB-52552 ↗ | 2026-05-07 | NocoBase 2.0.27 - VM Sandbox Escape | local | multiple | — | CVE-2026-34156 |
| EDB-52551 ↗ | 2026-05-07 | ThingsBoard IoT Platform 4.2.0 - Server-Side Request Forgery (SSRF) | webapps | multiple | — | CVE-2025-34282 |
| EDB-52550 ↗ | 2026-05-04 | Linux Kernel proc_readdir_de() 6.18-rc5 - Local Privilege Escalation | local | linux | — | CVE-2025-40271 |
| EDB-52549 ↗ | 2026-05-04 | Linux nf_tables 6.19.3 - Local Privilege Escalation | local | linux | — | CVE-2026-23231 |
| EDB-52548 ↗ | 2026-05-04 | Linksys E1200 2.0.04 - Authenticated Stack Buffer Overflow (RCE) | hardware | multiple | — | CVE-2025-60690 |
| EDB-52547 ↗ | 2026-05-04 | MindsDB 25.9.1.1 - Path Traversal | webapps | multiple | — | CVE-2026-27483 |
| EDB-52546 ↗ | 2026-05-04 | Windows 11 24H2 - Local Privilege Escalation | local | windows | — | CVE-2026-21250 |
| EDB-52545 ↗ | 2026-05-04 | Traccar GPS Tracking System 6.11.1 - Cross-Site WebSocket Hijacking (CSWSH) | webapps | multiple | — | CVE-2025-68930 |
| EDB-52544 ↗ | 2026-04-30 | FUXA 1.2.8 - Authentication Bypass + RCE Exploit | webapps | multiple | — | CVE-2025-69985 |
| EDB-52543 ↗ | 2026-04-30 | Python-Multipart 0.0.22 - Path Traversal | webapps | python | — | CVE-2026-24486 |
| EDB-52542 ↗ | 2026-04-30 | Google Chrome 145.0.7632.75 - CSSFontFeatureValuesMap | local | multiple | — | CVE-2026-2441 |
| EDB-52541 ↗ | 2026-04-30 | Windows 11 23H2 - Denial of Service (DoS) | local | windows | — | CVE-2025-47987 |
| EDB-52540 ↗ | 2026-04-30 | Repetier-Server 1.4.10 - Path Traversal | webapps | multiple | — | CVE-2026-26335 |
| EDB-52539 ↗ | 2026-04-30 | HUSTOJ Zip-Slip v26.01.24 - RCE | webapps | multiple | — | CVE-2026-24479 |
| EDB-52538 ↗ | 2026-04-30 | BusyBox 1.37.0 - Path Traversal | webapps | multiple | — | CVE-2026-26157 |
| EDB-52537 ↗ | 2026-04-30 | Windows 11 25H2 - Heap Overflow | local | windows | — | CVE-2026-21244CVE-2026-21248 |
| EDB-52536 ↗ | 2026-04-30 | JUNG Smart Visu Server 1.1.1050 - Dos | webapps | multiple | — | CVE-2026-26235 |
| EDB-52535 ↗ | 2026-04-30 | SumatraPDF 3.5.2 - Remote Code Execution | webapps | multiple | — | CVE-2026-25961 |
| EDB-52534 ↗ | 2026-04-30 | NiceGUI 3.6.1 - Path Traversal | webapps | multiple | — | CVE-2026-25732 |
| EDB-52533 ↗ | 2026-04-30 | Frigate NVR 0.16.3 - Remote Code Execution | webapps | multiple | — | CVE-2026-25643 |
| EDB-52532 ↗ | 2026-04-30 | Js2Py 0.74 - RCE | webapps | multiple | — | CVE-2024-28397 |
| EDB-52531 ↗ | 2026-04-30 | Camaleon CMS v2.9.0 - Path Traversal | webapps | multiple | — | CVE-2024-46987 |
| EDB-52530 ↗ | 2026-04-30 | Cybersecurity AI (CAI) Framework 0.5.10 - Command Injection | webapps | multiple | — | — |
| EDB-52529 ↗ | 2026-04-30 | Erugo 0.2.14 - Remote Code Execution (RCE) | webapps | multiple | — | CVE-2026-24897 |
| EDB-52528 ↗ | 2026-04-30 | deephas 1.0.7 - Prototype Pollution | webapps | multiple | — | CVE-2026-25047 |
About this data
Entries come from the Exploit-DB metadata index, maintained by OffSec. This page tracks metadata and links only: the title, publication date, exploit type, target platform, Exploit-DB's own verification flag, and the CVE identifiers each entry references. It never hosts, mirrors, or links to exploit code directly; the EDB column links to the entry's page on Exploit-DB, where the metadata and any code live. A CVE this tracker follows is a link into the vulnerabilities table; an untracked CVE is shown as plain text. The Verified badge is Exploit-DB's flag, not a verification by this tracker. The published-date window filters the same way the vulnerabilities view does: a segment shows only entries published within it, and an entry with no publication date appears under All only.
Exploit-DB data is provided byExploit-DB (OffSec)and is licensed underGPL-2.0. There is also an Exploit-DB RSS feed.