Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,401cataloged exploits
35,511CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,332GitHub PoC 14,209VulnCheck XDB 8,646Nuclei 4,289Metasploit 3,474✓ verified onlyrecentpopularrisk
22,301 exploits
Referência
CVE-2026-5563
AutohomeCorp frostmourne Alarm Preview previewData httpTest sql injection
33RISK
open ↗Referência
CVE-2026-5562
provectus kafka-ui Endpoint testexecutions validateAccess code injection
33RISK
open ↗Referência
CVE-2026-5561
Campcodes Complete POS Management and Inventory System Environment Variable SettingsController.php injection
33RISK
open ↗Referência
CVE-2026-5560
PHPGurukul Online Shopping Portal Project Parameter payment-method.php sql injection
33RISK
open ↗Referência
CVE-2026-4973
SourceCodester Online Quiz System add-question.php cross site scripting
33RISK
open ↗Referência
CVE-2026-4972
code-projects Online Reviewer System btn_functions.php cross site scripting
33RISK
open ↗Referência
CVE-2026-4970
code-projects Social Networking Site Endpoint delete_photos.php sql injection
33RISK
open ↗Referência
CVE-2026-4969
code-projects Social Networking Site Alert home.php cross site scripting
33RISK
open ↗Referência
CVE-2026-4966
itsourcecode Free Hotel Reservation System index.php sql injection
33RISK
open ↗Referência
CVE-2026-4965
letta-ai letta Incomplete Fix CVE-2025-6101 ast_parsers.py resolve_type eval injection
33RISK
open ↗Referência
CVE-2026-4964
letta-ai letta File URL message_helper.py _convert_message_create_to_message server-side request forgery
33RISK
open ↗Referência
CVE-2026-4963
huggingface smolagents Incomplete Fix CVE-2025-9959 local_python_executor.py evaluate_with code injection
33RISK
open ↗Referência
CVE-2026-4961
Tenda AC6 POST Request QuickIndex formQuickIndex stack-based overflow
41RISK
open ↗Referência
CVE-2026-4960
Tenda AC6 POST Request WizardHandle fromWizardHandle stack-based overflow
41RISK
open ↗Referência
CVE-2026-4959
OpenBMB XAgent ShareServer WebSocket Endpoint share.py check_user missing authentication
33RISK
open ↗Referência
CVE-2026-4958
OpenBMB XAgent WebSocket Endpoint replayer.py ReplayServer.send_data authorization
28RISK
open ↗Referência
CVE-2026-4957
OpenBMB XAgent API Key function_handler.py FunctionHandler.handle_tool_call log file
33RISK
open ↗Referência
CVE-2026-4956
Shenzhen Ruiming Technology Streamax Crocus Parameter DevicePrint.do sql injection
33RISK
open ↗Referência
CVE-2026-4955
Shenzhen Ruiming Technology Streamax Crocus OperateStatistic.do sql injection
33RISK
open ↗Referência
CVE-2026-4954
mingSoft MCMS Web Content List Endpoint ContentAction.java list sql injection
33RISK
open ↗Referência
CVE-2026-4953
mingSoft MCMS Editor Endpoint BaseAction.java catchImage server-side request forgery
33RISK
open ↗Referência
CVE-2026-4910
Shenzhen Ruiming Technology Streamax Crocus Endpoint RemoteFormat.do sql injection
33RISK
open ↗Referência
CVE-2026-42785
OpenKM 6.3.12 Remote Code Execution via Administrative Scripting
41RISK
open ↗Referência
CVE-2010-4997
SQL injection vulnerability in index.php in OlyKit Swoopo Clone 2010 allows remote attackers to execute arbitrary SQL co
23RISK
open ↗Referência
CVE-2026-12175
CodeAstro Student Attendance Management System createStudents.php sql injection
33RISK
open ↗Referência✓ VexDay Proof
Cisco IP Phone 7940 - Reboot (Denial of Service)
The Cisco IP Phone 7940 allows remote attackers to cause a denial of service (reboot) via a large amount of TCP SYN pack
28RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.