Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,151cataloged exploits
35,370CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,233GitHub PoC 14,119VulnCheck XDB 8,617Nuclei 4,257Metasploit 3,474✓ verified onlyrecentpopularrisk
22,233 exploits
Referência
CVE-2018-0752
The Windows Kernel API in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709
23RISK
open ↗Referência
CVE-2018-0823
The Named Pipe File System in Windows 10 version 1709 and Windows Server, version 1709 allows an elevation of privilege
23RISK
open ↗Referência
CVE-2026-5803
bigsk1 openai-realtime-ui API Proxy Endpoint server.js server-side request forgery
33RISK
open ↗Referência
CVE-2026-4338
ActivityPub Routing < 8.0.2 - Unauthenticated Drafts/Scheduled/Pending Posts Disclosure
41RISK
open ↗Referência
CVE-2026-5741
suvarchal docker-mcp-server HTTP index.ts pull_image os command injection
33RISK
open ↗Referência
CVE-2018-0838
Microsoft Edge and ChakraCore in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remot
35RISK
open ↗Referência
CVE-2018-0860
Microsoft Edge and ChakraCore in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remot
35RISK
open ↗Referência
CVE-2018-0897
The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Serve
23RISK
open ↗Referência
CVE-2024-14032
Twitch Studio LauncherHelper XPC Missing Authorization to Root File Write
41RISK
open ↗Referência
CVE-2026-5666
code-projects Online FIR System SQL Database Backup File complaints.sql sensitive information
33RISK
open ↗Referência
CVE-2026-5665
code-projects Online FIR System Login checklogin.php sql injection
33RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.