Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,302cataloged exploits
35,469CVEs with public exploitation
24,695lab-tested
22,266 exploits
Referência
CVE-2026-16534
Import and export users and customers < 2.4.2 - Custom Role Privilege Escalation to Administrator via CSV Import
48RISK
open
Referência
CVE-2026-63087
Grafana OnCall 1.16.11 Unauthenticated Token Hijack via Plugin Install Endpoint
48RISK
open
Referência
CVE-2026-63086
text-generation-inference 3.3.7 SSRF via fetch_image in multimodal chat completions
33RISK
open
Referência
CVE-2026-63085
Axelor Open Platform 8.x < 8.2.2 Authorization Bypass via Nested Relational Record Persistence
41RISK
open
Referência
CVE-2026-63082
Perfect Support Ticketing System 1.7 Broken Access Control via Agent Assignment
33RISK
open
Referência
CVE-2026-63081
Perfect Support Ticketing System 1.7 Stored XSS via Ticket Notes Field
33RISK
open
Referência
CVE-2026-12978
FunnelKit < 3.15.0.6 - Reflected XSS via Divi Optin Form
41RISK
open
Referência
CVE-2026-12907
RTMKit Addons for Elementor < 2.0.9 - Author+ Site-Wide Theme Builder Template Creation and Activation
28RISK
open
Referência
CVE-2026-12906
RTMKit Addons for Elementor < 2.0.9 - Contributor+ Private Post Title Disclosure
28RISK
open
Referência
CVE-2026-15749
mastergo-design mastergo-magic-mcp mcp__C2d get-c2d.ts execute path traversal
33RISK
open
Referência
CVE-2026-58475
Sustainable Irrigation Platform 5.2.16 Stored XSS via Program Name
33RISK
open
Referência
CVE-2026-11563
Word Count and Social Shares <= 1.0 - Subscriber+ Arbitrary File Deletion via Path Traversal
48RISK
open
Referência
CVE-2025-15665
BEAF < 4.7.1 - Admin+ Stored XSS via Widget Shortcode Field
33RISK
open
Referência
CVE-2026-15622
poco-ai poco-claw Workspace API workspace.py get_workspace_file authorization
33RISK
open
Referência
CVE-2026-15622
poco-ai poco-claw Workspace API workspace.py get_workspace_file authorization
33RISK
open
Referência
CVE-2026-15620
mosaxiv clawlet tool_web_fetch.go tools.webFetch server-side request forgery
33RISK
open
Referência
CVE-2026-15619
mosaxiv clawlet IPv4 tool_web_fetch.go web_fetch server-side request forgery
33RISK
open
Referência
CVE-2026-15607
tanstack db Alias Path select.ts select prototype pollution
33RISK
open
Referência
CVE-2026-62239
FlashAttention Symlink Attack via tarfile.extractall in hopper/setup.py
33RISK
open
Referência
CVE-2026-15546
Shibby Tomato start_jffs2 sub_2D568 os command injection
33RISK
open
Referência
CVE-2026-15545
Shibby Tomato apcupsd tomatodata.cgi main out-of-bounds write
41RISK
open
Referência
CVE-2026-15544
Shibby Tomato apcupsd tomatodata.cgi getupsvar stack-based overflow
41RISK
open
Referência
CVE-2026-12397
WP Job Portal < 2.5.5 - Subscriber+ Employer Email Disclosure via IDOR
33RISK
open
Referência
CVE-2026-15535
AkariAsai self-rag retrieval_lm index.py Indexer.deserialize_from deserialization
33RISK
open
Referência
CVE-2026-15531
yashbhalgat HashNeRF-pytorch Checkpoint File run_nerf.py torch.load deserialization
33RISK
open
Referência
CVE-2026-15530
WuzhiCMS Attachment API index.php listimage information disclosure
33RISK
open
Referência
CVE-2026-15527
better-auth better-icons scan_project_icons/sync_icon path traversal
33RISK
open
Referência
CVE-2026-15526
augmnt augments-mcp-server scan_project_deps scan-project-deps.ts scanProjectDeps path traversal
33RISK
open
Referência
CVE-2026-15525
kLOsk adloop write.py _validate_urls server-side request forgery
33RISK
open
Referência
CVE-2026-15524
alioshr memory-bank-mcp list-project-files-validation-factory.ts path traversal
33RISK
open
previouspage 464 / 743next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.