Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,231cataloged exploits
35,420CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,266GitHub PoC 14,131VulnCheck XDB 8,635Nuclei 4,274Metasploit 3,474✓ verified onlyrecentpopularrisk
22,266 exploits
Referência
CVE-2026-5971
FoundationAgents MetaGPT XML action_node.py ActionNode.xml_fill eval injection
33RISK
open ↗Referência
CVE-2026-5847
code-projects Movie Ticketing System SQL Database Backup File moviedb.sql information disclosure
33RISK
open ↗Referência
CVE-2026-5844
D-Link DIR-882 HNAP1 SetNetworkSettings prog.cgi sprintf os command injection
41RISK
open ↗Referência
CVE-2026-5840
PHPGurukul News Portal Project check_availability.php sql injection
33RISK
open ↗Referência
CVE-2026-5836
code-projects Online Shoe Store admin_product.php cross site scripting
33RISK
open ↗Referência
CVE-2026-5835
code-projects Online Shoe Store admin_football.php cross site scripting
33RISK
open ↗Referência
CVE-2026-5834
code-projects Online Shoe Store admin_running.php cross site scripting
33RISK
open ↗Referência
CVE-2026-5833
awwaiid mcp-server-taskwarrior index.ts server.setRequestHandler command injection
33RISK
open ↗Referência✓ VexDay Proof
jPORTAL 2.3.1 - 'articles.php' SQL Injection
SQL injection vulnerability in articles.php in JPortal 2.3.1 and earlier allows remote attackers to execute arbitrary SQ
23RISK
open ↗Referência
CVE-2018-6585
SQL Injection exists in the JTicketing 2.0.16 component for Joomla! via a view=events action with a filter_creator or fi
23RISK
open ↗Referência
CVE-2018-6604
SQL Injection exists in the Zh YandexMap 6.2.1.0 component for Joomla! via the id parameter in a task=getPlacemarkDetail
23RISK
open ↗Referência
CVE-2018-6606
An issue was discovered in MalwareFox AntiMalware 2.74.0.150. Improper access control in zam32.sys and zam64.sys allows
23RISK
open ↗Referência
Joomla! Component JSP Tickets 1.1 - SQL Injection
SQL Injection exists in the JSP Tickets 1.1 component for Joomla! via the ticketcode parameter in a ticketlist edit acti
23RISK
open ↗Referência
CVE-2011-0420
The grapheme_extract function in the Internationalization extension (Intl) for ICU for PHP 5.3.5 allows context-dependen
28RISK
open ↗Referência
CVE-2021-4473
Tianxin Internet Behavior Management System Command Injection via toQuery.php
48RISK
open ↗Referência
CVE-2026-22666
Dolibarr ERP/CRM < 23.0.2 Authenticated RCE via dol_eval_standard()
46RISK
open ↗Referência
CVE-2026-1900
Link Whisper Free < 0.9.1 - Unauthenticated Settings and User Meta Update
33RISK
open ↗Referência
CVE-2025-15611
Popup Box AYS Pro < 5.5.0 - Admin+ Stored Cross-Site Scripting (XSS) via CSRF
33RISK
open ↗Referência
CVE-2026-5719
itsourcecode Construction Management System borrowedtool.php sql injection
33RISK
open ↗Referência
CVE-2026-5692
Totolink A7100RU cstecgi.cgi setGameSpeedCfg os command injection
33RISK
open ↗Referência
CVE-2018-6755
True Key (TK) Windows Client - Weak Directory Permission Vulnerability
41RISK
open ↗Referência✓ VexDay Proof
project alumni 1.0.9 - Cross-Site Scripting / SQL Injection
Multiple cross-site scripting (XSS) vulnerabilities in project alumni 1.0.9 and earlier allow remote attackers to inject
23RISK
open ↗Referência
CVE-2018-6756
True Key (TK) Windows Client - Authentication Abuse vulnerability
41RISK
open ↗Referência
CVE-2018-6888
An issue was discovered in Typesetter 5.1. The User Permissions page (aka Admin/Users) suffers from critical flaw of Cro
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.