Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,533cataloged exploits
35,607CVEs with public exploitation
24,695lab-tested
22,407 exploits
Referência
CVE-2026-15628
zhayujie chatgpt-on-wechat CowAgent Vision Tool vision.py Vision._download_to_data_url server-side request forgery
33RISK
open
Referência
CVE-2026-15627
nextlevelbuilder GoClaw tool.go handleNavigate information disclosure
33RISK
open
Referência
CVE-2026-15626
nextlevelbuilder GoClaw ACP ToolBridge Workspace tool_bridge.go writeFile path traversal
33RISK
open
Referência
CVE-2026-15625
nextlevelbuilder GoClaw exec_approval.go ExecApprovalManager.CheckCommand incomplete blacklist
33RISK
open
Referência
CVE-2026-15537
SourceCodester Online Book Store System login.php sql injection
33RISK
open
Referência
CVE-2026-15536
itsourcecode Hospital Management System patviewprescription.php sql injection
33RISK
open
Referência
CVE-2026-15533
DedeCMS Column Management search.php code injection
33RISK
open
Referência
CVE-2026-15532
SourceCodester Online Book Store System User Management cross site scripting
33RISK
open
Referência
CVE-2026-15511
Comfast CF-WR631AX V3 FastCGI Backend webmgnt system_wl_upload_pic_file os command injection
48RISK
open
Referência
CVE-2026-15508
Helicone ai-gateway AWS Metadata Service service.rs build_target_url server-side request forgery
33RISK
open
Referência
CVE-2026-15507
coollabsio Coolify Policy Policies authorization
33RISK
open
Referência
CVE-2026-19000
JeecgBoot Anonymous Chat Attachment send server-side request forgery
33RISK
open
Referência
CVE-2026-18998
cosmicstack-labs mercury-agent delegate_task Tool sub-agent.ts SubAgent.run improper authorization
33RISK
open
Referência
CVE-2026-18997
cosmicstack-labs mercury-agent bg agent.ts Agent.handleBgCommand authorization
33RISK
open
Referência
CVE-2026-18996
cosmicstack-labs mercury-agent run_command permissions.ts PermissionManager.checkShellCommand privileges assignment
33RISK
open
Referência
CVE-2026-18995
netease-youdao LobsterAI MEDIA Path artifactParser.ts parseMediaTokensFromText information disclosure
33RISK
open
Referência
CVE-2026-18993
NousResearch hermes-agent Memory Toolset model_tools.py access control
33RISK
open
Referência
CVE-2026-18992
zhayujie CowAgent Self-Evolution Review Agent executor.py _select_tools authorization
33RISK
open
Referência
CVE-2020-11698
An issue was discovered in Titan SpamTitan 7.07. Improper input sanitization of the parameter community on the page snmp
60RISK
open
Referência
CVE-2020-11978
CVE-2020-11978HIGHunder attack
An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was disco
100RISK
open
Referência
PandoraFMS 7.0 NG 746 - Persistent Cross-Site Scripting
CVE-2020-11749webappsphp
Pandora FMS 7.0 NG <= 746 suffers from Multiple XSS vulnerabilities in different browser views. A network administrator
28RISK
open
Referência
CVE-2026-59509
Unauthenticated arbitrary MongoDB collection read in cve-search
48RISK
open
Referência
CVE-2026-18991
nanocoai NanoClaw send_file core.ts path traversal
33RISK
open
Referência
CVE-2026-18990
letta-ai LettaBot API Status Route server.ts missing authentication
33RISK
open
Referência
CVE-2026-18980
nearai ironclaw shell.rs classify_command_risk command injection
33RISK
open
Referência
CVE-2026-18976
NousResearch hermes-agent disabled_toolsets agent_init.py get_tool_definitions privileges assignment
33RISK
open
Referência
CVE-2026-18974
heshengtao super-agent-party execute_tool_manually Endpoint server.py get_file_content information disclosure
33RISK
open
Referência
CVE-2026-18973
heshengtao super-agent-party extension_proxy Route server.py sanitize_proxy_url server-side request forgery
33RISK
open
Referência
CVE-2026-70620
Odysseus SSRF via Embedding Endpoint Configuration
33RISK
open
Referência
CVE-2026-18814
H3C NX15 esps reload.reload_config command injection
41RISK
open
previouspage 483 / 747next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.