Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,360cataloged exploits
35,511CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,332GitHub PoC 14,168VulnCheck XDB 8,646Nuclei 4,289Metasploit 3,474✓ verified onlyrecentpopularrisk
22,301 exploits
Referência
CVE-2026-13553
itsourcecode Online Hotel Management System controller.php add unrestricted upload
33RISK
open ↗Referência
CVE-2011-0611
Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; A
100RISK
open ↗Referência
CVE-2013-3214
vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.
60RISK
open ↗Referência
CVE-2026-13549
CodeAstro Complaint Management System Report Endpoint Report.php deletereport authorization
33RISK
open ↗Referência
CVE-2026-5832
atototo api-lab-mcp HTTP http-server.ts test_http_endpoint server-side request forgery
33RISK
open ↗Referência
CVE-2026-5829
code-projects Simple IT Discussion Forum content.php sql injection
33RISK
open ↗Referência
CVE-2026-5828
code-projects Simple IT Discussion Forum addcomment.php sql injection
33RISK
open ↗Referência
CVE-2026-5827
code-projects Simple IT Discussion Forum question-function.php sql injection
33RISK
open ↗Referência
CVE-2026-5826
code-projects Simple IT Discussion Forum edit-category.php cross site scripting
33RISK
open ↗Referência
CVE-2026-5705
code-projects Online Hotel Booking Booking Endpoint booknow.php cross site scripting
33RISK
open ↗Referência
CVE-2026-5691
Totolink A7100RU cstecgi.cgi setFirewallType os command injection
33RISK
open ↗Referência
CVE-2026-5687
Tenda CX12L NatStaticSetting fromNatStaticSetting stack-based overflow
41RISK
open ↗Referência
CVE-2026-5684
Tenda CX12L webExcptypemanFilter fromwebExcptypemanFilter stack-based overflow
41RISK
open ↗Referência
CVE-2026-5682
Meesho Online Shopping App com.meesho.supply endpoint risky encryption
33RISK
open ↗Referência
CVE-2026-5681
itsourcecode sanitize or validate this input Parameter borrowedequip.php sql injection
33RISK
open ↗Referência
CVE-2026-5676
Totolink A8000R cstecgi.cgi setLanguageCfg missing authentication
33RISK
open ↗Referência
CVE-2026-5675
itsourcecode Construction Management System Parameter borrowed_tool.php sql injection
33RISK
open ↗Referência
CVE-2026-5672
code-projects Simple IT Discussion Forum Parameter edit-category.php sql injection
33RISK
open ↗Referência
CVE-2026-5671
Cyber-III Student-Management-System Class Schedule Deletion Endpoint delete_batch.php cross site scripting
33RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.