Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,313cataloged exploits
34,834CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,797GitHub PoC 13,885VulnCheck XDB 8,484Nuclei 4,237Metasploit 3,467✓ verified onlyrecentpopularrisk
21,797 exploits
Referência
CVE-2009-4581
Directory traversal vulnerability in modules/admincp.php in RoseOnlineCMS 3 B1 and earlier, when magic_quotes_gpc is dis
23RISK
open ↗Referência
CVE-2017-5638
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open ↗Referência
CVE-2026-11312
bytedance InfiniStore KV Map infinistore.h purge_kv_map algorithmic complexity
33RISK
open ↗Referência✓ VexDay Proof
Limbo CMS 1.0.4.2L - 'com_contact' Remote Code Execution
Unrestricted file upload vulnerability in contact.html.php in the Contact (com_contact) component in Limbo (aka Lite Mam
23RISK
open ↗Referência
CVE-2026-50266
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another p
28RISK
open ↗Referência
CVE-2026-10815
LakshayD02 Hostel-Management-System-PHP Admin Dashboard index.php authorization
33RISK
open ↗Referência
CVE-2026-10812
zilliztech GPTCache Cache Key pre.py BufferedReader.peek weak hash
28RISK
open ↗Referência
CVE-2026-8037
OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF
85RISK
open ↗Referência
CVE-2026-10803
MLflow Dataset Digest Computation digest_utils.py mlflow.data.digest_utils weak hash
28RISK
open ↗Referência
CVE-2026-10802
keystonejs keystone GraphQL API Endpoint output-field.ts resource consumption
33RISK
open ↗Referência
CVE-2026-10801
modelscope ms-swift PIL Image Cache Key base.py Template._save_pil_image weak hash
28RISK
open ↗Referência
CVE-2026-10662
ahujasid blender-mcp ZIP File server.py requests.get server-side request forgery
33RISK
open ↗Referência
CVE-2026-10650
warmcat libwebsockets SSH Protocol sshd.c lws_ssh_parse_plaintext resource consumption
33RISK
open ↗Referência
CVE-2026-10650
warmcat libwebsockets SSH Protocol sshd.c lws_ssh_parse_plaintext resource consumption
33RISK
open ↗Referência
CVE-2026-10624
SourceCodester Human Resource Management Employee View detailview.php resource injection
33RISK
open ↗Referência
CVE-2021-22005
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISK
open ↗Referência
CVE-2017-8484
Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2,
23RISK
open ↗Referência
CVE-2020-5902
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.