Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,151cataloged exploits
35,370CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,233GitHub PoC 14,119VulnCheck XDB 8,617Nuclei 4,257Metasploit 3,474✓ verified onlyrecentpopularrisk
22,232 exploits
Referência
CVE-2026-41460
SocialEngine <= 7.8.0 SQL Injection via activity/index/get-memberall
48RISK
open ↗Referência✓ VexDay Proof
Absolute NewsLetter 6.1 - Insecure Cookie Handling
Xigla Software Absolute Newsletter 6.0 and 6.1 allows remote attackers to bypass authentication and gain administrative
23RISK
open ↗Referência✓ VexDay Proof
Absolute Content Rotator 6.0 - Insecure Cookie Handling
Absolute Content Rotator 6.0 allows remote attackers to bypass authentication and gain administrative access by setting
23RISK
open ↗Referência✓ VexDay Proof
Absolute Live Support 5.1 - Insecure Cookie Handling
Xigla Software Absolute Live Support .NET 5.1 allows remote attackers to bypass authentication and gain administrative a
23RISK
open ↗Referência✓ VexDay Proof
merlix educate servert - Authentication Bypass / File Disclosure
Merlix Educate Server allows remote attackers to bypass intended security restrictions and obtain sensitive information
23RISK
open ↗Referência✓ VexDay Proof
merlix educate servert - Authentication Bypass / File Disclosure
Merlix Educate Server stores db.mdb under the web root with insufficient access control, which allows remote attackers t
23RISK
open ↗Referência✓ VexDay Proof
Active Web Mail 4 - Blind SQL Injection
SQL injection vulnerability in Active Web Mail 4.0 allows remote attackers to execute arbitrary SQL commands via the Tab
23RISK
open ↗Referência✓ VexDay Proof
ASPSiteWare Automotive Dealer 1.0/2.0 - SQL Injection
Multiple SQL injection vulnerabilities in ASP SiteWare autoDealer 1 and 2 allow remote attackers to execute arbitrary SQ
23RISK
open ↗Referência
CVE-2010-4721
SQL injection vulnerability in news.php in Immo Makler allows remote attackers to execute arbitrary SQL commands via the
23RISK
open ↗Referência
CVE-2017-9810
There are no Anti-CSRF tokens in any forms on the web interface in Kaspersky Anti-Virus for Linux File Server before Mai
23RISK
open ↗Referência
CVE-2017-9810
There are no Anti-CSRF tokens in any forms on the web interface in Kaspersky Anti-Virus for Linux File Server before Mai
23RISK
open ↗Referência
CVE-2017-9822
DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code e
100RISK
open ↗Referência
CVE-2026-7213
ef10007 MLOps_MCP save_file Tool fastmcp_server.py path traversal
33RISK
open ↗Referência
CVE-2026-7211
dvladimirov MCP Git Search API mcp_server.py GitSearchRequest command injection
33RISK
open ↗Referência
CVE-2026-7204
Totolink A8000RU CGI cstecgi.cgi setPptpServerCfg os command injection
48RISK
open ↗Referência
CVE-2026-7203
Totolink A8000RU CGI cstecgi.cgi setUrlFilterRules os command injection
48RISK
open ↗Referência
CVE-2026-38651
Authentication Bypass vulnerability exists in Netmaker versions prior to 1.5.0. The VerifyHostToken function in logic/jw
41RISK
open ↗Referência
CVE-2026-7202
Totolink A8000RU CGI cstecgi.cgi setWiFiWpsStart os command injection
48RISK
open ↗Referência
CVE-2026-7146
AlejandroArciniegas mcp-data-vis HTTP Request server.js axios server-side request forgery
33RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.