Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,533cataloged exploits
35,607CVEs with public exploitation
24,695lab-tested
22,367 exploits
Referência
CVE-2026-9543
Totolink N300RH Web Management cstecgi.cgi setPasswordCfg os command injection
48RISK
open
Referência
CVE-2018-9237
iScripts EasyCreate 3.2.1 has Stored Cross-Site Scripting in the "Site Description" field.
23RISK
open
Referência
CVE-2026-10783
gradio-app gradio Audio Cache Key save_audio_to_cache weak hash
28RISK
open
Referência
CVE-2026-10722
cilium ebpf LoadCollectionSpec/LoadCollectionSpecFromReader btf.go loadRawSpec integer overflow
33RISK
open
Referência
CVE-2026-10704
SourceCodester Pizzafy E-Commerce System Administrative Control Panel admin_class_novo.php login sql injection
33RISK
open
Referência
CVE-2026-10703
EIPStackGroup OpENer SendRRData cipmessagerouter.c CreateMessageRouterRequestStructure use after free
33RISK
open
Referência
CVE-2026-10692
johnhuang316 code-index-mcp search_code_advanced is_safe_regex_pattern redos
33RISK
open
Referência
CVE-2026-10691
wonderwhy-er DesktopCommanderMCP start_search search-manager.ts redos
33RISK
open
Referência
CVE-2018-9238
proberv.php in Yahei-PHP Proberv 0.4.7 has XSS via the funName parameter.
23RISK
open
Referência
CVE-2026-10688
ahujasid blender-mcp server.py execute_blender_code code injection
33RISK
open
Referência
CVE-2018-9445
In readMetadata of Utils.cpp, there is a possible path traversal bug due to a confused deputy. This could lead to local
23RISK
open
Referência
CVE-2026-32848
NetBSD cryptodev Race Condition Double-Free via cryptodev_op()
33RISK
open
Referência
CVE-2026-32849
NetBSD Signed Integer Overflow in cryptodev_op via cryptodev.c
33RISK
open
Referência
CVE-2018-25391
HaPe PKH 1.1 Missing Authorization Allows Unauthenticated Record Deletion
41RISK
open
Referência
CVE-2018-25390
HaPe PKH 1.1 SQL Injection via desa Parameter
41RISK
open
Referência
CVE-2026-9807
Incorrect Authorization in GitLab
33RISK
open
Referência
CVE-2026-6268
EventPress < 22.2 – Reflected Cross-Site Scripting
41RISK
open
Referência
CVE-2026-9603
SourceCodester eDoc Doctor Appointment System delete-session.php authorization
33RISK
open
Referência
CVE-2026-9484
SourceCodester Student Grades Management System classroom.php removeStudentFromClassroom improper authorization
33RISK
open
Referência
CVE-2026-9483
SourceCodester Student Grades Management System grades.php improper authorization
33RISK
open
Referência
CVE-2026-9479
Edimax EW-7438RPn formLogout stack-based overflow
41RISK
open
Referência
CVE-2026-9581
JeecgBoot add access control
33RISK
open
Referência
CVE-2026-9542
CodeAstro Leave Management System add_staff.php sql injection
33RISK
open
Referência
CVE-2026-9541
Squirrel Cnut File sqobject.cpp ReadObject heap-based overflow
33RISK
open
Referência
CVE-2026-9540
vllm-project vllm OpenAI-compatible Serving Path denial of service
33RISK
open
Referência
CVE-2026-9534
Totolink CA750-PoE Setting cstecgi.cgi setWiFiWpsConfig os command injection
38RISK
open
Referência
CVE-2026-9533
Totolink CA750-PoE Setting cstecgi.cgi recvUpgradeNewFw os command injection
38RISK
open
Referência
CVE-2026-9530
GNU LibreDWG Dwgbmp Utility decode.c read_2004_compressed_section out-of-bounds
33RISK
open
Referência
CVE-2026-9472
dazeb markdown-downloader index.ts create_subdirectory path traversal
33RISK
open
Referência
CVE-2019-0731
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), ak
23RISK
open
previouspage 474 / 746next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.