Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,325cataloged exploits
36,055CVEs with public exploitation
24,695lab-tested
22,573 exploits
Referência
CVE-2026-7672
youlaitech youlai-boot Users Endpoint UserController.java getUserList sql injection
33RISK
open
Referência
CVE-2026-7671
CodeWise Tornet Scooter Mobile App TwoFactor excessive authentication
33RISK
open
Referência
CVE-2026-7669
sgl-project SGLang HuggingFace Transformer hf_transformers_utils.py get_tokenizer code injection
33RISK
open
Referência
CVE-2026-7669
sgl-project SGLang HuggingFace Transformer hf_transformers_utils.py get_tokenizer code injection
33RISK
open
Referência
CVE-2026-7668
MikroTik RouterOS SCEP Endpoint scep.p ASN1_STRING_data out-of-bounds
33RISK
open
Referência
CVE-2026-7653
r-huijts mcp-server-rijksmuseum MCP index.ts open_image_in_browser os command injection
33RISK
open
Referência
CVE-2026-56122
Winstone Servlet Engine 0.9.10 Path Traversal via HTTP Request Paths
41RISK
open
Referência
CVE-2026-56121
Feast < 0.63.0 Unauthenticated RCE via ApplyFeatureView gRPC Deserialization
48RISK
open
Referência
CVE-2026-56111
Marlin Firmware 2.1.2.7 Out-of-Bounds Write via M421 G-code Handler
41RISK
open
Referência
CVE-2026-7384
ezequiroga mcp-bases research_server.py search_papers path traversal
33RISK
open
ReferênciaVexDay Proof
Kostenloses Linkmanagementscript - Remote File Inclusion
CVE-2008-2270webappsphp
Multiple PHP remote file inclusion vulnerabilities in PHPWAY Kostenloses Linkmanagementscript allow remote attackers to
23RISK
open
Referência
CVE-2026-9815
MagicForm <= 0.1.3 - Unauthenticated Arbitrary File Upload to RCE
33RISK
open
Referência
CVE-2026-55200
libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c
48RISK
open
ReferênciaVexDay Proof
Enthrallweb emates 1.0 - 'newsdetail.asp' SQL Injection
CVE-2006-6806webappsasp
SQL injection vulnerability in newsdetail.asp in Enthrallweb eMates 1.0 allows remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
Prozilla Hosting Index - 'id' SQL Injection
CVE-2008-6115webappsphp
SQL injection vulnerability in directory.php in Prozilla Hosting Index allows remote attackers to execute arbitrary SQL
23RISK
open
Referência
CVE-2019-9194
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
60RISK
open
Referência
CVE-2019-9194
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
60RISK
open
ReferênciaVexDay Proof
Internet PhotoShow (Special Edition) - Insecure Cookie Handling
CVE-2008-2282webappsphp
admin.php in Internet Photoshow and Internet Photoshow Special Edition (SE) allows remote attackers to bypass authentica
23RISK
open
Referência
CVE-2023-33246
CVE-2023-33246CRITICALunder attack
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RISK
open
Referência
CVE-2023-33246
CVE-2023-33246CRITICALunder attack
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RISK
open
Referência104
CVE-2023-33246 RocketMQ RCE Detect By Version and Exploit
CVE-2023-33246CRITICALunder attack
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RISK
open
ReferênciaVexDay Proof
idautomation bar code - ActiveX Multiple Vulnerabilities
CVE-2008-2283remotewindows
IDAutomation allows remote attackers to overwrite arbitrary files via the argument to the (1) SaveBarCode and (2) SaveEn
23RISK
open
Referência
CVE-2026-10815
LakshayD02 Hostel-Management-System-PHP Admin Dashboard index.php authorization
33RISK
open
Referência
CVE-2026-10814
milvus-io milvus Grantee ID Hash kv_catalog.go weak hash
28RISK
open
Referência
CVE-2026-10812
zilliztech GPTCache Cache Key pre.py BufferedReader.peek weak hash
28RISK
open
Referência
CVE-2023-46747
CVE-2023-46747CRITICALunder attackransomware
BIG-IP Configuration utility unauthenticated remote code execution vulnerability
100RISK
open
Referência
CVE-2019-25745
WordPress Plugin Google Review Slider 6.1 SQL Injection via tid
41RISK
open
Referência
CVE-2019-25735
AllPlayer 7.4 Local Buffer Overflow via SEH Unicode
41RISK
open
Referência
CVE-2020-8260
CVE-2020-8260HIGHunder attack
A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform
100RISK
open
Referência
CVE-2020-11651
CVE-2020-11651CRITICALunder attack
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.