Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,058cataloged exploits
35,300CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,175GitHub PoC 14,096VulnCheck XDB 8,607Nuclei 4,255Metasploit 3,474✓ verified onlyrecentpopularrisk
22,166 exploits
Referência
CVE-2026-16131
itsourcecode Hospital Management System prescriptionrecord.php sql injection
33RISK
open ↗Referência
CVE-2026-10272
a4m4 Student-Management-System deleteform.php improper authorization
33RISK
open ↗Referência
CVE-2026-10209
code-projects Online Hospital Management System Appointment appointmentdetail.php sql injection
33RISK
open ↗Referência
CVE-2026-10208
code-projects Online Hospital Management System login_1.php login_user sql injection
33RISK
open ↗Referência
CVE-2021-34369
portlets/contact/ref/refContactDetail.do in Accela Civic Platform through 20.1 allows remote attackers to obtain sensiti
23RISK
open ↗Referência
CVE-2021-35323
Cross Site Scripting (XSS) vulnerability exists in bludit 3-13-1 via the username in admin/login.
38RISK
open ↗Referência✓ VexDay Proof
Millewin 13.39.146.1 - Local Privilege Escalation
Millennium Millewin (also known as "Cartella clinica") 13.39.028, 13.39.28.3342, and 13.39.146.1 has insecure folder per
23RISK
open ↗Referência
CVE-2026-42626
HP ENVY 5000 series printers VERBASPP1N003.2237A.00 do not properly manage concurrent TCP connections to port 9100 (JetD
33RISK
open ↗Referência
CVE-2026-67349
OpenCost < 1.121.0 Unauthenticated Helm Values Exposure and Admin Bypass
41RISK
open ↗Referência
CVE-2026-67348
Julep Insecure Direct Object Reference via GET /executions/{execution_id}
41RISK
open ↗Referência
CVE-2026-67347
Vendure 3.7.1 Cross-Channel Authorization Bypass via StockLocation and Asset Update
33RISK
open ↗Referência
CVE-2026-67345
MaxKey 4.1.12 DefaultRedirectResolver OAuth Authorization Code Theft
41RISK
open ↗Referência
CVE-2026-14310
Tutor LMS < 4.0.0 - Subscriber+ Cross-Course Q&A Content Disclosure and Reply Injection
33RISK
open ↗Referência
CVE-2026-14305
WP Delicious < 1.10.2 - Unauthenticated Arbitrary Post Meta Update via recipe_likes
33RISK
open ↗Referência
CVE-2026-14300
miniOrange Social Login and Register < 7.8.0 - Unauthenticated Account Takeover
41RISK
open ↗Referência
CVE-2026-14234
WOLF - WordPress Posts Bulk Editor and Manager < 1.1.0 - Stored XSS via CSRF
41RISK
open ↗Referência
CVE-2026-14224
Easy Appointments < 3.12.28 - Subscriber+ Cross-User Appointment Data Modification via IDOR
33RISK
open ↗Referência
CVE-2026-14802
react create-react-app react-dev-utils openBrowser.js startBrowserProcess os command injection
33RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.