Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,058cataloged exploits
35,300CVEs with public exploitation
24,695lab-tested
22,175 exploits
Referência
CVE-2026-14936
Simple Membership < 4.7.7 - Unauthenticated Payment Bypass via Missing PayPal IPN Receiver Verification
33RISK
open
Referência
CVE-2026-14831
Easy Booking < 3.5.0 - Unauthenticated Minimum Booking Duration Bypass
33RISK
open
Referência
CVE-2026-12901
GetPaid < 2.8.55 - Unauthenticated Worldpay Payment Bypass via Insufficient IPN Verification
33RISK
open
Referência
CVE-2026-12501
WP Travel Engine < 6.8.2 - Unauthenticated Payment Bypass via Missing PayPal IPN Receiver and Amount Verification
33RISK
open
Referência
CVE-2026-15152
WP Hotel Booking < 2.3.2 - Unauthenticated PayPal Payment Bypass
33RISK
open
Referência
CVE-2026-14225
Easy Appointments < 3.12.28 - Contributor+ Shortcode Allowlist Bypass
28RISK
open
Referência
CVE-2026-14842
Events Made Easy < 3.1.2 - Unauthenticated Payment Bypass
33RISK
open
Referência
CVE-2026-14812
Premium SEO - Unauthenticated Backdoor (Admin Creation / RCE / SSRF / Content Injection)
48RISK
open
Referência
CVE-2026-13399
Payment Plugins for PayPal WooCommerce < 2.0.20 - Unauthenticated Payment Bypass via Reuse of a Completed PayPal Order
41RISK
open
Referência
CVE-2026-14306
Tutor LMS < 3.9.14 - Subscriber+ Paid Course Content Disclosure via Enrollment Check Bypass
33RISK
open
Referência
CVE-2026-12584
Payment Gateway for Redsys & WooCommerce Lite < 7.0.2 - Unauthenticated Payment Confirmation via Unverified Inespay Callback
41RISK
open
Referência
CVE-2026-11361
Formidable Forms < 6.32.1 - Unauthenticated Payment Bypass via PayPal APPROVAL_PENDING Subscription Status
33RISK
open
Referência
CVE-2026-10599
Integrate PhonePe with WooCommerce <= 1.2.1 - Unauthenticated Payment Bypass via Transaction ID Reuse
41RISK
open
Referência
CVE-2026-19060
FoundationAgents MetaGPT code injection
33RISK
open
Referência
CVE-2026-11976
MonsterInsights Pro 10.2.0/10.2.2 - Backdoored via AWS S3 bucket compromise
48RISK
open
Referência
CVE-2026-5336
Dataverse Integration < 2.91 - Contributor+ Server-Side Template Injection (SSTI) to Information Disclosure
33RISK
open
Referência
CVE-2026-19059
FoundationAgents MetaGPT editor.py read path traversal
33RISK
open
Referência
CVE-2026-14314
PeproDev WooCommerce Receipt Uploader <= 2.8.0 - Unauthenticated Image Attachment Disclosure via IDOR
33RISK
open
Referência
CVE-2026-14313
PeproDev WooCommerce Receipt Uploader <= 2.8.0 - Unauthenticated Order Receipt Tampering via IDOR
33RISK
open
Referência
CVE-2026-15629
louisho5 picobot Workspace filesystem.go GetSkill link following
33RISK
open
Referência
CVE-2026-15628
zhayujie chatgpt-on-wechat CowAgent Vision Tool vision.py Vision._download_to_data_url server-side request forgery
33RISK
open
Referência
CVE-2026-15627
nextlevelbuilder GoClaw tool.go handleNavigate information disclosure
33RISK
open
Referência
CVE-2026-15626
nextlevelbuilder GoClaw ACP ToolBridge Workspace tool_bridge.go writeFile path traversal
33RISK
open
Referência
CVE-2026-15625
nextlevelbuilder GoClaw exec_approval.go ExecApprovalManager.CheckCommand incomplete blacklist
33RISK
open
Referência
CVE-2026-15537
SourceCodester Online Book Store System login.php sql injection
33RISK
open
Referência
CVE-2026-15536
itsourcecode Hospital Management System patviewprescription.php sql injection
33RISK
open
Referência
CVE-2026-15533
DedeCMS Column Management search.php code injection
33RISK
open
Referência
CVE-2026-15532
SourceCodester Online Book Store System User Management cross site scripting
33RISK
open
Referência
CVE-2026-15511
Comfast CF-WR631AX V3 FastCGI Backend webmgnt system_wl_upload_pic_file os command injection
48RISK
open
Referência
CVE-2026-15508
Helicone ai-gateway AWS Metadata Service service.rs build_target_url server-side request forgery
33RISK
open
previouspage 373 / 740next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.