Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,231cataloged exploits
35,420CVEs with public exploitation
24,695lab-tested
22,266 exploits
Referência
CVE-2026-7855
D-Link DI-8100 HTTP Request tggl.asp tggl_asp buffer overflow
41RISK
open
Referência
CVE-2026-6124
Tenda F451 httpd SafeMacFilter fromSafeMacFilter stack-based overflow
41RISK
open
Referência
CVE-2026-6123
Tenda F451 httpd addressNat fromAddressNat stack-based overflow
41RISK
open
Referência
CVE-2026-6122
Tenda F451 httpd L7Prot frmL7ProtForm stack-based overflow
41RISK
open
Referência
CVE-2026-6121
Tenda F451 httpd WrlclientSet stack-based overflow
41RISK
open
Referência
CVE-2026-6120
Tenda F451 httpd DhcpListClient fromDhcpListClient stack-based overflow
41RISK
open
Referência
CVE-2026-6119
AstrBotDevs AstrBot API Endpoint post_data.get server-side request forgery
33RISK
open
Referência
CVE-2026-6117
AstrBotDevs AstrBot install-upload Endpoint plugin.py install_plugin_upload sandbox
33RISK
open
Referência
CVE-2026-6116
Totolink A7100RU CGI cstecgi.cgi setDiagnosisCfg os command injection
48RISK
open
Referência
CVE-2026-6115
Totolink A7100RU CGI cstecgi.cgi setAppCfg os command injection
48RISK
open
Referência
CVE-2026-6114
Totolink A7100RU CGI cstecgi.cgi setNetworkCfg os command injection
48RISK
open
Referência
CVE-2026-6111
FoundationAgents MetaGPT common.py decode_image server-side request forgery
33RISK
open
Referência
CVE-2026-6110
FoundationAgents MetaGPT Tree-of-Thought Solver tot.py generate_thoughts code injection
33RISK
open
Referência
CVE-2026-6108
1Panel-dev MaxKB Model Context Protocol Node base_mcp_node.py execute os command injection
33RISK
open
Referência
CVE-2026-6106
1Panel-dev MaxKB Public Chat static_headers_middleware.py StaticHeadersMiddleware cross site scripting
33RISK
open
Referência
CVE-2026-6105
perfree go-fastdfs-web doInstall InstallController.java improper authorization
33RISK
open
Referência
CVE-2025-9484
Missing Authorization in GitLab
33RISK
open
Referência
CVE-2026-1092
Improper Validation of Specified Quantity in Input in GitLab
41RISK
open
Referência
CVE-2026-1101
Improper Validation of Specified Quantity in Input in GitLab
33RISK
open
Referência
CVE-2026-1516
Improper Control of Generation of Code ('Code Injection') in GitLab
33RISK
open
Referência
CVE-2026-1752
Incorrect Authorization in GitLab
33RISK
open
Referência
CVE-2026-2104
Authorization Bypass Through User-Controlled Key in GitLab
33RISK
open
Referência
CVE-2026-2619
Incorrect Authorization in GitLab
33RISK
open
Referência
CVE-2017-7293
The Dolby DAX2 and DAX3 API services are vulnerable to a privilege escalation vulnerability that allows a normal user to
23RISK
open
Referência
CVE-2010-4273
SQL injection vulnerability in imoveis.php in DescargarVista ACC IMoveis 1.1 allows remote attackers to execute arbitrar
23RISK
open
Referência
CVE-2010-4273
SQL injection vulnerability in imoveis.php in DescargarVista ACC IMoveis 1.1 allows remote attackers to execute arbitrar
23RISK
open
Referência
CVE-2017-7642
The sudo helper in the HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) before 4.0.21 allows local use
23RISK
open
Referência
CVE-2026-7510
OWAP DefectDojo Benchmark/Engagement/Product/Survey authorization
33RISK
open
Referência
CVE-2026-7508
Bootstrap CMS Page Creation show.blade.php code injection
33RISK
open
Referência
CVE-2026-7506
SourceCodester Hotel Management System check sql injection
33RISK
open
previouspage 444 / 743next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.