Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,369cataloged exploits
35,511CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,332GitHub PoC 14,177VulnCheck XDB 8,646Nuclei 4,289Metasploit 3,474✓ verified onlyrecentpopularrisk
22,301 exploits
Referência
CVE-2016-20070
WordPress Booking Calendar Contact Form 1.0.23 Privilege Escalation Stored XSS
33RISK
open ↗Referência
CVE-2018-9445
In readMetadata of Utils.cpp, there is a possible path traversal bug due to a confused deputy. This could lead to local
23RISK
open ↗Referência
CVE-2018-9488
In the SELinux permissions of crash_dump.te, there is a permissions bypass due to a missing restriction. This could lead
23RISK
open ↗Referência
CVE-2026-10550
elunez eladmin Application Deployment App.java command injection
33RISK
open ↗Referência
CVE-2026-10548
NousResearch hermes-agent Credential Pool Synchronization credential_pool.py _sync_anthropic_entry_from_credentials_file improper authentication
33RISK
open ↗Referência
CVE-2026-10301
itsourcecode Fees Management System index.php cross site scripting
33RISK
open ↗Referência
CVE-2026-10295
SourceCodester Customer Review App review_app.py get_all_reviews denial of service
33RISK
open ↗Referência
CVE-2026-10290
code-projects Hotel and Tourism Reservation System GET Parameter tour.php sql injection
33RISK
open ↗Referência
CVE-2026-10289
code-projects Hotel and Tourism Reservation System tour.php cross site scripting
33RISK
open ↗Referência
CVE-2026-10288
code-projects Hotel and Tourism Reservation System Admin Login login.php password_verify improper authentication
33RISK
open ↗Referência
CVE-2026-12189
Moovit Bus & Public Transit App com.tranzmate improper authorization in handler for custom url scheme
33RISK
open ↗Referência
CVE-2026-12187
GL.iNet GL-MT3000 Online Firmware Upgrade one_click_upgrade command injection
41RISK
open ↗Referência
CVE-2026-12186
GL.iNet GL-MT3000 Tor Proxy Service Configuration tor replace_country command injection
41RISK
open ↗Referência
CVE-2026-25557
Evoluted PHP Directory Listing Script 4.0.5 Reflected XSS via dir parameter
33RISK
open ↗Referência
CVE-2004-0798
Buffer overflow in the _maincfgret.cgi script for Ipswitch WhatsUp Gold before 8.03 Hotfix 1 allows remote attackers to
50RISK
open ↗Referência
CVE-2026-11621
Dcat-Admin User Setting upload editorMDUpload unrestricted upload
33RISK
open ↗Referência
CVE-2026-11584
CodeAstro Student Attendance Management System createClass.php edit sql injection
33RISK
open ↗Referência
CVE-2026-11583
CodeAstro Student Attendance Management System createClass.php sql injection
33RISK
open ↗Referência
CVE-2019-0541
A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML E
83RISK
open ↗Referência
CVE-2026-11312
bytedance InfiniStore KV Map infinistore.h purge_kv_map algorithmic complexity
33RISK
open ↗Referência
CVE-2026-9544
Shenzhen Sixun Software Sixun Shanghui Group Business Management System PayConfig sql injection
33RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.