Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,589cataloged exploits
34,508CVEs with public exploitation
24,695lab-tested
21,554 exploits
Referência
CVE-2026-12492
Happy Coders OTP Login for WooCommerce < 2.8 - Unauthenticated Account Takeover via hcotp_auto_login_user
48RISK
open
Referência
CVE-2026-12395
WP Job Portal < 2.5.5 - Subscriber+ SQL Injection via Applied Resumes 'ta' Parameter
33RISK
open
Referência
CVE-2026-11866
LatePoint < 5.6.3 - Multiple Privileged Actions via CSRF
33RISK
open
Referência
CVE-2026-11371
BetterDocs < 4.5.5 - Unauthenticated Stored XSS via AI Doc Summarizer Prompt Injection
33RISK
open
Referência
CVE-2026-12512
Quotes Llama < 3.1.6 - Unauthenticated SQL Injection via sc Parameter
41RISK
open
Referência
CVE-2026-12281
Shibboleth < 2.5.4 - Unauthenticated Administrator Account Creation via Identity Header Spoofing
41RISK
open
Referência
CVE-2026-11580
Kali Forms < 2.4.17 - Contributor+ Arbitrary Post Metadata Disclosure via IDOR
33RISK
open
Referência
CVE-2026-11579
Kali Forms < 2.4.17 - Unauthenticated Media Upload
33RISK
open
Referência
CVE-2026-15751
mastergo-design mastergo-magic-mcp mcp__getComponentGenerator component-workflow.md execute path traversal
33RISK
open
Referência
CVE-2026-15535
AkariAsai self-rag retrieval_lm index.py Indexer.deserialize_from deserialization
33RISK
open
Referência
CVE-2026-15481
Trendnet TEW-635BRM IPoA WAN Connection Setup rc ipoa_test command injection
41RISK
open
Referência
CVE-2026-15480
Trendnet TEW-635BRM Web Service rc start_httpd stack-based overflow
41RISK
open
Referência
CVE-2026-15479
H3C NX15 Administrator Password Modification Endpoint modify change_passwd password recovery
33RISK
open
Referência
CVE-2026-15476
QILING Disk Master Kernel Driver diskbckp.sys access control
33RISK
open
Referência
CVE-2026-15475
MiniTool Partition Wizard Signed Kernel Driver pwdrvio.sys access control
33RISK
open
Referência
CVE-2026-15474
Eleveo Call Recording Software audio.jsp improper authorization
33RISK
open
Referência
CVE-2026-15472
Eleveo Call Recording Software composeEmailAction.do improper authorization
33RISK
open
Referência
CVE-2026-15471
Eleveo Call Recording Software pci_dss_status.jsp improper authorization
33RISK
open
Referência
CVE-2026-15470
Eleveo Call Recording Software group.jsp improper authorization
33RISK
open
Referência
CVE-2026-61461
Dify < 1.16.0-rc1 SQL Injection via MyScale Vector Store search_by_full_text
41RISK
open
Referência
CVE-2026-15374
Eleveo Call Recording Software Group roleAddAction.do improper authorization
33RISK
open
Referência
CVE-2026-15373
Eleveo Call Recording Software userAddAction.do improper authorization
33RISK
open
Referência
CVE-2026-12685
EscortWP <= 3.6.2 - Content Deletion via Vendor-Authored Backdoor
41RISK
open
Referência
CVE-2026-15330
zhayujie CowAgent Vision Tool vision.py _download_to_data_url server-side request forgery
33RISK
open
Referência
CVE-2026-15329
zhayujie CowAgent Browser Tool browser_tool.py BrowserTool._do_navigate information disclosure
33RISK
open
Referência
CVE-2026-15326
halo-dev halo Theme Installation ThemeUtils.java ThemeUtils.unzipThemeTo path traversal
33RISK
open
Referência
CVE-2026-15321
MyEMS Admin Backend svg.py on_post cross site scripting
33RISK
open
Referência
CVE-2026-15317
Sipeed PicoClaw Guarded Web Fetch Flow web.go WebFetchTool.Execute server-side request forgery
33RISK
open
Referência
CVE-2026-15274
lo48576 fbxcel Node Header parser.rs denial of service
33RISK
open
Referência
CVE-2026-15270
D-link DIR-823G Web boa.conf least privilege violation
41RISK
open
previouspage 213 / 719next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.