Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,401cataloged exploits
35,511CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,332GitHub PoC 14,209VulnCheck XDB 8,646Nuclei 4,289Metasploit 3,474✓ verified onlyrecentpopularrisk
22,332 exploits
Referência
CVE-2026-8773
linlinjava litemall Database Setting DbUtil.java load argument injection
33RISK
open ↗Referência
CVE-2025-56352
In tinyMQTT commit 6226ade15bd4f97be2d196352e64dd10937c1962 (2024-02-18), the broker mishandles protocol violations duri
41RISK
open ↗Referência
CVE-2021-47957
WordPress Plugin Cookie Law Bar 1.2.1 Stored XSS via clb_bar_msg
33RISK
open ↗Referência
CVE-2026-3093
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
33RISK
open ↗Referência
CVE-2026-12436
Improperly Controlled Modification of Dynamically-Determined Object Attributes in GitLab
41RISK
open ↗Referência
CVE-2026-11351
ShinyStat Analytics < 1.0.17 - Unauthenticated Non-Published Product Information Disclosure
33RISK
open ↗Referência
CVE-2026-54653
`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field
41RISK
open ↗Referência
CVE-2026-55391
datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding
41RISK
open ↗Referência
CVE-2026-13493
AIDC-AI ComfyUI-Copilot Workflow Checkpoint Restore conversation_api.py resource injection
28RISK
open ↗Referência
CVE-2026-13491
78 xiaozhi-esp32 MQTT Goodbye mqtt_protocol.cc GetInstance denial of service
33RISK
open ↗Referência
CVE-2026-13489
78 xiaozhi-esp32 MCP Response mcp_server.cc ParseMessage improper synchronization
28RISK
open ↗Referência
CVE-2026-13488
SourceCodester Class and Exam Timetabling System preview7.php sql injection
33RISK
open ↗Referência
CVE-2026-13487
SourceCodester Class and Exam Timetabling System archive.php sql injection
33RISK
open ↗Referência
CVE-2026-11437
perfree go-fastdfs-web Installation Endpoint checkServer server-side request forgery
33RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.