Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,449cataloged exploits
35,552CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,367GitHub PoC 14,225VulnCheck XDB 8,649Nuclei 4,283Metasploit 3,474✓ verified onlyrecentpopularrisk
22,301 exploits
Referência
CVE-2021-41773
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open ↗Referência
CVE-2026-8263
Tenda AC6 httpd WifiExtraSet fromSetWirelessRepeat os command injection
33RISK
open ↗Referência
CVE-2026-8250
Open5GS SMF n4-build.c smf_n4_build_qos_flow_to_modify_list denial of service
33RISK
open ↗Referência
CVE-2026-8249
Open5GS SMF npcf-handler.c update_authorized_pcc_rule_and_qos denial of service
33RISK
open ↗Referência
CVE-2021-47930
Balbooa Joomla Forms Builder 2.0.6 SQL Injection Unauthenticated
41RISK
open ↗Referência
CVE-2015-7898
Samsung Gallery in the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).
23RISK
open ↗Referência
CVE-2015-7898
Samsung Gallery in the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).
23RISK
open ↗Referência
CVE-2015-7985
Valve Steam 2.10.91.91 uses weak permissions (Users: read and write) for the Install folder, which allows local users to
23RISK
open ↗Referência
CVE-2015-8103
The Jenkins CLI subsystem in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to execute arbitrary co
60RISK
open ↗Referência
CVE-2015-8103
The Jenkins CLI subsystem in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to execute arbitrary co
60RISK
open ↗Referência
CVE-2015-8412
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RISK
open ↗Referência
CVE-2022-50959
WordPress Contact Form Builder 1.6.1 Cross-Site Scripting via code_generator.php
33RISK
open ↗Referência
CVE-2022-50958
WordPress Plugin Jetpack 9.1 Cross Site Scripting via grunion-form-view.php
33RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.