Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,107cataloged exploits
34,679CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,692GitHub PoC 13,812VulnCheck XDB 8,460Nuclei 4,233Metasploit 3,467✓ verified onlyrecentpopularrisk
21,692 exploits
Referência
CVE-2026-49494
Xcitium Client Security / Comodo Internet Security Remote Denial of Service
41RISK
open ↗Referência
CVE-2026-11458
erzhongxmu JeeWMS Boot Actuator Endpoint actuator information disclosure
33RISK
open ↗Referência
CVE-2026-11457
erzhongxmu JeeWMS JimuReport test-connection Endpoint testConnection injection
33RISK
open ↗Referência
CVE-2026-11411
iAI Lab PDF AI App chatpdf.pro getExternalCacheDir path traversal
33RISK
open ↗Referência✓ VexDay Proof
FastStone Image Viewer 3.6 - '.BMP' Image Crash
FastStone Image Viewer 3.6 allows user-assisted attackers to cause a denial of service (application crash) via a malform
23RISK
open ↗Referência
CVE-2026-15525
kLOsk adloop write.py _validate_urls server-side request forgery
33RISK
open ↗Referência
CVE-2026-15524
alioshr memory-bank-mcp list-project-files-validation-factory.ts path traversal
33RISK
open ↗Referência
CVE-2026-15523
CodeAstro Simple Online Leave Management System dashboard.php sql injection
33RISK
open ↗Referência
CVE-2026-15522
tugcantopaloglu godot-mcp run_project index.js validatePath path traversal
33RISK
open ↗Referência
CVE-2026-15521
makafeli n8n-workflow-builder update_node_from_file server.cjs path traversal
33RISK
open ↗Referência
CVE-2026-15520
GNU LibreDWG R2004 Section Decompression decode.c decompress_R2004_section heap-based overflow
33RISK
open ↗Referência
CVE-2011-4062
Buffer overflow in the kernel in FreeBSD 7.3 through 9.0-RC1 allows local users to cause a denial of service (panic) or
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component 5starhotels - SQL Injection
Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System (aka HBS) for Joomla! allow remote attack
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component com_allhotels - Blind SQL Injection
Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System (aka HBS) for Joomla! allow remote attack
23RISK
open ↗Referência
CVE-2026-15478
IceHRM UserReport Endpoint EmployeeAttendanceReport.php sql injection
33RISK
open ↗Referência
CVE-2026-15473
Eleveo Call Recording Software Recorded Calls restoreCallAction.do improper authorization
33RISK
open ↗Referência
CVE-2026-15472
Eleveo Call Recording Software composeEmailAction.do improper authorization
33RISK
open ↗Referência✓ VexDay Proof
Joomla! Component com_lowcosthotels - Blind SQL Injection
SQL injection vulnerability in the com_lowcosthotels component in the Hotel Booking Reservation System (aka HBS) for Joo
23RISK
open ↗Referência
CVE-2026-15471
Eleveo Call Recording Software pci_dss_status.jsp improper authorization
33RISK
open ↗Referência
CVE-2026-15311
NousResearch hermes-agent Matrix Adapter matrix.py MatrixAdapter._markdown_to_html cross site scripting
33RISK
open ↗Referência
CVE-2008-5923
SQL injection vulnerability in default.asp in ASP-DEv XM Events Diary allows remote attackers to execute arbitrary SQL c
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.