Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,620cataloged exploits
35,647CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,429GitHub PoC 14,270VulnCheck XDB 8,693Nuclei 4,299Metasploit 3,474✓ verified onlyrecentpopularrisk
22,429 exploits
Referência
CVE-2026-11344
code-projects Vehicle Management System New Driver Registration Form newdriver.php unrestricted upload
33RISK
open ↗Referência
CVE-2026-11342
code-projects Hotel and Tourism Reservation System details.php sql injection
33RISK
open ↗Referência
CVE-2020-37227
WordPress Plugin HS Brand Logo Slider 2.1 Unrestricted File Upload
41RISK
open ↗Referência
CVE-2018-25331
Zenar Content Management System Cross-Site Scripting via ajax.php
33RISK
open ↗Referência
CVE-2020-10220
An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php
60RISK
open ↗Referência
CVE-2020-10220
An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php
60RISK
open ↗Referência
CVE-2020-10220
An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php
60RISK
open ↗Referência
CVE-2026-66731
facil.io 0.7.5 - 0.7.6 HTTP/1.1 Chunked Transfer Encoding Parser Crash DoS
41RISK
open ↗Referência
CVE-2026-66730
facil.io 0.6.0 - 0.7.6 Infinite Loop DoS via Multipart MIME Body Parser
41RISK
open ↗Referência
CVE-2026-66729
facil.io 0.6.0 - 0.7.6 Integer Underflow DoS via Multipart MIME Body Parser
41RISK
open ↗Referência
CVE-2026-15217
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
41RISK
open ↗Referência
CVE-2026-15216
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
41RISK
open ↗Referência
CVE-2026-69114
Spacebar Server Cross-Channel Message Deletion via Permission Check Bypass
41RISK
open ↗Referência
CVE-2026-18470
Login & Register Forms < 4.0.2 - Unauthenticated Registered User Email Address Disclosure via Lost Password Response
41RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.