Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,231cataloged exploits
35,420CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,266GitHub PoC 14,131VulnCheck XDB 8,635Nuclei 4,274Metasploit 3,474✓ verified onlyrecentpopularrisk
22,266 exploits
Referência
CVE-2026-6124
Tenda F451 httpd SafeMacFilter fromSafeMacFilter stack-based overflow
41RISK
open ↗Referência
CVE-2026-6120
Tenda F451 httpd DhcpListClient fromDhcpListClient stack-based overflow
41RISK
open ↗Referência
CVE-2026-6119
AstrBotDevs AstrBot API Endpoint post_data.get server-side request forgery
33RISK
open ↗Referência
CVE-2026-6117
AstrBotDevs AstrBot install-upload Endpoint plugin.py install_plugin_upload sandbox
33RISK
open ↗Referência
CVE-2026-6116
Totolink A7100RU CGI cstecgi.cgi setDiagnosisCfg os command injection
48RISK
open ↗Referência
CVE-2026-6114
Totolink A7100RU CGI cstecgi.cgi setNetworkCfg os command injection
48RISK
open ↗Referência
CVE-2026-6111
FoundationAgents MetaGPT common.py decode_image server-side request forgery
33RISK
open ↗Referência
CVE-2026-6110
FoundationAgents MetaGPT Tree-of-Thought Solver tot.py generate_thoughts code injection
33RISK
open ↗Referência
CVE-2026-6108
1Panel-dev MaxKB Model Context Protocol Node base_mcp_node.py execute os command injection
33RISK
open ↗Referência
CVE-2026-6106
1Panel-dev MaxKB Public Chat static_headers_middleware.py StaticHeadersMiddleware cross site scripting
33RISK
open ↗Referência
CVE-2026-6105
perfree go-fastdfs-web doInstall InstallController.java improper authorization
33RISK
open ↗Referência
CVE-2026-1516
Improper Control of Generation of Code ('Code Injection') in GitLab
33RISK
open ↗Referência
CVE-2017-7293
The Dolby DAX2 and DAX3 API services are vulnerable to a privilege escalation vulnerability that allows a normal user to
23RISK
open ↗Referência
CVE-2010-4273
SQL injection vulnerability in imoveis.php in DescargarVista ACC IMoveis 1.1 allows remote attackers to execute arbitrar
23RISK
open ↗Referência
CVE-2010-4273
SQL injection vulnerability in imoveis.php in DescargarVista ACC IMoveis 1.1 allows remote attackers to execute arbitrar
23RISK
open ↗Referência
CVE-2017-7642
The sudo helper in the HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) before 4.0.21 allows local use
23RISK
open ↗Referência
CVE-2026-7510
OWAP DefectDojo Benchmark/Engagement/Product/Survey authorization
33RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.