Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 19,967GitHub PoC 13,264VulnCheck XDB 8,156Nuclei 4,201Metasploit 3,462✓ verified onlyrecentpopularrisk
19,967 exploits
Referência
CVE-2026-6940
radare2 < 6.1.4 Project Deletion Path Traversal Directory Deletion
13RISK
open ↗Referência
CVE-2026-23751
Kofax Capture 6.0.0.0 Unauthenticated File Read/Write & SMB Coercion via .NET Remoting
48RISK
open ↗Referência
CVE-2026-41460
SocialEngine <= 7.8.0 SQL Injection via activity/index/get-memberall
48RISK
open ↗Referência
CVE-2026-9358
postcss-selector-parser AST Serialization container.js toString recursion
33RISK
open ↗Referência
CVE-2026-9355
SourceCodester Hospitals Patient Records Management System Master.php save_patient_history sql injection
33RISK
open ↗Referência
CVE-2026-9354
NousResearch hermes-agent Slack Agent/Mattermost Agent escape output
33RISK
open ↗Referência
CVE-2026-9353
NousResearch hermes-agent Skills Guard Multi-Word Prompt skills_guard.py injection
33RISK
open ↗Referência
CVE-2026-9352
NousResearch hermes-agent Messaging Gateway local.py _make_run_env information disclosure
33RISK
open ↗Referência
CVE-2026-9351
NousResearch hermes-agent read_file Tool file_tools.py _is_blocked_device path traversal
33RISK
open ↗Referência
CVE-2026-9350
NousResearch hermes-agent Batch Runner approval.py check_all_command_guards authorization
33RISK
open ↗Referência
CVE-2026-9349
calcom cal.diy Generic React API bookings-single-view.getServerSideProps.tsx getServerSideProps information disclosure
33RISK
open ↗Referência
CVE-2019-25714
Seeyon Office Anywhere (OA) A8 Unauthenticated Arbitrary File Write via htmlofficeservlet
48RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.