Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,302cataloged exploits
35,469CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,301GitHub PoC 14,141VulnCheck XDB 8,646Nuclei 4,289Metasploit 3,474✓ verified onlyrecentpopularrisk
22,266 exploits
Referência
CVE-2026-5633
assafelovic gpt-researcher ws Endpoint server-side request forgery
33RISK
open ↗Referência
CVE-2013-4694
Stack-based buffer overflow in gen_jumpex.dll in Winamp before 5.64 Build 3418 allows remote attackers to cause a denial
28RISK
open ↗Referência
CVE-2026-5330
SourceCodester/mayuri_k Best Courier Management System User Delete ajax.php access control
33RISK
open ↗Referência
CVE-2026-5328
shsuishang modulithshop ProductItemDao ProductIndexServiceImpl.java listItem sql injection
33RISK
open ↗Referência
CVE-2026-5327
efforthye fast-filesystem-mcp index.ts handleGetDiskUsage command injection
33RISK
open ↗Referência
CVE-2026-5326
SourceCodester Leave Application System User Information index.php authorization
33RISK
open ↗Referência
CVE-2026-5325
SourceCodester Simple Customer Relationship Management System Create Ticket create-ticket.php cross site scripting
33RISK
open ↗Referência
CVE-2026-5259
AutohomeCorp frostmourne Alarm Preview AlarmController.java server-side request forgery
33RISK
open ↗Referência
CVE-2026-5258
Sanster IOPaint File Manager file_manager.py _get_file path traversal
33RISK
open ↗Referência
CVE-2026-5257
code-projects Simple Laundry System Parameter delstaffinfo.php sql injection
33RISK
open ↗Referência
CVE-2026-5256
code-projects Simple Laundry System Parameter modify.php sql injection
33RISK
open ↗Referência
CVE-2026-5152
Tenda CH22 createFileName formCreateFileName stack-based overflow
41RISK
open ↗Referência
CVE-2026-5150
code-projects Accounting System Parameter viewin_costumer.php sql injection
33RISK
open ↗Referência
CVE-2026-5126
SourceCodester RSS Feed Parser file_get_contents server-side request forgery
33RISK
open ↗Referência
CVE-2026-5125
raine consult-llm-mcp server.ts child_process.execSync os command injection
33RISK
open ↗Referência
CVE-2018-9059
Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 7.2 allows remote attackers to execute arbitrary code
60RISK
open ↗Referência
CVE-2018-9155
Cross-site scripting (XSS) vulnerability in Open-AudIT Professional 2.1.1 allows remote attackers to inject arbitrary we
23RISK
open ↗Referência✓ VexDay Proof
Woltlab Burning Board 3.0.x - Blind SQL Injection
SQL injection vulnerability in index.php in WoltLab Burning Board 3.0.3 PL 1 allows remote attackers to execute arbitrar
23RISK
open ↗Referência✓ VexDay Proof
XOOPS Module Classifieds - 'cid' SQL Injection
SQL injection vulnerability in index.php in the jlmZone Classifieds module for XOOPS allows remote attackers to execute
23RISK
open ↗Referência
CVE-2013-5028
SQL injection vulnerability in IT/hardware-list.dll in Kwoksys Kwok Information Server before 2.8.5 allows remote authen
23RISK
open ↗Referência
CVE-2013-5038
The HOT HOTBOX router with software 2.1.11 allows remote attackers to bypass authentication by configuring a source IP a
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.