Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,620cataloged exploits
35,647CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,429GitHub PoC 14,270VulnCheck XDB 8,693Nuclei 4,299Metasploit 3,474✓ verified onlyrecentpopularrisk
22,407 exploits
Referência
CVE-2019-25763
WordPress Ultimate Addons for Beaver Builder 1.2.4.1 Authentication Bypass
48RISK
open ↗Referência
CVE-2017-20280
Joomla Component Myportfolio 3.0.2 SQL Injection via pid Parameter
41RISK
open ↗Referência
CVE-2019-12181
A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux.
50RISK
open ↗Referência
CVE-2026-24066
Slate Digital Connect macOS XPC certificate validation privilege escalation
41RISK
open ↗Referência
CVE-2026-9067
Schema & Structured Data for WP & AMP < 1.60 - Unauthenticated Arbitrary Media Upload
48RISK
open ↗Referência
CVE-2017-20248
WordPress Plugin Apptha Slider Gallery 1.0 Path Traversal File Download
41RISK
open ↗Referência
CVE-2026-11557
Tenda F451 Web Management Natlimit fromNatlimit stack-based overflow
41RISK
open ↗Referência
CVE-2026-39908
OpenBullet2 0.3.2 NTLMv2 Hash Disclosure via UNC Path Proxy Source
41RISK
open ↗Referência
CVE-2026-11533
imvks786 student_management_system Student Deletion Endpoint see.php improper authorization
33RISK
open ↗Referência
CVE-2026-11532
imvks786 student_management_system Student Record add.php access control
33RISK
open ↗Referência
CVE-2026-11506
CodeAstro Leave Management System search_staff_for_deletion.php sql injection
33RISK
open ↗Referência
CVE-2026-11504
Tenda CX12L Wi-Fi Schedule Configuration Endpoint openSchedWifi setSchedWifi stack-based overflow
41RISK
open ↗Referência
CVE-2019-12372
Petraware pTransformer ADC before 2.1.7.22827 allows SQL Injection via the User ID parameter to the login form.
23RISK
open ↗Referência
CVE-2019-13272
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISK
open ↗Referência
CVE-2019-13272
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISK
open ↗Referência
CVE-2019-13272
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISK
open ↗Referência
CVE-2019-13272
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISK
open ↗Referência
CVE-2026-14549
Ray Enterprise Translation <= 1.7.3 - Subscriber+ Language Addition and Deletion
33RISK
open ↗Referência
CVE-2026-14548
Ray Enterprise Translation <= 1.7.3 - Subscriber+ Arbitrary API Token Update
33RISK
open ↗Referência
CVE-2026-73030
unearth 0.18.2 Path Traversal via Unnormalized Paths and Symlink Escape
41RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.