Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,020cataloged exploits
35,276CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,446Referência 22,166GitHub PoC 14,080VulnCheck XDB 8,604Nuclei 4,251Metasploit 3,473✓ verified onlyrecentpopularrisk
22,166 exploits
Referência
CVE-2026-19070
itsourcecode Hospital Management System viewadmin.php sql injection
33RISK
open ↗Referência
CVE-2026-19069
itsourcecode Hospital Management System treatmentrecord.php sql injection
33RISK
open ↗Referência
CVE-2026-19068
itsourcecode Hospital Management System treatmentdetail.php sql injection
33RISK
open ↗Referência
CVE-2026-19067
itsourcecode Hospital Management System treatment.php sql injection
33RISK
open ↗Referência
CVE-2025-15674
Content Protector (Passster) < 4.3.7 - Contributor+ Protected Content Disclosure via Core REST API
28RISK
open ↗Referência
CVE-2026-16620
WPC Name Your Price for WooCommerce < 2.2.5 - Unauthenticated Price Manipulation via Select Mode
41RISK
open ↗Referência
CVE-2026-16619
miniOrange 2FA < 6.2.8 - 2FA Bypass via Unlimited Second-Factor Attempts
41RISK
open ↗Referência
CVE-2026-16067
Event Booking Manager for WooCommerce (Pro) < 5.0.3 - Unauthenticated Payment Bypass via Client-Controlled Ticket Price
33RISK
open ↗Referência
CVE-2026-15256
Ninja Forms < 3.14.10 - Unauthenticated Arbitrary Shortcode Execution via Query-String Populated Field Default
33RISK
open ↗Referência
CVE-2026-17032
Supsystic Multiple Pro Plugins - Backdoor via Compromised Vendor Update Server
48RISK
open ↗Referência
CVE-2026-13342
Security Optimizer – The All-In-One Protection Plugin < 1.6.5 - Login Access IP Allowlist Bypass via post_password
33RISK
open ↗Referência
CVE-2026-15149
WP Hotel Booking < 2.3.3 - Unauthenticated Payment Bypass via Price Manipulation
33RISK
open ↗Referência
CVE-2026-15208
RegistrationMagic < 6.0.9.5 - Unauthenticated Payment Bypass via Amount-Blind PayPal Verification
33RISK
open ↗Referência
CVE-2026-15147
Five Star Restaurant Reservations < 2.7.23 - Unauthenticated Payment Bypass and Booking Confirmation via IDOR
33RISK
open ↗Referência
CVE-2026-14936
Simple Membership < 4.7.7 - Unauthenticated Payment Bypass via Missing PayPal IPN Receiver Verification
33RISK
open ↗Referência
CVE-2026-14831
Easy Booking < 3.5.0 - Unauthenticated Minimum Booking Duration Bypass
33RISK
open ↗Referência
CVE-2026-12901
GetPaid < 2.8.55 - Unauthenticated Worldpay Payment Bypass via Insufficient IPN Verification
33RISK
open ↗Referência
CVE-2026-12501
WP Travel Engine < 6.8.2 - Unauthenticated Payment Bypass via Missing PayPal IPN Receiver and Amount Verification
33RISK
open ↗Referência
CVE-2026-15152
WP Hotel Booking < 2.3.2 - Unauthenticated PayPal Payment Bypass
33RISK
open ↗Referência
CVE-2026-14225
Easy Appointments < 3.12.28 - Contributor+ Shortcode Allowlist Bypass
28RISK
open ↗Referência
CVE-2026-14812
Premium SEO - Unauthenticated Backdoor (Admin Creation / RCE / SSRF / Content Injection)
48RISK
open ↗Referência
CVE-2026-13399
Payment Plugins for PayPal WooCommerce < 2.0.20 - Unauthenticated Payment Bypass via Reuse of a Completed PayPal Order
41RISK
open ↗Referência
CVE-2026-14306
Tutor LMS < 3.9.14 - Subscriber+ Paid Course Content Disclosure via Enrollment Check Bypass
33RISK
open ↗Referência
CVE-2026-12584
Payment Gateway for Redsys & WooCommerce Lite < 7.0.2 - Unauthenticated Payment Confirmation via Unverified Inespay Callback
41RISK
open ↗Referência
CVE-2026-11361
Formidable Forms < 6.32.1 - Unauthenticated Payment Bypass via PayPal APPROVAL_PENDING Subscription Status
33RISK
open ↗Referência
CVE-2026-10599
Integrate PhonePe with WooCommerce <= 1.2.1 - Unauthenticated Payment Bypass via Transaction ID Reuse
41RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.