Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,401cataloged exploits
35,511CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,332GitHub PoC 14,209VulnCheck XDB 8,646Nuclei 4,289Metasploit 3,474✓ verified onlyrecentpopularrisk
22,301 exploits
Referência
CVE-2026-15258
Product Feed Manager for WooCommerce < 7.6.1 - Contributor+ SQL Injection via Feed Filter
41RISK
open ↗Referência
CVE-2026-15209
JS Help Desk – AI-Powered Support & Ticketing System < 3.1.5 - Subscriber+ Cross-User Support Ticket Disclosure via IDOR
33RISK
open ↗Referência
CVE-2026-14921
Ultimate Addons for WPBakery Page Builder < 3.21.5 - Contributor+ Stored XSS via ult_buttons Shortcode
33RISK
open ↗Referência
CVE-2026-14849
Paid Member Subscriptions < 3.0.7 - Unauthenticated Sensitive Information Exposure via Residual Export Files
28RISK
open ↗Referência
CVE-2026-67181
Rouille 0.3.3 - 3.6.2 HTTP Request Smuggling via proxy Transfer-Encoding Header
33RISK
open ↗Referência
CVE-2026-18038
nextlevelbuilder GoClaw jq Handler tools_invoke.go ExecTool.Execute information disclosure
33RISK
open ↗Referência
CVE-2026-66731
facil.io 0.7.5 - 0.7.6 HTTP/1.1 Chunked Transfer Encoding Parser Crash DoS
41RISK
open ↗Referência
CVE-2026-66729
facil.io 0.6.0 - 0.7.6 Integer Underflow DoS via Multipart MIME Body Parser
41RISK
open ↗Referência
CVE-2026-61511
vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php
48RISK
open ↗Referência
CVE-2026-17432
NousResearch hermes-agent SimpleX Gateway Authorization adapter.py access control
28RISK
open ↗Referência
CVE-2026-65694
Microweber CMS 2.0.20 Path Traversal via ServeStaticFileController
56RISK
open ↗Referência
CVE-2026-65916
CyberPanel Missing Authorization in cancelBackupCreation Handler
41RISK
open ↗Referência
CVE-2026-16735
release-it conventional-changelog Changelog File index.js writeChangelog os command injection
33RISK
open ↗Referência
CVE-2026-16733
bahmutov find-cypress-specs Branch index.js shell.exec os command injection
33RISK
open ↗Referência
CVE-2026-12082
Praison AI SEO < 5.0.7 - Unauthenticated Multiple Missing Authorization (Post Permalink Modification, Plugin Settings Disclosure)
41RISK
open ↗Referência
CVE-2018-6005
SQL Injection exists in the Realpin through 1.5.04 component for Joomla! via the pinboard parameter.
23RISK
open ↗Referência
CVE-2018-6191
The js_strtod function in jsdtoa.c in Artifex MuJS through 1.0.2 has an integer overflow because of incorrect exponent v
23RISK
open ↗Referência
CVE-2018-6193
A Cross-Site Scripting (XSS) vulnerability was found in Routers2 2.24, affecting the 'rtr' GET parameter in a page=graph
23RISK
open ↗Referência
CVE-2018-6221
An unvalidated software update vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a man-in-the-middle
23RISK
open ↗Referência
CVE-2018-6365
SQL Injection exists in TSiteBuilder 1.0 via the id parameter to /site.php, /pagelist.php, or /page_new.php.
23RISK
open ↗Referência
CVE-2018-6365
SQL Injection exists in TSiteBuilder 1.0 via the id parameter to /site.php, /pagelist.php, or /page_new.php.
23RISK
open ↗Referência
CVE-2026-16009
itsourcecode Hospital Management System prescriptionorderdetail.php sql injection
33RISK
open ↗Referência
CVE-2026-12684
Customer Reviews for WooCommerce < 5.113.0 - Unauthenticated Arbitrary Media Upload via cr_upload_media
33RISK
open ↗Referência
CVE-2026-12585
Abandoned Cart Lite for WooCommerce < 6.8.2 - Unauthenticated Account Takeover via Malleable Recovery-Link Token
41RISK
open ↗Referência
CVE-2026-12525
Redux Framework < 4.5.13 - Subscriber+ Privilege Escalation to Administrator
41RISK
open ↗Referência
CVE-2026-12510
AI Engine < 3.5.5 - Subscriber+Chatbot Discussion Disclosure and Takeover via IDOR
33RISK
open ↗Referência
CVE-2026-12512
Quotes Llama < 3.1.6 - Unauthenticated SQL Injection via sc Parameter
41RISK
open ↗Referência
CVE-2026-12281
Shibboleth < 2.5.4 - Unauthenticated Administrator Account Creation via Identity Header Spoofing
41RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.