Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,449cataloged exploits
35,552CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,367GitHub PoC 14,225VulnCheck XDB 8,649Nuclei 4,283Metasploit 3,474✓ verified onlyrecentpopularrisk
22,301 exploits
Referência
CVE-2023-46453
Certain GL.iNet devices with 4.x firmware allow authentication bypass (resulting in administrative control of the device
48RISK
open ↗Referência
CVE-2013-6881
CRU Ditto Forensic FieldStation with firmware before 2013Oct15a allows remote attackers to execute arbitrary commands vi
28RISK
open ↗Referência
CVE-2024-33288
Prison Management System Using PHP v1.0 was discovered to contain a SQL injection vulnerability via the username on the
56RISK
open ↗Referência
CVE-2013-7025
Multiple cross-site scripting (XSS) vulnerabilities in ematStaticAlertTypes.jsp in the Alert Settings section in Dell So
23RISK
open ↗Referência✓ VexDay Proof
RunCMS Module Photo 3.02 - 'cid' SQL Injection
SQL injection vulnerability in viewcat.php in the Photo 3.02 module for RunCMS allows remote attackers to execute arbitr
23RISK
open ↗Referência✓ VexDay Proof
TopperMod 2.0 - SQL Injection
SQL injection vulnerability in account/index.php in TopperMod 2.0, when magic_quotes_gpc is disabled, allows remote atta
23RISK
open ↗Referência✓ VexDay Proof
MPlayer 1.0 rc2 - 'sdpplin_parse()' Array Indexing Buffer Overflow (PoC)
Uncontrolled array index in the sdpplin_parse function in stream/realrtsp/sdpplin.c in MPlayer 1.0 rc2 allows remote att
28RISK
open ↗Referência
CVE-2026-7604
JeecgBoot OpenApi Service OpenApiController.java OpenApiController.call server-side request forgery
33RISK
open ↗Referência
CVE-2026-7401
SourceCodester CET Automated Grading System with AI Predictive Analytics Registration index.php register cross site scripting
33RISK
open ↗Referência
CVE-2026-7400
geekgod382 filesystem-mcp-server read_file_tool/write_file_tool server.py is_path_allowed path traversal
33RISK
open ↗Referência
CVE-2026-7319
elinsky execution-system-mcp add_action Tool server.py _get_context_file_path path traversal
33RISK
open ↗Referência
CVE-2026-7316
eiliyaabedini aider-mcp code_with_ai aider_mcp.py command injection
33RISK
open ↗Referência
CVE-2026-7314
eiceblue spire-doc-mcp-server base.py get_doc_path path traversal
33RISK
open ↗Referência✓ VexDay Proof
Watchfire Appscan 7.0 - ActiveX Multiple Insecure Methods
Multiple absolute path traversal vulnerabilities in certain ActiveX controls in WatchFire AppScan 7.0 allow remote attac
23RISK
open ↗Referência
CVE-2019-0808
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
98RISK
open ↗Referência✓ VexDay Proof
Megabbs Forum 2.2 - SQL Injection / Cross-Site Scripting
Multiple SQL injection vulnerabilities in PD9 Software MegaBBS 2.2 allow remote attackers to execute arbitrary SQL comma
23RISK
open ↗Referência
CVE-2019-1003000
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RISK
open ↗Referência
CVE-2014-10020
SQL injection vulnerability in login.php in Simple e-document 1.31 allows remote attackers to execute arbitrary SQL comm
23RISK
open ↗Referência
CVE-2014-10034
Multiple SQL injection vulnerabilities in the admin area in couponPHP before 1.2.0 allow remote administrators to execut
23RISK
open ↗Referência
CVE-2026-5634
projectworlds Car Rental Project Parameter book_car.php sql injection
33RISK
open ↗Referência
CVE-2026-5632
assafelovic gpt-researcher HTTP REST API Endpoint missing authentication
33RISK
open ↗Referência
CVE-2026-5631
assafelovic gpt-researcher ws Endpoint server_utils.py extract_command_data code injection
33RISK
open ↗Referência
CVE-2026-5630
assafelovic gpt-researcher Report API app.py cross site scripting
33RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.