Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,020cataloged exploits
35,276CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,446Referência 22,166GitHub PoC 14,080VulnCheck XDB 8,604Nuclei 4,251Metasploit 3,473✓ verified onlyrecentpopularrisk
22,166 exploits
Referência
CVE-2026-16451
zsadmin2025 ZS-Admin com.zs.file.controller.SysFileController upload unrestricted upload
33RISK
open ↗Referência
CVE-2026-64824
Home Assistant Core < 2026.7.0 Symlink Path Traversal RCE via backup-restore
48RISK
open ↗Referência
CVE-2026-16450
zsadmin2025 ZS-Admin MyBatis-Plus Tenant Plugin page getTenantId authorization
33RISK
open ↗Referência
CVE-2026-16449
zsadmin2025 ZS-Admin com.zs.sys.dept.controller.SysDeptController page OrderItem.desc sql injection
33RISK
open ↗Referência
CVE-2026-16448
D-Link DNS-1550-04 remote_backup.cgi cgi_check_rsync_rw command injection
33RISK
open ↗Referência
CVE-2026-63770
Glance 0.8.5 IP Spoofing Authentication Brute-Force Protection Bypass
41RISK
open ↗Referência
CVE-2026-13402
Royal Elementor Addons < 1.7.1063 - Unauthenticated Private Mega Menu Template Disclosure
33RISK
open ↗Referência
CVE-2026-16015
poco-ai poco-claw executor_manager API tasks.py create_task missing authentication
33RISK
open ↗Referência
CVE-2026-12869
Header Footer Builder for Elementor < 1.2.1 - Contributor+ Stored XSS via Template Import
33RISK
open ↗Referência
CVE-2026-15907
H3C SecPath F1000-C8300 g=log_fw_nbc_mail_jsondata sql injection
33RISK
open ↗Referência
CVE-2018-6005
SQL Injection exists in the Realpin through 1.5.04 component for Joomla! via the pinboard parameter.
23RISK
open ↗Referência
CVE-2018-6191
The js_strtod function in jsdtoa.c in Artifex MuJS through 1.0.2 has an integer overflow because of incorrect exponent v
23RISK
open ↗Referência
CVE-2018-6193
A Cross-Site Scripting (XSS) vulnerability was found in Routers2 2.24, affecting the 'rtr' GET parameter in a page=graph
23RISK
open ↗Referência
CVE-2018-6221
An unvalidated software update vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a man-in-the-middle
23RISK
open ↗Referência
CVE-2018-6365
SQL Injection exists in TSiteBuilder 1.0 via the id parameter to /site.php, /pagelist.php, or /page_new.php.
23RISK
open ↗Referência
CVE-2018-6365
SQL Injection exists in TSiteBuilder 1.0 via the id parameter to /site.php, /pagelist.php, or /page_new.php.
23RISK
open ↗Referência
CVE-2026-16009
itsourcecode Hospital Management System prescriptionorderdetail.php sql injection
33RISK
open ↗Referência
CVE-2026-11966
User Registration & Membership < 5.2.3 - Unauthenticated Limited User Deletion via Stripe Subscription Handler
33RISK
open ↗Referência
CVE-2026-11961
User Registration & Membership < 5.2.3 - Unauthenticated Privilege Escalation via Unbound members_data Membership ID
41RISK
open ↗Referência
CVE-2026-11575
PhonePe Payment Solutions < 3.1.0 - Unauthenticated Payment Bypass via Forged Callback
41RISK
open ↗Referência
CVE-2026-10525
NEX-Forms < 9.2.3 - Unauthenticated Stored XSS via Form Submission
33RISK
open ↗Referência
CVE-2026-12684
Customer Reviews for WooCommerce < 5.113.0 - Unauthenticated Arbitrary Media Upload via cr_upload_media
33RISK
open ↗Referência
CVE-2026-12585
Abandoned Cart Lite for WooCommerce < 6.8.2 - Unauthenticated Account Takeover via Malleable Recovery-Link Token
41RISK
open ↗Referência
CVE-2026-12525
Redux Framework < 4.5.13 - Subscriber+ Privilege Escalation to Administrator
41RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.