Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,313cataloged exploits
34,834CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,797GitHub PoC 13,885VulnCheck XDB 8,484Nuclei 4,237Metasploit 3,467✓ verified onlyrecentpopularrisk
21,797 exploits
Referência
CVE-2026-9822
WP Hotel Booking < 2.3.1 - Subscriber+ Missing Authorization in Multiple AJAX Handlers
33RISK
open ↗Referência
CVE-2026-2604
Evolution-data-server: evolution data server: arbitrary file deletion via inconsistent uri handling
33RISK
open ↗Referência
CVE-2026-49954
Discuz! X5.0 Local File Inclusion via enable_disable.php Plugin Directory
41RISK
open ↗Referência
CVE-2016-20080
WordPress Brandfolder Plugin 3.0 Local File Inclusion via callback.php
33RISK
open ↗Referência
CVE-2016-20078
WordPress IMDb Profile Widget 1.0.8 Local File Inclusion via pic.php
33RISK
open ↗Referência
CVE-2016-20077
WordPress Plugin Photocart Link 1.6 Local File Inclusion via decode.php
33RISK
open ↗Referência
CVE-2016-20076
WordPress Simple-Backup 2.7.11 Arbitrary File Deletion and Download
41RISK
open ↗Referência
CVE-2016-20075
WordPress Ultimate Product Catalog 3.8.6 Arbitrary File Upload RCE
41RISK
open ↗Referência
CVE-2026-34021
Lack of cryptographic protection in Wertheim SafeController 5400 enables RS-485 message sniffing and replay
41RISK
open ↗Referência
CVE-2026-12217
DVDFab Virtual Drive Signed Kernel Driver dvdfabio.sys privileges management
41RISK
open ↗Referência
CVE-2026-12204
ShopXO Scheduled Task Endpoint Crontab.php GoodsGiveIntegral authorization
33RISK
open ↗Referência
CVE-2026-12203
HKUDS AI-Trader Research Export agents.csv information disclosure
33RISK
open ↗Referência
CVE-2026-12200
Ritlabs TinyWeb Server Header libeay32.dll.html stack-based overflow
33RISK
open ↗Referência
CVE-2026-12198
Microweber API Endpoint thumbnail_img userfiles_path path traversal
33RISK
open ↗Referência
CVE-2026-12193
VS Revo RevoUninstaller IOCTL RevoDetector.sys IOCtl_Handler heap-based overflow
41RISK
open ↗Referência
CVE-2026-12193
VS Revo RevoUninstaller IOCTL RevoDetector.sys IOCtl_Handler heap-based overflow
41RISK
open ↗Referência
CVE-2026-12188
Grit42 Grit GritEntityController grit_entity_controller.rb sql injection
33RISK
open ↗Referência
CVE-2026-12183
Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 through 2.10.2 on Linux contains an Improper Authentic
48RISK
open ↗Referência
CVE-2026-9062
Agile Store Locator < 1.6.9 - Admin+ Arbitrary File Read via Path Traversal
28RISK
open ↗Referência
CVE-2026-12066
PbootCMS Password MemberController.php retrieve password recovery
33RISK
open ↗Referência
CVE-2026-12065
Groww Stock, Mutual Fund, Gold App WebView URL improper authorization in handler for custom url scheme
28RISK
open ↗Referência
CVE-2026-12065
Groww Stock, Mutual Fund, Gold App WebView URL improper authorization in handler for custom url scheme
28RISK
open ↗Referência
CVE-2026-9269
Secure Copy Content Protection and Content Locking < 5.1.5 - Admin+ Stored XSS via ays_sccp_sub_icon_image Parameter
28RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.