Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
75,526cataloged exploits
34,478CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,534GitHub PoC 13,654VulnCheck XDB 8,213Nuclei 4,218Metasploit 3,464✓ verified onlyrecentpopularrisk
21,534 exploits
Referência
CVE-2026-5826
code-projects Simple IT Discussion Forum edit-category.php cross site scripting
33RISK
open ↗Referência✓ VexDay Proof
PowerNews 2.5.6 - Local File Inclusion
Multiple directory traversal vulnerabilities in PowerScripts PowerNews 2.5.6 allow remote attackers to read and include
23RISK
open ↗Referência✓ VexDay Proof
Mambo Component com_gallery - SQL Injection
SQL injection vulnerability in index.php in the Gallery (com_gallery) component for Mambo and Joomla! allows remote atta
23RISK
open ↗Referência
CVE-2026-5705
code-projects Online Hotel Booking Booking Endpoint booknow.php cross site scripting
33RISK
open ↗Referência
CVE-2026-5691
Totolink A7100RU cstecgi.cgi setFirewallType os command injection
33RISK
open ↗Referência
CVE-2026-5687
Tenda CX12L NatStaticSetting fromNatStaticSetting stack-based overflow
41RISK
open ↗Referência
CVE-2026-5684
Tenda CX12L webExcptypemanFilter fromwebExcptypemanFilter stack-based overflow
41RISK
open ↗Referência
CVE-2026-5682
Meesho Online Shopping App com.meesho.supply endpoint risky encryption
33RISK
open ↗Referência
CVE-2026-5681
itsourcecode sanitize or validate this input Parameter borrowedequip.php sql injection
33RISK
open ↗Referência
CVE-2026-5676
Totolink A8000R cstecgi.cgi setLanguageCfg missing authentication
33RISK
open ↗Referência
CVE-2026-5675
itsourcecode Construction Management System Parameter borrowed_tool.php sql injection
33RISK
open ↗Referência
CVE-2026-5672
code-projects Simple IT Discussion Forum Parameter edit-category.php sql injection
33RISK
open ↗Referência
CVE-2026-5671
Cyber-III Student-Management-System Class Schedule Deletion Endpoint delete_batch.php cross site scripting
33RISK
open ↗Referência
CVE-2026-5670
Cyber-III Student-Management-System upload.php move_uploaded_file unrestricted upload
33RISK
open ↗Referência
CVE-2026-5330
SourceCodester/mayuri_k Best Courier Management System User Delete ajax.php access control
33RISK
open ↗Referência
CVE-2026-5328
shsuishang modulithshop ProductItemDao ProductIndexServiceImpl.java listItem sql injection
33RISK
open ↗Referência
CVE-2026-5327
efforthye fast-filesystem-mcp index.ts handleGetDiskUsage command injection
33RISK
open ↗Referência
CVE-2026-5326
SourceCodester Leave Application System User Information index.php authorization
33RISK
open ↗Referência
CVE-2026-5325
SourceCodester Simple Customer Relationship Management System Create Ticket create-ticket.php cross site scripting
33RISK
open ↗Referência
CVE-2026-5259
AutohomeCorp frostmourne Alarm Preview AlarmController.java server-side request forgery
33RISK
open ↗Referência
CVE-2026-5258
Sanster IOPaint File Manager file_manager.py _get_file path traversal
33RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.