Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,302cataloged exploits
35,469CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,301GitHub PoC 14,141VulnCheck XDB 8,646Nuclei 4,289Metasploit 3,474✓ verified onlyrecentpopularrisk
22,301 exploits
Referência
CVE-2018-14894
CyberArk Endpoint Privilege Manager 10.2.1.603 and earlier allows an attacker (who is able to edit permissions of a file
23RISK
open ↗Referência
CVE-2018-14912
cgit_clone_objects in CGit before 1.2.1 has a directory traversal vulnerability when `enable-http-clone=1` is not turned
60RISK
open ↗Referência
CVE-2026-7694
Acrel Electrical ECEMS Enterprise Microgrid Energy Efficiency Management System elecMaxMinAvgValue sql injection
33RISK
open ↗Referência
CVE-2026-7689
Dolibarr ERP CRM Online Signature security.lib.php dol_verifyHash signature verification
33RISK
open ↗Referência
CVE-2026-7687
langflow-ai langflow Full Builtins code_parser.py CodeParser.parse_callable_details command injection
33RISK
open ↗Referência
CVE-2012-1213
Cross-site scripting (XSS) vulnerability in zimbra/h/calendar in Zimbra Web Client in Zimbra Collaboration Suite (ZCS) 6
23RISK
open ↗Referência
CVE-2026-9386
Totolink A8000RU Web Management cstecgi.cgi setLanguageCfg os command injection
48RISK
open ↗Referência
CVE-2026-9385
Totolink A8000RU Web Management cstecgi.cgi setTracerouteCfg os command injection
48RISK
open ↗Referência
CVE-2026-9376
JPress UCenter Article Submission Endpoint doWriteSave improper authorization
33RISK
open ↗Referência
CVE-2026-9372
ItzCrazyKns Vane Model Provider API route.ts server-side request forgery
33RISK
open ↗Referência
CVE-2026-9370
ulisesbocchio jasypt-spring-boot Password Hash SimpleGCMConfig.java getSecretKeySaltGenerator hash predictable salt
33RISK
open ↗Referência✓ VexDay Proof
mxBB Module MX Shotcast 1.0 RC2 - 'getinfo1.php' Remote File Inclusion
PHP remote file inclusion vulnerability in getinfo1.php in the Shotcast 1.0 RC2 module for mxBB allows remote attackers
23RISK
open ↗Referência
CVE-2020-37244
WordPress Plugin Supsystic Membership 1.4.7 SQL Injection via sidx
41RISK
open ↗Referência
CVE-2020-37243
WordPress Plugin Supsystic Pricing Table 1.8.7 SQL Injection XSS
41RISK
open ↗Referência
CVE-2026-7678
YunaiV yudao-cloud GoViewDataServiceImpl.java getDataBySQL sql injection
33RISK
open ↗Referência
CVE-2026-7443
BurtTheCoder mcp-dnstwist MCP index.ts fuzz_domain os command injection
33RISK
open ↗Referência
CVE-2012-1465
Stack-based buffer overflow in the HTTP Server in NetMechanica NetDecision before 4.6.1 allows remote attackers to cause
43RISK
open ↗Referência
CVE-2026-7417
Algovate xhs-mcp MCP mcp.server.ts xhs_publish_content server-side request forgery
33RISK
open ↗Referência
CVE-2026-7416
PolarVista xcode-mcp-server MCP index.ts run_tests os command injection
33RISK
open ↗Referência
CVE-2026-7410
SourceCodester Pizzafy Ecommerce System ajax.php add_to_cart sql injection
33RISK
open ↗Referência
CVE-2026-7409
SourceCodester Pizzafy Ecommerce System ajax.php save_user sql injection
33RISK
open ↗Referência
CVE-2018-15657
An SSRF issue was discovered in 42Gears SureMDM before 2018-11-27 via the /api/DownloadUrlResponse.ashx "url" parameter.
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.