Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,647cataloged exploits
34,986CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,899GitHub PoC 14,014VulnCheck XDB 8,571Nuclei 4,248Metasploit 3,472✓ verified onlyrecentpopularrisk
21,899 exploits
Referência
CVE-2021-44228
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open ↗Referência
CVE-2021-44228
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open ↗Referência
CVE-2021-44228
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open ↗Referência
CVE-2021-44228
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open ↗Referência
CVE-2026-15048
GeekyBot < 1.2.8 - Unauthenticated Sensitive Information Exposure via Chat History
41RISK
open ↗Referência
CVE-2026-14930
JS Help Desk < 3.1.4 - Unauthenticated Arbitrary Ticket File Attachment Upload
41RISK
open ↗Referência
CVE-2026-14929
JS Help Desk < 3.1.4 - Subscriber+ Ticket Reply Modification via IDOR
33RISK
open ↗Referência
CVE-2026-14928
JS Help Desk < 3.1.4 - Subscriber+ Sensitive Information Disclosure via checkAIReplyTicketsBySubject
33RISK
open ↗Referência
CVE-2026-14927
FluentCart < 1.5.3 - Unauthenticated Order PII Disclosure via Print Routes
28RISK
open ↗Referência
CVE-2026-14922
WP Photo Album Plus < 9.2.04.003 - Subscriber+ Stored XSS via Photo Comment
33RISK
open ↗Referência
CVE-2026-66746
Rouille 0.4.0 - 3.6.2 HTTP Response Splitting via Header Injection
33RISK
open ↗Referência
CVE-2026-66754
Rouille 0.1.6 - 3.6.2 Reachable Assertion DoS via remove_prefix percent-encoding
41RISK
open ↗Referência
CVE-2026-66748
Camaleon CMS 2.1.1 - 2.9.1 Authenticated RCE via select_eval Custom Field
41RISK
open ↗Referência
CVE-2026-66748
Camaleon CMS 2.1.1 - 2.9.1 Authenticated RCE via select_eval Custom Field
41RISK
open ↗Referência
CVE-2026-66748
Camaleon CMS 2.1.1 - 2.9.1 Authenticated RCE via select_eval Custom Field
41RISK
open ↗Referência
CVE-2026-43760
An access issue was addressed with improved access restrictions. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe
41RISK
open ↗Referência
CVE-2025-15662
Printcart Web to Print Product Designer for WooCommerce < 2.5.3 - Unauthenticated Arbitrary File Read and Server-Side Request Forgery
41RISK
open ↗Referência
CVE-2026-15193
AidanPark openclaw-android Android WebView Bridge JsBridge.kt os command injection
33RISK
open ↗Referência
CVE-2026-15184
GNU LibreDWG DWG File dwg.c dwg_next_entity null pointer dereference
33RISK
open ↗Referência
CVE-2026-14798
CodeAstro Apartment Visitor Management System visitor-entry.php sql injection
33RISK
open ↗Referência
CVE-2026-53359
KVM: x86: Fix shadow paging use-after-free due to unexpected role
41RISK
open ↗Referência
CVE-2026-14622
jairiidriss restaurant-website-php-mysql AJAX Endpoint ajax_files missing authentication
33RISK
open ↗Referência
CVE-2026-10820
ProfilePress < 4.16.17 - Subscriber+ Subscription Cancellation via IDOR
41RISK
open ↗Referência
CVE-2026-9299
omec-project amf handler.go PDUSessionResourceModifyIndication memory corruption
33RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.