Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,460Referência 22,832GitHub PoC 14,991VulnCheck XDB 8,829Nuclei 4,357Metasploit 3,489✓ verified onlyrecentpopularrisk
8,829 exploits
VulnCheck XDB
denial-of-service
PgBouncer integer overflow in PgBouncer network packet parsing
41RISK
open ↗VulnCheck XDB
initial-access
An improper authentication control vulnerability exists in AiCloud. This vulnerability can be triggered by a crafted req
48RISK
open ↗VulnCheck XDB
initial-access
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open ↗VulnCheck XDB
initial-access
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.7 - Unauthenticated Arbitrary File Upload via Non-ASCII Filename Blacklist Bypass
56RISK
open ↗VulnCheck XDB
initial-access
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open ↗VulnCheck XDB
local
Kernel: io_uring: page use-after-free vulnerability via buffer ring mmap
46RISK
open ↗VulnCheck XDB
initial-access
Livewire vulnerable to remote command execution during property update hydration
100RISK
open ↗VulnCheck XDB
initial-access
Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor
100RISK
open ↗VulnCheck XDB
initial-access
Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload
75RISK
open ↗VulnCheck XDB
initial-access
PostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validation
78RISK
open ↗VulnCheck XDB
initial-access
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RISK
open ↗VulnCheck XDB
info-leak
Relevanssi <= 4.24.4 (Free) and <= 2.27.5 (Premium) - Unauthenticated SQL Injection
56RISK
open ↗VulnCheck XDB
initial-access
Breeze Cache <= 2.4.4 - Unauthenticated Arbitrary File Upload via fetch_gravatar_from_remote
68RISK
open ↗VulnCheck XDB
info-leak
cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
60RISK
open ↗VulnCheck XDB
initial-access
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open ↗VulnCheck XDB
client-side
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allow
71RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.