Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,620cataloged exploits
35,647CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,429GitHub PoC 14,270VulnCheck XDB 8,693Nuclei 4,299Metasploit 3,474✓ verified onlyrecentpopularrisk
22,407 exploits
Referência
CVE-2026-9469
yashpokharna2555 StudentManagementSystem success.php sql injection
33RISK
open ↗Referência
CVE-2026-9467
debugmcp mcp-debugger server.ts handleGetSourceContext path traversal
33RISK
open ↗Referência
CVE-2026-9466
Tiandy Easy7 Integrated Management Platform API Endpoint updateUserPassword password recovery
33RISK
open ↗Referência
CVE-2019-0708
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open ↗Referência
CVE-2019-0708
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open ↗Referência
CVE-2019-0708
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open ↗Referência
CVE-2026-8291
Open5GS NRF nnrf-handler.c ogs_nnrf_nfm_handle_nf_profile denial of service
33RISK
open ↗Referência
CVE-2026-9361
Edimax EW-7438RPn POST Request formAccep formAccept command injection
33RISK
open ↗Referência
CVE-2026-8252
Open5GS SMF smf_nsmf_handle_create_data_in_hsmf null pointer dereference
33RISK
open ↗Referência
CVE-2026-8248
Open5GS SMF npcf-handler.c update_authorized_pcc_rule_and_qos denial of service
33RISK
open ↗Referência
CVE-2021-47953
OpenCart 3.0.3.7 Cross-Site Request Forgery via account/password
33RISK
open ↗Referência
CVE-2021-47949
CyberPanel 2.1 Authenticated Remote Code Execution via Symlink Attack
41RISK
open ↗Referência
CVE-2021-47947
Projectsend r1295 Stored Cross-Site Scripting via files-edit.php
33RISK
open ↗Referência
CVE-2021-47946
OpenCart 3.0.3.6 Account Takeover via Cross Site Request Forgery
33RISK
open ↗Referência
CVE-2021-47945
Argus Surveillance DVR 4.0 Unquoted Service Path Privilege Escalation
41RISK
open ↗Referência
CVE-2021-47937
e107 CMS 2.3.0 Authenticated Remote Code Execution via Theme Upload
41RISK
open ↗Referência
CVE-2026-9356
SourceCodester Hospitals Patient Records Management System manage_history.php sql injection
33RISK
open ↗Referência
CVE-2026-9350
NousResearch hermes-agent Batch Runner approval.py check_all_command_guards authorization
33RISK
open ↗Referência
CVE-2026-9349
calcom cal.diy Generic React API bookings-single-view.getServerSideProps.tsx getServerSideProps information disclosure
33RISK
open ↗Referência
CVE-2018-25352
WordPress Ultimate Form Builder Lite 1.3.7 SQL Injection via entry_id
41RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.