Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,008cataloged exploits
34,638CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,662GitHub PoC 13,743VulnCheck XDB 8,460Nuclei 4,233Metasploit 3,467✓ verified onlyrecentpopularrisk
21,662 exploits
Referência
CVE-2010-5008
SQL injection vulnerability in pages/contact_list_mail_form.asp in BrightSuite Groupware 5.4 allows remote attackers to
23RISK
open ↗Referência
CVE-2026-6124
Tenda F451 httpd SafeMacFilter fromSafeMacFilter stack-based overflow
41RISK
open ↗Referência
CVE-2026-6120
Tenda F451 httpd DhcpListClient fromDhcpListClient stack-based overflow
41RISK
open ↗Referência
CVE-2026-6119
AstrBotDevs AstrBot API Endpoint post_data.get server-side request forgery
33RISK
open ↗Referência
CVE-2026-6117
AstrBotDevs AstrBot install-upload Endpoint plugin.py install_plugin_upload sandbox
33RISK
open ↗Referência
CVE-2026-6116
Totolink A7100RU CGI cstecgi.cgi setDiagnosisCfg os command injection
48RISK
open ↗Referência
CVE-2026-6114
Totolink A7100RU CGI cstecgi.cgi setNetworkCfg os command injection
48RISK
open ↗Referência
CVE-2026-6111
FoundationAgents MetaGPT common.py decode_image server-side request forgery
33RISK
open ↗Referência
CVE-2026-6110
FoundationAgents MetaGPT Tree-of-Thought Solver tot.py generate_thoughts code injection
33RISK
open ↗Referência
CVE-2026-6108
1Panel-dev MaxKB Model Context Protocol Node base_mcp_node.py execute os command injection
33RISK
open ↗Referência
CVE-2026-6106
1Panel-dev MaxKB Public Chat static_headers_middleware.py StaticHeadersMiddleware cross site scripting
33RISK
open ↗Referência
CVE-2026-6105
perfree go-fastdfs-web doInstall InstallController.java improper authorization
33RISK
open ↗Referência
CVE-2026-1516
Improper Control of Generation of Code ('Code Injection') in GitLab
33RISK
open ↗Referência✓ VexDay Proof
SimpleBlog 2.3 - '/admin/edit.asp' SQL Injection
SQL injection vulnerability in admin/edit.asp in 8pixel.net simpleblog 2.3 and earlier allows remote attackers to execut
23RISK
open ↗Referência
CVE-2026-4332
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
33RISK
open ↗Referência
CVE-2026-5669
Cyber-III Student-Management-System Parameter login.php sql injection
33RISK
open ↗Referência
CVE-2026-5637
projectworlds Car Rental System Parameter message_admin.php sql injection
33RISK
open ↗Referência
CVE-2026-5636
PHPGurukul Online Shopping Portal Project Parameter cancelorder.php sql injection
33RISK
open ↗Referência
CVE-2026-5635
PHPGurukul Online Shopping Portal Project Parameter categorywise-products.php sql injection
33RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.