CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build

State now. Changed: 0 tier promotions, +4 known-exploited vulnerability additions, 27 leak-site claims, and 0 confirmed breaches since yesterday.

Why today matters · Analyst view

Exploits

Public exploit and proof-of-concept entries from Exploit-DB, maintained by OffSec, linked to the Common Vulnerabilities and Exposures (CVE) identifiers they target. This page carries metadata and links only, and never hosts or mirrors exploit code: every entry links out to its Exploit-DB page.

Why now: 41 public exploit records were published in the last 30 days.

46,688 Exploit Database records in this site build41 published in the last 30 days33,776 verified all-time

Source: Exploit-DB (OffSec)

What changed

This page does not publish a page-specific change count. Open the daily comparison for material tracker changes, then use the publication windows below for new exploit records.

Details

The legend defines the source fields, and the publication window and filters sit beside the source-linked records.

Showing the newest 5,000 of 46,688 tracked Exploit-DB entries, published since 2019-08-30. Filters, search, and the all-dates view cover every entry and load on demand.

Published within
41 matches
CVEs
EDB-52682 ↗CVE-2026-80428 Unauthenticated PHP Object Injection via Shibboleth - ILIAS < 9.22_ 10.0 < 10.10_ 11.0 < 11.3 - RCEremotemultipleNot verifiedCVE-2026-80428
EDB-52681 ↗FreePBX 17.0.2 - Remote Code Execution (RCE)webappsmultipleNot verifiedCVE-2025-57819
EDB-52680 ↗Metabase 0.61.0 - Authenticated Remote Code ExecutionwebappsmultipleNot verifiedCVE-2026-59827
EDB-52679 ↗EVerest 2025.9.0 - DoSdosmultipleNot verifiedCVE-2025-68137
EDB-52678 ↗Bludit CMS 3.20.0 - Reflected Cross-Site ScriptingwebappsmultipleNot verifiedCVE-2026-41456
EDB-52677 ↗PodcastGenerator 3.2.9 - Stored XSSwebappsmultipleNot verifiedCVE-2025-70336
EDB-52676 ↗Ghost_CMS 6.19.0 - Remote Code ExecutionwebappsmultipleNot verifiedCVE-2026-29053
EDB-52675 ↗Langflow 1.10.0 - RCEwebappsmultipleNot verifiedCVE-2026-9198
EDB-52674 ↗Fullhan FH8626V100 - Multiple VulnerabilitieshardwaremultipleNot verifiedCVE-2026-51402CVE-2026-51403CVE-2026-51404CVE-2026-51405CVE-2026-51406CVE-2026-51407
EDB-52673 ↗Marimo 0.20.4 - RCEwebappsmultipleNot verifiedCVE-2026-39987
EDB-52672 ↗Wolf CMS 0.8.3.1 - RCE vwebappsmultipleNot verifiedCVE-2026-67206
EDB-52671 ↗Payload CMS 3.72.0 - Blind SQL InjectionwebappsmultipleNot verifiedCVE-2026-25544
EDB-52670 ↗Bludit CMS - Stored XSSwebappsmultipleNot verifiedNone listed
EDB-52669 ↗Grav CMS 2.0.7 - RCEwebappsmultipleNot verifiedCVE-2026-65008
EDB-52668 ↗miniOrange 5.4.3 - Unauthenticated Auth BypasswebappsmultipleNot verifiedCVE-2026-15013
EDB-52667 ↗EasyAppointments 1.5.1 - Blind SQL InjectionwebappsmultipleNot verifiedCVE-2025-50455
EDB-52666 ↗C-MOR 6.0104 - Directory TraversalwebappsmultipleNot verifiedCVE-2026-51134
EDB-52665 ↗C-MOR 6.0104 - Cross-Site Scripting (XSS)webappshardwareNot verifiedCVE-2026-51133
EDB-52664 ↗CubeCart 6.7.4 - SQL injectionwebappsmultipleNot verifiedCVE-2026-54647
EDB-52663 ↗CubeCart 6.7.4 - SQLwebappsmultipleNot verifiedCVE-2026-54646
EDB-52662 ↗CubeCart 6.7.4 - Stored XSSwebappsmultipleNot verifiedCVE-2026-54645
EDB-52661 ↗CubeCart 6.7.4 - Cross-Site ScriptingwebappsmultipleNot verifiedCVE-2026-54644
EDB-52660 ↗Linksys E1200_2.0.04 - Unauthenticated OS Command InjectionwebappshardwareNot verifiedCVE-2025-60689
EDB-52659 ↗Langflow 1.8.4 - Path Traversal to Remote Code ExecutionwebappsmultipleNot verifiedCVE-2026-5027
EDB-52658 ↗CVE-2026-42167 - ProFTPD mod_sql post-authentication SQLi - RCEremotemultipleNot verifiedCVE-2026-42167
EDB-52657 ↗PCMan 2.0.7 - Buffer OverflowremotewindowsNot verifiedCVE-2025-4871
EDB-52656 ↗NanaZip 6.5 - DoSdosmultipleNot verifiedNone listed
EDB-52655 ↗flyto-core 2.26.7 - Arbitrary File WritewebappsmultipleNot verifiedNone listed
EDB-52654 ↗Nodemailer 9.0.0 - File Read/ SSRFwebappsmultipleNot verifiedNone listed
EDB-52653 ↗Linuxfabrik monitoring_plugins_6.0.0 - SSRFwebappsmultipleNot verifiedNone listed
EDB-52652 ↗NanaZip 6.5 - DoSdoswindowsNot verifiedCVE-2026-55780
EDB-52651 ↗flyto_core 2.26.7 - Server-Side Request ForgerywebappsmultipleNot verifiedNone listed
EDB-52650 ↗Probo 0.222.2 - IDORwebappsmultipleNot verifiedCVE-2026-63505
EDB-52649 ↗webpack_devserver 5.2.5 - CSRFwebappsmultipleNot verifiedCVE-2026-14620
EDB-52648 ↗phpSysInfo 3.4.5 - IP Allowlist BypassremotelinuxNot verifiedCVE-2026-55584
EDB-52647 ↗Nmap 7.99 - Extension Header Integer UnderflowdosmultipleNot verifiedCVE-2026-58058
EDB-52646 ↗Duplicati 2.2.0.3 - JWT Signing Key LeakwebappsmultipleNot verifiedNone listed
EDB-52645 ↗Joomla JCE_2.9.15 - Remote Code ExecutionwebappsmultipleNot verifiedCVE-2026-48907
EDB-52644 ↗ipTIME A3004T - Remote Code ExecutionremotemultipleNot verifiedNone listed
EDB-52643 ↗D-Link DNS_340L - OS Command InjectionremotehardwareNot verifiedCVE-2024-10914
EDB-52642 ↗WooCommerce 1.5.0 - Unauthenticated Arbitrary File UploadwebappsmultipleNot verifiedCVE-2026-3891
About this data

Entries come from the Exploit-DB metadata index, maintained by OffSec. This page tracks metadata and links only: the title, publication date, exploit type, target platform, Exploit-DB's own verification flag, and the CVE identifiers each entry references. It never hosts, mirrors, or links to exploit code directly; the EDB column links to the entry's page on Exploit-DB, where the metadata and any code live. A CVE this tracker follows is a link into the vulnerabilities table; an untracked CVE is shown as plain text. The Verified badge is Exploit-DB's flag, not a verification by this tracker. The published-date window filters the same way the vulnerabilities view does: a segment shows only entries published within it, and an entry with no publication date appears under All only.

Browse every record in stable static pages, for search engines and no-JavaScript access to the full catalog.

Exploit-DB data is provided byExploit-DB (OffSec)and is licensed underGPL-2.0. There is also an Exploit-DB RSS feed.

How this is computed

Records come from the Exploit Database metadata index. Publication windows use the source date, undated entries appear only under All, and this site publishes metadata and links rather than exploit code.

Method reviewed on .

Glossary