Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,620cataloged exploits
35,647CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,429GitHub PoC 14,270VulnCheck XDB 8,693Nuclei 4,299Metasploit 3,474✓ verified onlyrecentpopularrisk
22,429 exploits
Referência
CVE-2026-58166
OpenBMB ChatDev - Unauthenticated Path Traversal in Upload Handler Allows Arbitrary File Write and Delete
41RISK
open ↗Referência
CVE-2026-13545
D-Link DCS-935L POST Parameter setconf.cgi sub_400E40 os command injection
41RISK
open ↗Referência
CVE-2026-13541
itsourcecode Hospital Management System doctorchangepassword.php sql injection
33RISK
open ↗Referência
CVE-2026-13515
Tenda JD12L SetPptpServerCfg formSetPPTPServer stack-based overflow
41RISK
open ↗Referência
CVE-2025-12669
Improper Control of Generation of Code ('Code Injection') in GitLab
33RISK
open ↗Referência
CVE-2020-37236
NewsLister Authenticated Persistent Cross-Site Scripting via Admin Panel
33RISK
open ↗Referência
CVE-2020-37235
WordPress Theme Wibar 1.1.8 Stored Cross-Site Scripting via Brand Component
33RISK
open ↗Referência
CVE-2020-37233
WordPress Plugin Buddypress 6.2.0 Persistent Cross-Site Scripting
33RISK
open ↗Referência
CVE-2020-37230
Syncplify.me Server! 5.0.37 Unquoted Service Path Privilege Escalation
41RISK
open ↗Referência
CVE-2020-37229
OKI sPSV Port Manager 1.0.41 Unquoted Service Path Privilege Escalation
41RISK
open ↗Referência
CVE-2026-3607
Access Control Check Implemented After Asset is Accessed in GitLab
33RISK
open ↗Referência
CVE-2026-10529
westboy CicadasCMS Task Scheduling Management ScheduleJobController.java cross site scripting
33RISK
open ↗Referência
CVE-2026-10276
hekmon8 Jenkins-server-mcp get_build_status/get_build_log/trigger_build index.ts jobPath server-side request forgery
33RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.