Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,302cataloged exploits
35,469CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,301GitHub PoC 14,141VulnCheck XDB 8,646Nuclei 4,289Metasploit 3,474✓ verified onlyrecentpopularrisk
22,266 exploits
Referência
CVE-2018-25346
WordPress Form Maker Plugin 1.12.24 SQL Injection via admin-ajax.php
41RISK
open ↗Referência
CVE-2026-7553
code-projects Gym Management System edit_exercises.php sql injection
33RISK
open ↗Referência
CVE-2026-7550
SourceCodester Pharmacy Sales and Inventory System ajax.php save_customer sql injection
33RISK
open ↗Referência
CVE-2026-7549
SourceCodester Pharmacy Sales and Inventory System ajax.php delete_customer sql injection
33RISK
open ↗Referência
CVE-2018-25312
LifeSize ClearSea 3.1.4 Directory Traversal Remote Code Execution
41RISK
open ↗Referência
CVE-2018-25308
BuddyPress Xprofile Custom Fields Type 2.6.3 Arbitrary File Deletion
41RISK
open ↗Referência
CVE-2026-7117
code-projects Employee Management System approve.php sql injection
33RISK
open ↗Referência
CVE-2026-7116
code-projects Employee Management System mark.php cross site scripting
33RISK
open ↗Referência
CVE-2026-7115
code-projects Employee Management System delete.php sql injection
33RISK
open ↗Referência✓ VexDay Proof
PHP-Fusion Mod TI - 'id' SQL Injection
SQL injection vulnerability in blog.php in the Team Impact TI Blog System mod for PHP-Fusion allows remote attackers to
23RISK
open ↗Referência
CVE-2019-3398
Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote at
100RISK
open ↗Referência
CVE-2026-15377
Eleveo Call Recording Software sendlogfile improper authorization
33RISK
open ↗Referência
CVE-2026-15376
Eleveo Call Recording Software statisticReportAction.do improper authorization
33RISK
open ↗Referência
CVE-2026-15375
Eleveo Call Recording Software LDAP User users_ldap.jsp improper authorization
33RISK
open ↗Referência
CVE-2026-15374
Eleveo Call Recording Software Group roleAddAction.do improper authorization
33RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.