Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,401cataloged exploits
35,511CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,332GitHub PoC 14,209VulnCheck XDB 8,646Nuclei 4,289Metasploit 3,474✓ verified onlyrecentpopularrisk
22,301 exploits
Referência
CVE-2026-14738
exo-explore exo Vision Feature Cache vision.py _image_cache_key weak hash
33RISK
open ↗Referência
CVE-2026-14737
Hanwang e-Face General Management Platform querySysAuthStr.do sql injection
33RISK
open ↗Referência
CVE-2026-14731
itsourcecode Hospital Management System patientreport.php sql injection
33RISK
open ↗Referência
CVE-2026-14730
itsourcecode Hospital Management System patientprofile.php sql injection
33RISK
open ↗Referência
CVE-2026-14722
tiddly-gittly TidGi-Desktop Git Repository Import loadWikiTiddlersWithSubWikis.ts code injection
33RISK
open ↗Referência
CVE-2026-14635
kirilkirkov Ecommerce-CodeIgniter-Bootstrap Vendor Multi-Image Endpoint AddProduct.php path traversal
33RISK
open ↗Referência
CVE-2026-14634
kirilkirkov Ecommerce-CodeIgniter-Bootstrap Subscribed Emails Admin MY_Controller.php checkForPostRequests cross site scripting
33RISK
open ↗Referência
CVE-2026-14628
NousResearch hermes-agent Live Webhook Endpoint base.py extract_media path traversal
33RISK
open ↗Referência
CVE-2026-14627
NousResearch hermes-agent Discord Platform Integration discord.py DiscordAdapter._is_allowed_user improper authentication
33RISK
open ↗Referência
CVE-2026-14626
NousResearch hermes-agent HTTP API run_agent.py AIAgent.run_conversation denial of service
33RISK
open ↗Referência
CVE-2023-31748
Insecure permissions in MobileTrans v4.0.11 allows attackers to escalate privileges to local admin via replacing the exe
41RISK
open ↗Referência
CVE-2023-3184
SourceCodester Sales Tracker Management System cross site scripting
28RISK
open ↗Referência
CVE-2023-3187
PHPGurukul Teachers Record Management System Profile Picture changeimage.php unrestricted upload
33RISK
open ↗Referência
CVE-2023-31873
Gin 0.7.4 allows execution of arbitrary code when a crafted file is opened, e.g., via require('child_process').
41RISK
open ↗Referência
CVE-2023-33580
Phpgurukul Student Study Center Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in the "Admin Name" f
23RISK
open ↗Referência
CVE-2017-8601
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to execute
35RISK
open ↗Referência✓ VexDay Proof
Student Study Center Management System v1.0 - Stored Cross-Site Scripting (XSS)
Phpgurukul Student Study Center Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in the "Admin Name" f
23RISK
open ↗Referência
Thruk Monitoring Web Interface 3.06 - Path Traversal
Thruk has Path Traversal Vulnerability in panorama.pm
45RISK
open ↗Referência✓ VexDay Proof
Service Provider Management System v1.0 - SQL Injection
Sourcecodester Service Provider Management System v1.0 is vulnerable to SQL Injection via the ID parameter in /php-spms/
23RISK
open ↗Referência
CVE-2023-33592
Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lf
23RISK
open ↗Referência
CVE-2023-34581
Sourcecodester Service Provider Management System v1.0 is vulnerable to SQL Injection via the ID parameter in /php-spms/
23RISK
open ↗Referência
CVE-2018-17383
SQL Injection exists in the Collection Factory 4.1.9 component for Joomla! via the filter_order or filter_order_Dir para
23RISK
open ↗Referência
CVE-2002-1230
NetDDE Agent on Windows NT 4.0, 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute
23RISK
open ↗Referência
CVE-2023-37979
WordPress Ninja Forms Plugin <= 3.6.25 is vulnerable to Cross Site Scripting (XSS)
56RISK
open ↗Referência
Campcodes Online Matrimonial Website System v3.3 - Code Execution via malicious SVG file upload
install/aiz-uploader/upload in Campcodes Online Matrimonial Website System Script 3.3 allows XSS via a crafted SVG docum
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.