Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,533cataloged exploits
35,607CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,407GitHub PoC 14,247VulnCheck XDB 8,663Nuclei 4,287Metasploit 3,474✓ verified onlyrecentpopularrisk
22,407 exploits
Referência
CVE-2026-10209
code-projects Online Hospital Management System Appointment appointmentdetail.php sql injection
33RISK
open ↗Referência
CVE-2026-10208
code-projects Online Hospital Management System login_1.php login_user sql injection
33RISK
open ↗Referência
CVE-2019-7440
JioFi 4G M2S 1.0.2 devices have CSRF via the SSID name and Security Key field under Edit Wi-Fi Settings (aka a SetWiFi_S
23RISK
open ↗Referência
CVE-2019-7442
An XML external entity (XXE) vulnerability in the Password Vault Web Access (PVWA) of CyberArk Enterprise Password Vault
35RISK
open ↗Referência
CVE-2019-8196
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
28RISK
open ↗Referência
CVE-2019-8452
A hard-link created from log file archive of Check Point ZoneAlarm up to 15.4.062 or Check Point Endpoint Security clien
23RISK
open ↗Referência
CVE-2019-8926
An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zon
23RISK
open ↗Referência
CVE-2026-9458
Totolink A8000RU Web Management cstecgi.cgi setWanCfg os command injection
48RISK
open ↗Referência
CVE-2026-9457
Totolink A8000RU Web Management cstecgi.cgi UploadFirmwareFile os command injection
48RISK
open ↗Referência
CVE-2026-9451
code-projects Employee Management System applyleaveprocess.php sql injection
33RISK
open ↗Referência
CVE-2026-67349
OpenCost < 1.121.0 Unauthenticated Helm Values Exposure and Admin Bypass
41RISK
open ↗Referência
CVE-2026-67348
Julep Insecure Direct Object Reference via GET /executions/{execution_id}
41RISK
open ↗Referência
CVE-2026-67347
Vendure 3.7.1 Cross-Channel Authorization Bypass via StockLocation and Asset Update
33RISK
open ↗Referência
CVE-2026-67345
MaxKey 4.1.12 DefaultRedirectResolver OAuth Authorization Code Theft
41RISK
open ↗Referência
CVE-2026-14310
Tutor LMS < 4.0.0 - Subscriber+ Cross-Course Q&A Content Disclosure and Reply Injection
33RISK
open ↗Referência
CVE-2026-14305
WP Delicious < 1.10.2 - Unauthenticated Arbitrary Post Meta Update via recipe_likes
33RISK
open ↗Referência✓ VexDay Proof
Free MP3 CD Ripper 2.6 - '.mp3' Buffer Overflow (SEH)
Stack-based buffer overflow in Free MP3 CD Ripper 2.6, when converting a file, allows user-assisted remote attackers to
23RISK
open ↗Referência✓ VexDay Proof
Free MP3 CD Ripper 2.6 - '.wma' Local Buffer Overflow (SEH)
Stack-based buffer overflow in Free MP3 CD Ripper 2.6, when converting a file, allows user-assisted remote attackers to
23RISK
open ↗Referência✓ VexDay Proof
AirMore 1.6.1 - Denial of Service (PoC)
The AirMore application through 1.6.1 for Android allows remote attackers to cause a denial of service (system hang) via
23RISK
open ↗Referência
AirDrop 2.0 - Denial of Service (DoS)
The AirDrop application through 2.0 for Android allows remote attackers to cause a denial of service via a client that m
23RISK
open ↗Referência
NetData 1.13.0 - HTML Injection
The Netdata web application through 1.13.0 allows remote attackers to inject their own malicious HTML code into an impor
23RISK
open ↗Referência
CVE-2026-9368
NousResearch hermes-agent Environment Variable code_execution_tool.py execute_code sandbox
33RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.