Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,533cataloged exploits
35,607CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,407GitHub PoC 14,247VulnCheck XDB 8,663Nuclei 4,287Metasploit 3,474✓ verified onlyrecentpopularrisk
22,407 exploits
Referência
CVE-2026-12799
BerriAI litellm Incomplete Fix CVE-2025-0628 internal_user_endpoints.py ui_view_users improper authorization
33RISK
open ↗Referência
CVE-2026-12796
BerriAI litellm SSO Authentication Flow ui_sso.py get_redirect_response_from_openid session expiration
33RISK
open ↗Referência
CVE-2026-12795
BerriAI litellm SSO Debug Flow ui_sso.py json.dumps missing authentication
33RISK
open ↗Referência
CVE-2026-12788
zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 XML Parser import xml external entity reference
33RISK
open ↗Referência✓ VexDay Proof
2532/Gigs 1.2.2 Stable - Remote Authentication Bypass
Multiple SQL injection vulnerabilities in checkuser.php in 2532designs 2532|Gigs 1.2.2 Stable, when magic_quotes_gpc is
23RISK
open ↗Referência✓ VexDay Proof
Zeeways Shaadi Clone 2.0 - Authentication Bypass (1)
Zeeways SHAADICLONE 2.0 allows remote attackers to bypass authentication and gain administrative privileges via a direct
23RISK
open ↗Referência
CVE-2012-5388
Cross-site scripting (XSS) vulnerability in wlcms-plugin.php in the White Label CMS plugin 1.5 for WordPress allows remo
23RISK
open ↗Referência
CVE-2026-12183
Nefteprodukttekhnika BUK TS-G Gas Station Automation System Authentication Bypass via ajax-login.php Accepting Arbitrary Credentials
48RISK
open ↗Referência
CVE-2026-12066
PbootCMS Password MemberController.php retrieve password recovery
33RISK
open ↗Referência
CVE-2026-8589
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
41RISK
open ↗Referência
CVE-2026-25860
OpenClinic GA 5.351.19 Reflected XSS via DICOM Image Upload Handler
33RISK
open ↗Referência
CVE-2026-25860 POC git
OpenClinic GA 5.351.19 Reflected XSS via DICOM Image Upload Handler
33RISK
open ↗Referência
CVE-2026-34417
OSCAL-GUI Reflected XSS via project parameter in oscal-forms.php
33RISK
open ↗Referência
CVE-2025-55651
A NULL pointer dereference in the gf_isom_get_user_data_count function (isomedia/isom_read.c) of GPAC MP4Box v2.4 allows
33RISK
open ↗Referência
CVE-2026-11582
CodeAstro Student Attendance Management System index.php sql injection
33RISK
open ↗Referência✓ VexDay Proof
AJ Article 1.0 - Remote Authentication Bypass
AJ Square AJ Article allows remote attackers to bypass authentication and access administrator functionality via a direc
23RISK
open ↗Referência✓ VexDay Proof
Pre Real Estate Listings - Arbitrary File Upload
Unrestricted file upload vulnerability in profile.php in Pre Projects Pre Real Estate Listings allows remote authenticat
23RISK
open ↗Referência
CVE-2012-6045
Cross-site scripting (XSS) vulnerability in gb/user/index.php in Ramui Forum, possibly 1.0 Beta, allows remote attackers
23RISK
open ↗Referência
CVE-2012-6047
Cross-site request forgery (CSRF) vulnerability in X7 Chat 2.0.5.1 and earlier allows remote attackers to hijack the aut
23RISK
open ↗Referência✓ VexDay Proof
Nero ShowTime 5.0.15.0 - '.m3u' Playlist File Remote Buffer Overflow (PoC)
Buffer overflow in Nero ShowTime 5.0.15.0 allows remote attackers to cause a denial of service (crash) and possibly exec
23RISK
open ↗Referência✓ VexDay Proof
ReVou Twitter Clone - Authentication Bypass
Multiple SQL injection vulnerabilities in ReVou Micro Blogging Twitter clone allow remote attackers to execute arbitrary
23RISK
open ↗Referência✓ VexDay Proof
HockeySTATS Online 2.0 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in TheHockeyStop HockeySTATS Online 2.0 Basic and Advanced allow remote attackers
23RISK
open ↗Referência✓ VexDay Proof
Maian Greetings 2.1 - Insecure Cookie Handling
Maian Greetings 2.1 allows remote attackers to bypass authentication and gain administrative privileges by setting the m
23RISK
open ↗Referência✓ VexDay Proof
PhotoPost vBGallery 2.4.2 - Arbitrary File Upload
Unrestricted file upload vulnerability in upload.php in PhotoPost vBGallery 2.4.2 allows remote authenticated users to e
23RISK
open ↗Referência✓ VexDay Proof
Pligg CMS 9.9.0 - Cross-Site Scripting / Local File Inclusion / SQL Injection
Multiple directory traversal vulnerabilities in Pligg 9.9 and earlier allow remote attackers to (1) determine the existe
23RISK
open ↗Referência✓ VexDay Proof
Pligg CMS 9.9.0 - Cross-Site Scripting / Local File Inclusion / SQL Injection
Multiple SQL injection vulnerabilities in Pligg 9.9 and earlier allow remote attackers to execute arbitrary SQL commands
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.