Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,020cataloged exploits
35,276CVEs with public exploitation
24,695lab-tested
22,166 exploits
Referência
CVE-2026-56109
ALSA Library < 1.2.16.1 Double-Free via parse_def() in conf.c
41RISK
open
Referência
CVE-2026-6858
Transbank Webpay < 1.14.0 - Unauthenticated Stored XSS
41RISK
open
Referência
CVE-2026-4259
Ultimate WooCommerce Auction Pro <= 2.4.5 - Reflected XSS via uwa_manage_auctions
41RISK
open
Referência
CVE-2026-4110
Ultimate WooCommerce Auction Pro <= 2.4.5 - Reflected XSS via uwa_auctions_bids_list
33RISK
open
Referência
CVE-2026-10530
Pie Register < 3.8.4.10 - Unauthenticated Email Verification Bypass via Predictable Token
33RISK
open
Referência
CVE-2026-13592
liftoff-sr CIPster EtherNet IP Message append out-of-bounds write
33RISK
open
Referência
CVE-2026-13591
DeepMyst Mysti Contact Tracking ChannelBridge.ts _isTrackedConversation improper authorization
28RISK
open
Referência
CVE-2026-13590
seladb PcapPlusPlus Modbus Protocol ModbusLayer.h getLength heap-based overflow
33RISK
open
Referência
CVE-2026-13589
seladb PcapPlusPlus Telnet Subnegotiation Packet TelnetLayer.cpp getSubCommand heap-based overflow
33RISK
open
Referência
CVE-2026-34112
Guardian Language-System Unauthenticated OS Command Injection via id Parameter in speechmac.php
48RISK
open
Referência
CVE-2026-13588
seladb PcapPlusPlus TLS Hello SSLHandshake.cpp getHandshakeVersion heap-based overflow
33RISK
open
Referência
CVE-2026-13587
seladb PcapPlusPlus LightPcapNg light_pcapng.c parse_by_block_type heap-based overflow
33RISK
open
Referência
CVE-2026-13583
Edimax EW-7478APC POST Request formUSBFolder buffer overflow
41RISK
open
Referência
CVE-2026-13582
Edimax EW-7478APC POST Request formUSBAccount buffer overflow
41RISK
open
Referência
CVE-2026-13581
Edimax EW-7478APC POST Request formStaDrvSetup os command injection
33RISK
open
Referência
CVE-2017-20274
Joomla LMS King Professional 3.2.4.0 SQL Injection via learningpath
41RISK
open
Referência
CVE-2016-20084
WordPress appointment-booking-calendar 1.1.24 Privilege Escalation XSS
33RISK
open
Referência
CVE-2016-20083
WordPress More Fields Plugin 2.1 Cross-Site Request Forgery
33RISK
open
Referência
CVE-2016-20082
WordPress Plugin Abtest Local File Inclusion via abtest_admin.php
33RISK
open
Referência
CVE-2017-20273
Joomla Event Registration Pro Calendar 4.1.3 SQL Injection
41RISK
open
Referência
CVE-2026-12188
Grit42 Grit GritEntityController grit_entity_controller.rb sql injection
33RISK
open
Referência
CVE-2017-20272
Joomla Ultimate Property Listing 1.0.2 SQL Injection via sf_selectuser_id
41RISK
open
Referência
CVE-2026-12797
BerriAI litellm Completions banned_keywords.py async_pre_call_hook authorization
33RISK
open
Referência
CVE-2017-20271
Joomla StreetGuessr Game 1.1.8 SQL Injection via catid
41RISK
open
Referência
CVE-2017-20270
Joomla! Component Twitch Tv 1.1 SQL Injection
41RISK
open
Referência
CVE-2017-20269
Joomla! Component KissGallery 1.0.0 SQL Injection
41RISK
open
Referência
CVE-2026-12776
Montodel House-Rental-Management index.php houses sql injection
33RISK
open
Referência
CVE-2026-12774
BerriAI litellm MCP Server Connection Testing rest_endpoints.py _execute_with_mcp_client server-side request forgery
33RISK
open
Referência
CVE-2026-12771
BerriAI litellm M2M JWT user_api_key_auth.py improper authorization
28RISK
open
Referência
CVE-2026-12770
BerriAI litellm Admin Key key_management_endpoints.py improper authorization
33RISK
open
previouspage 358 / 739next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.