Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,231cataloged exploits
35,420CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,266GitHub PoC 14,131VulnCheck XDB 8,635Nuclei 4,274Metasploit 3,474✓ verified onlyrecentpopularrisk
22,266 exploits
Referência
CVE-2026-7028
CodeAstro Online Job Portal All Jobs delete-jobs.php sql injection
33RISK
open ↗Referência
CVE-2026-7025
Typecho Ping Back Service Endpoint Service.php sendPingHandle server-side request forgery
33RISK
open ↗Referência
CVE-2018-13405
The inode_init_owner function in fs/inode.c in the Linux kernel through 3.16 allows local users to create files with an
23RISK
open ↗Referência
CVE-2026-8234
EFM ipTIME A8004T WifiBasicSet formWifiBasicSet stack-based overflow
41RISK
open ↗Referência
CVE-2026-8231
CodeAstro Online Catering Ordering System deleteorder.php sql injection
33RISK
open ↗Referência✓ VexDay Proof
WebCalendar 1.2.4 - Remote Code Execution
install/index.php in WebCalendar before 1.2.5 allows remote attackers to execute arbitrary code via the form_single_user
60RISK
open ↗Referência
CVE-2026-7582
AcademySoftwareFoundation OpenImageIO DDS Image ddsinput.cpp out-of-bounds write
33RISK
open ↗Referência
CVE-2026-7144
1000 Projects Portfolio Management System MCA update_passwd_process.php authorization
33RISK
open ↗Referência
CVE-2026-7581
alexta69 MeTube CORS Policy main.py on_prepare cross-domain policy
33RISK
open ↗Referência
CVE-2026-7578
MacCMS Pro Plugin Installation add.html install unrestricted upload
33RISK
open ↗Referência
CVE-2026-6623
BichitroGan ISP Billing Software Profile users-view cross site scripting
33RISK
open ↗Referência
CVE-2026-6622
BichitroGan ISP Billing Software Customer edit cross site scripting
33RISK
open ↗Referência
CVE-2026-6620
SonicCloudOrg sonic-server File Upload Endpoint FileTool.java upload path traversal
33RISK
open ↗Referência
CVE-2026-6619
langgenius dify ImagePreview image-preview.tsx openInNewTab cross site scripting
33RISK
open ↗Referência
CVE-2026-6618
langgenius dify ApiBasedToolSchemaParser parser.py parse_openai_plugin_json_to_tool_bundle server-side request forgery
33RISK
open ↗Referência
CVE-2026-6616
TransformerOptimus SuperAGI WebScraperTool webpage_extractor.py extract_with_lxml server-side request forgery
33RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.