Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,020cataloged exploits
35,276CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,446Referência 22,166GitHub PoC 14,080VulnCheck XDB 8,604Nuclei 4,251Metasploit 3,473✓ verified onlyrecentpopularrisk
22,166 exploits
Referência
CVE-2026-4259
Ultimate WooCommerce Auction Pro <= 2.4.5 - Reflected XSS via uwa_manage_auctions
41RISK
open ↗Referência
CVE-2026-4110
Ultimate WooCommerce Auction Pro <= 2.4.5 - Reflected XSS via uwa_auctions_bids_list
33RISK
open ↗Referência
CVE-2026-10530
Pie Register < 3.8.4.10 - Unauthenticated Email Verification Bypass via Predictable Token
33RISK
open ↗Referência
CVE-2026-13592
liftoff-sr CIPster EtherNet IP Message append out-of-bounds write
33RISK
open ↗Referência
CVE-2026-13591
DeepMyst Mysti Contact Tracking ChannelBridge.ts _isTrackedConversation improper authorization
28RISK
open ↗Referência
CVE-2026-13590
seladb PcapPlusPlus Modbus Protocol ModbusLayer.h getLength heap-based overflow
33RISK
open ↗Referência
CVE-2026-13589
seladb PcapPlusPlus Telnet Subnegotiation Packet TelnetLayer.cpp getSubCommand heap-based overflow
33RISK
open ↗Referência
CVE-2026-34112
Guardian Language-System Unauthenticated OS Command Injection via id Parameter in speechmac.php
48RISK
open ↗Referência
CVE-2026-13588
seladb PcapPlusPlus TLS Hello SSLHandshake.cpp getHandshakeVersion heap-based overflow
33RISK
open ↗Referência
CVE-2026-13587
seladb PcapPlusPlus LightPcapNg light_pcapng.c parse_by_block_type heap-based overflow
33RISK
open ↗Referência
CVE-2026-13581
Edimax EW-7478APC POST Request formStaDrvSetup os command injection
33RISK
open ↗Referência
CVE-2017-20274
Joomla LMS King Professional 3.2.4.0 SQL Injection via learningpath
41RISK
open ↗Referência
CVE-2016-20084
WordPress appointment-booking-calendar 1.1.24 Privilege Escalation XSS
33RISK
open ↗Referência
CVE-2016-20082
WordPress Plugin Abtest Local File Inclusion via abtest_admin.php
33RISK
open ↗Referência
CVE-2026-12188
Grit42 Grit GritEntityController grit_entity_controller.rb sql injection
33RISK
open ↗Referência
CVE-2017-20272
Joomla Ultimate Property Listing 1.0.2 SQL Injection via sf_selectuser_id
41RISK
open ↗Referência
CVE-2026-12797
BerriAI litellm Completions banned_keywords.py async_pre_call_hook authorization
33RISK
open ↗Referência
CVE-2026-12774
BerriAI litellm MCP Server Connection Testing rest_endpoints.py _execute_with_mcp_client server-side request forgery
33RISK
open ↗Referência
CVE-2026-12771
BerriAI litellm M2M JWT user_api_key_auth.py improper authorization
28RISK
open ↗Referência
CVE-2026-12770
BerriAI litellm Admin Key key_management_endpoints.py improper authorization
33RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.