Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,058cataloged exploits
35,300CVEs with public exploitation
24,695lab-tested
22,166 exploits
Referência
CVE-2026-16131
itsourcecode Hospital Management System prescriptionrecord.php sql injection
33RISK
open
Referência
CVE-2026-10272
a4m4 Student-Management-System deleteform.php improper authorization
33RISK
open
Referência
CVE-2026-10271
a4m4 Student-Management-System Admin Endpoint admin redirect
33RISK
open
Referência
CVE-2026-10209
code-projects Online Hospital Management System Appointment appointmentdetail.php sql injection
33RISK
open
Referência
CVE-2026-10208
code-projects Online Hospital Management System login_1.php login_user sql injection
33RISK
open
Referência
CVE-2026-10206
D-Link DI-8400 dbsrv.asp stack-based overflow
41RISK
open
Referência
CVE-2026-10183
TRENDnet TEW-432BRP formWlanSetup stack-based overflow
41RISK
open
Referência
CVE-2026-10166
Edimax BR-6478AC POST Request formWlbasic command injection
33RISK
open
Referência
CVE-2026-10161
TRENDnet TEW-432BRP formResetStatistic stack-based overflow
41RISK
open
Referência
CVE-2021-34369
portlets/contact/ref/refContactDetail.do in Accela Civic Platform through 20.1 allows remote attackers to obtain sensiti
23RISK
open
Referência
CVE-2021-35323
Cross Site Scripting (XSS) vulnerability exists in bludit 3-13-1 via the username in admin/login.
38RISK
open
ReferênciaVexDay Proof
Millewin 13.39.146.1 - Local Privilege Escalation
CVE-2021-3394localwindows
Millennium Millewin (also known as "Cartella clinica") 13.39.028, 13.39.28.3342, and 13.39.146.1 has insecure folder per
23RISK
open
Referência
CVE-2026-42626
HP ENVY 5000 series printers VERBASPP1N003.2237A.00 do not properly manage concurrent TCP connections to port 9100 (JetD
33RISK
open
Referência
CVE-2026-4929
Simple Hierarchical Select (Drupal 7) XSS in term-derived output
33RISK
open
Referência
CVE-2026-47102
LiteLLM < 1.83.10 Privilege Escalation via User Update
41RISK
open
Referência
CVE-2026-47102
LiteLLM < 1.83.10 Privilege Escalation via User Update
41RISK
open
Referência
CVE-2026-47101
LiteLLM < 1.83.14 Privilege Escalation via API Key Generation
41RISK
open
Referência
CVE-2026-47101
LiteLLM < 1.83.14 Privilege Escalation via API Key Generation
41RISK
open
Referência
CVE-2026-47101
LiteLLM < 1.83.14 Privilege Escalation via API Key Generation
41RISK
open
Referência
CVE-2026-67349
OpenCost < 1.121.0 Unauthenticated Helm Values Exposure and Admin Bypass
41RISK
open
Referência
CVE-2026-67348
Julep Insecure Direct Object Reference via GET /executions/{execution_id}
41RISK
open
Referência
CVE-2026-67347
Vendure 3.7.1 Cross-Channel Authorization Bypass via StockLocation and Asset Update
33RISK
open
Referência
CVE-2026-67345
MaxKey 4.1.12 DefaultRedirectResolver OAuth Authorization Code Theft
41RISK
open
Referência
CVE-2026-14310
Tutor LMS < 4.0.0 - Subscriber+ Cross-Course Q&A Content Disclosure and Reply Injection
33RISK
open
Referência
CVE-2026-14305
WP Delicious < 1.10.2 - Unauthenticated Arbitrary Post Meta Update via recipe_likes
33RISK
open
Referência
CVE-2026-14300
miniOrange Social Login and Register < 7.8.0 - Unauthenticated Account Takeover
41RISK
open
Referência
CVE-2026-14234
WOLF - WordPress Posts Bulk Editor and Manager < 1.1.0 - Stored XSS via CSRF
41RISK
open
Referência
CVE-2026-14224
Easy Appointments < 3.12.28 - Subscriber+ Cross-User Appointment Data Modification via IDOR
33RISK
open
Referência
CVE-2026-13692
PayU CommercePro < 3.9.0 - Unauthenticated Order Tampering
33RISK
open
Referência
CVE-2026-14802
react create-react-app react-dev-utils openBrowser.js startBrowserProcess os command injection
33RISK
open
previouspage 361 / 739next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.