Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,008cataloged exploits
34,638CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,662GitHub PoC 13,743VulnCheck XDB 8,460Nuclei 4,233Metasploit 3,467✓ verified onlyrecentpopularrisk
21,662 exploits
Referência
CVE-2017-20248
WordPress Plugin Apptha Slider Gallery 1.0 Path Traversal File Download
41RISK
open ↗Referência
CVE-2026-11557
Tenda F451 Web Management Natlimit fromNatlimit stack-based overflow
41RISK
open ↗Referência
CVE-2026-39908
OpenBullet2 0.3.2 NTLMv2 Hash Disclosure via UNC Path Proxy Source
41RISK
open ↗Referência
CVE-2026-11533
imvks786 student_management_system Student Deletion Endpoint see.php improper authorization
33RISK
open ↗Referência
CVE-2026-11532
imvks786 student_management_system Student Record add.php access control
33RISK
open ↗Referência
CVE-2026-11506
CodeAstro Leave Management System search_staff_for_deletion.php sql injection
33RISK
open ↗Referência
CVE-2026-11504
Tenda CX12L Wi-Fi Schedule Configuration Endpoint openSchedWifi setSchedWifi stack-based overflow
41RISK
open ↗Referência
CVE-2026-11503
Tenda CX12L Wi-Fi Configuration Endpoint fast_setting_wifi_set form_fast_setting_wifi_set stack-based overflow
41RISK
open ↗Referência
CVE-2026-11502
JeecgBoot Third-Party Login ThirdLoginController.java HttpServletResponse.sendRedirect redirect
28RISK
open ↗Referência
CVE-2026-11501
SourceCodester Hospitals Patient Records Management System Master.php save_patient sql injection
33RISK
open ↗Referência
CVE-2026-11495
CodeAstro Ingredients Stock Management System add_stock.php sql injection
33RISK
open ↗Referência
CVE-2026-11333
tittuvarghese CollegeManagementSystem Student Data Upload Endpoint upload_student_data.php unrestricted upload
33RISK
open ↗Referência
CVE-2026-10529
westboy CicadasCMS Task Scheduling Management ScheduleJobController.java cross site scripting
33RISK
open ↗Referência
CVE-2026-10276
hekmon8 Jenkins-server-mcp get_build_status/get_build_log/trigger_build index.ts jobPath server-side request forgery
33RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.