Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,231cataloged exploits
35,420CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,266GitHub PoC 14,131VulnCheck XDB 8,635Nuclei 4,274Metasploit 3,474✓ verified onlyrecentpopularrisk
22,266 exploits
Referência
CVE-2026-4996
Sinaptik AI PandasAI pandasai-lancedb Extension lancedb.py get_relevant_docs_by_id sql injection
33RISK
open ↗Referência
CVE-2026-4995
wandb OpenUI Window Message Event index.html cross site scripting
33RISK
open ↗Referência
CVE-2026-4994
wandb OpenUI APIStatusError server.py generic_exception_handler information exposure
33RISK
open ↗Referência
CVE-2025-15445
Restaurant Cafeteria <= 0.4.6 - Subscriber+ Arbitrary Plugin Installation/Activation
33RISK
open ↗Referência
CVE-2026-9709
Themeco Cornerstone < 7.8.9 (Premium, bundled with X Theme) - Subscriber+ Arbitrary User Meta Disclosure
41RISK
open ↗Referência
CVE-2018-18777
Directory traversal vulnerability in Microstrategy Web, version 7, in "/WebMstr7/servlet/mstrWeb" (in the parameter subp
43RISK
open ↗Referência
CVE-2018-18777
Directory traversal vulnerability in Microstrategy Web, version 7, in "/WebMstr7/servlet/mstrWeb" (in the parameter subp
43RISK
open ↗Referência
CVE-2018-18795
School Event Management System 1.0 has SQL Injection via the student/index.php or event/index.php id parameter.
23RISK
open ↗Referência
CVE-2018-18795
School Event Management System 1.0 has SQL Injection via the student/index.php or event/index.php id parameter.
23RISK
open ↗Referência
CVE-2018-18797
School Attendance Monitoring System 1.0 has CSRF via /user/user/edit.php.
23RISK
open ↗Referência
CVE-2018-18797
School Attendance Monitoring System 1.0 has CSRF via /user/user/edit.php.
23RISK
open ↗Referência
CVE-2018-18798
Attendance Monitoring System 1.0 has SQL Injection via the 'id' parameter to student/index.php?view=view, event/index.ph
23RISK
open ↗Referência
CVE-2018-18798
Attendance Monitoring System 1.0 has SQL Injection via the 'id' parameter to student/index.php?view=view, event/index.ph
23RISK
open ↗Referência
CVE-2012-3835
Multiple cross-site scripting (XSS) vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 3.
23RISK
open ↗Referência
CVE-2012-3839
Multiple SQL injection vulnerabilities in application/core/MY_Model.php in MyClientBase 0.12 allow remote attackers to e
23RISK
open ↗Referência
CVE-2018-18799
School Attendance Monitoring System 1.0 has CSRF via event/controller.php?action=photos.
23RISK
open ↗Referência
CVE-2018-18799
School Attendance Monitoring System 1.0 has CSRF via event/controller.php?action=photos.
23RISK
open ↗Referência
CVE-2018-18800
The Tubigan "Welcome to our Resort" 1.0 software allows SQL Injection via index.php?p=accomodation&q=[SQL], index.php?p=
23RISK
open ↗Referência
CVE-2018-18800
The Tubigan "Welcome to our Resort" 1.0 software allows SQL Injection via index.php?p=accomodation&q=[SQL], index.php?p=
23RISK
open ↗Referência
CVE-2018-18801
The BSEN Ordering software 1.0 has SQL Injection via student/index.php?view=view&id=[SQL] or index.php?q=single-item&id=
23RISK
open ↗Referência
CVE-2018-18801
The BSEN Ordering software 1.0 has SQL Injection via student/index.php?view=view&id=[SQL] or index.php?q=single-item&id=
23RISK
open ↗Referência
CVE-2018-18803
Curriculum Evaluation System 1.0 allows SQL Injection via the login screen, related to frmCourse.vb and includes/user.vb
23RISK
open ↗Referência
CVE-2018-18805
Point Of Sales 1.0 allows SQL injection via the login screen, related to LoginForm1.vb.
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.