Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,302cataloged exploits
35,469CVEs with public exploitation
24,695lab-tested
22,301 exploits
Referência
CVE-2026-19008
mf-yang openclaw-cn apply_patch Tool sandbox-paths.ts assertNoSymlinkEscape link following
33RISK
open
Referência
CVE-2026-19007
mf-yang openclaw-cn reply-elevated.ts isApprovedElevatedSender privileges management
33RISK
open
Referência
CVE-2026-14204
Google Authenticator < 0.56 - 2FA Secret Overwrite via CSRF
33RISK
open
Referência
CVE-2026-67599
ClearOS 7.9 OS Command Injection via Log Viewer filter parameter
41RISK
open
Referência
CVE-2026-18593
vxcontrol PentAGI Tool Management Protocol pentester.tmpl sandbox
33RISK
open
Referência
CVE-2026-18592
osCommerce Email Template Configuration EmailController.php EmailController sql injection
33RISK
open
Referência
CVE-2026-18591
Meesho Online Shopping App com.meesho.supply cleartext storage
28RISK
open
Referência
CVE-2026-16572
LogMyTrip <= 1.9 - Unauthenticated SQL Injection via 'tid' Cookie
41RISK
open
Referência
CVE-2026-16565
Dokan < 5.0.9 - Vendor+ Cross-Vendor Product Attribute Modification via Product Attribute REST API
33RISK
open
Referência
CVE-2026-16564
Dokan < 5.0.9 - Vendor+ Arbitrary Order Status Modification via orders/bulk-actions REST Endpoint
33RISK
open
Referência
CVE-2026-16563
Academy LMS < 3.8.3 - Subscriber+ Arbitrary Lesson Content Disclosure via lessons REST Endpoint
33RISK
open
Referência
CVE-2026-16539
SM Page Duplicator <= 1.0.0 - Editor+ SQL Injection via Page Duplication
41RISK
open
Referência
CVE-2026-16300
Chama < 1.0.13 - Unauthenticated Arbitrary User Password Reset
48RISK
open
Referência
CVE-2026-16289
ProfileGrid < 6.0.0.0 - Subscriber+ Group Join Request Disclosure via pm_get_all_requests_from_group
33RISK
open
Referência
CVE-2026-16250
Personal QR Message <= 1.0 - Unauthenticated Arbitrary File Upload
48RISK
open
Referência
CVE-2026-16060
Insert or Embed Articulate Content into WordPress <= 4.3000000027 - Editor+ Arbitrary File Upload
48RISK
open
Referência
CVE-2026-15931
Simple Membership < 4.7.8 - Unauthenticated Stored XSS via PayPal Subscription Subscriber Name
33RISK
open
Referência
CVE-2026-15930
Simple Membership < 4.7.8 - Unauthenticated Administrator Account Takeover via Registration Username Collision
48RISK
open
Referência
CVE-2026-15383
Blog Floating Button <= 1.4.20 - Unauthenticated Stored XSS via User-Agent Header
33RISK
open
Referência
CVE-2026-15260
Geo My WP < 4.5.5.3 - Subscriber+ Arbitrary Geolocation Record Modification and Deletion via IDOR
33RISK
open
Referência
CVE-2026-15231
TaxoPress < 3.51.0 - Contributor+ Private Post Disclosure via IDOR
28RISK
open
Referência
CVE-2026-14557
SoftMarket <= 1.0.0 - Unauthenticated Account Takeover via Email Verification Bypass
48RISK
open
Referência
CVE-2026-13340
SVG Support < 2.5.17 - Author+ Stored XSS via .svgz Sanitization Bypass
33RISK
open
Referência
CVE-2026-12965
Super Store Finder <= 7.8 - Unauthenticated SQL Injection via ssf_tracking
48RISK
open
Referência
CVE-2026-12872
Webinfos <= 1.2 - Unauthenticated Arbitrary File Upload
48RISK
open
Referência
CVE-2025-15673
Import and export users and customers < 2.4.3 - Admin+ Arbitrary File Read
33RISK
open
Referência
CVE-2025-15672
Chama < 1.0.13 - Unauthenticated PHP Object Injection
41RISK
open
Referência
CVE-2026-16534
Import and export users and customers < 2.4.2 - Custom Role Privilege Escalation to Administrator via CSV Import
48RISK
open
Referência
CVE-2026-14318
GiveWP < 4.16.3 - GiveWP Worker+ Stored XSS via Donation Form Template Settings
33RISK
open
Referência
CVE-2026-15235
Hotel Booking Lite < 6.0.4 - Subscriber+ Sensitive Data Disclosure via Admin Calendar AJAX Action
33RISK
open
previouspage 472 / 744next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.