Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,020cataloged exploits
35,276CVEs with public exploitation
24,695lab-tested
22,166 exploits
Referência
CVE-2026-5106
code-projects Exam Form Submission update_fst.php cross site scripting
33RISK
open
Referência
CVE-2026-5105
Totolink A3300R Parameter cstecgi.cgi setVpnPassCfg command injection
33RISK
open
Referência
CVE-2026-5104
Totolink A3300R cstecgi.cgi setStaticRoute command injection
33RISK
open
Referência
CVE-2026-5103
Totolink A3300R cstecgi.cgi setUPnPCfg command injection
33RISK
open
Referência
CVE-2026-5102
Totolink A3300R Parameter cstecgi.cgi setSmartQosCfg command injection
33RISK
open
Referência
CVE-2026-2370
Improper Handling of Parameters in GitLab
41RISK
open
Referência
CVE-2026-5101
Totolink A3300R Parameter cstecgi.cgi setLanCfg command injection
33RISK
open
Referência
CVE-2026-5046
Tenda FH1201 Parameter WrlExtraSet formWrlExtraSet stack-based overflow
41RISK
open
Referência
CVE-2026-5045
Tenda FH1201 Parameter WrlclientSet stack-based overflow
41RISK
open
Referência
CVE-2026-4973
SourceCodester Online Quiz System add-question.php cross site scripting
33RISK
open
Referência
CVE-2026-4972
code-projects Online Reviewer System btn_functions.php cross site scripting
33RISK
open
Referência
CVE-2026-4971
SourceCodester Note Taking App cross-site request forgery
33RISK
open
Referência
CVE-2026-4970
code-projects Social Networking Site Endpoint delete_photos.php sql injection
33RISK
open
Referência
CVE-2026-4969
code-projects Social Networking Site Alert home.php cross site scripting
33RISK
open
Referência
CVE-2026-4968
SourceCodester Diary App diary.php cross-site request forgery
33RISK
open
Referência
CVE-2026-4966
itsourcecode Free Hotel Reservation System index.php sql injection
33RISK
open
Referência
CVE-2026-4965
letta-ai letta Incomplete Fix CVE-2025-6101 ast_parsers.py resolve_type eval injection
33RISK
open
Referência
CVE-2026-4964
letta-ai letta File URL message_helper.py _convert_message_create_to_message server-side request forgery
33RISK
open
Referência
CVE-2026-4963
huggingface smolagents Incomplete Fix CVE-2025-9959 local_python_executor.py evaluate_with code injection
33RISK
open
Referência
CVE-2026-4962
UltraVNC Service version.dll uncontrolled search path
41RISK
open
Referência
CVE-2026-4961
Tenda AC6 POST Request QuickIndex formQuickIndex stack-based overflow
41RISK
open
Referência
CVE-2026-4960
Tenda AC6 POST Request WizardHandle fromWizardHandle stack-based overflow
41RISK
open
Referência
CVE-2026-4959
OpenBMB XAgent ShareServer WebSocket Endpoint share.py check_user missing authentication
33RISK
open
Referência
CVE-2026-4958
OpenBMB XAgent WebSocket Endpoint replayer.py ReplayServer.send_data authorization
28RISK
open
Referência
CVE-2026-4957
OpenBMB XAgent API Key function_handler.py FunctionHandler.handle_tool_call log file
33RISK
open
Referência
CVE-2026-4956
Shenzhen Ruiming Technology Streamax Crocus Parameter DevicePrint.do sql injection
33RISK
open
Referência
CVE-2026-4955
Shenzhen Ruiming Technology Streamax Crocus OperateStatistic.do sql injection
33RISK
open
Referência
CVE-2026-4954
mingSoft MCMS Web Content List Endpoint ContentAction.java list sql injection
33RISK
open
Referência
CVE-2026-4953
mingSoft MCMS Editor Endpoint BaseAction.java catchImage server-side request forgery
33RISK
open
Referência
CVE-2026-4910
Shenzhen Ruiming Technology Streamax Crocus Endpoint RemoteFormat.do sql injection
33RISK
open
previouspage 384 / 739next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.