Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,008cataloged exploits
34,638CVEs with public exploitation
24,695lab-tested
21,624 exploits
Referência
CVE-2026-6007
itsourcecode Construction Management System del.php sql injection
33RISK
open
Referência
CVE-2026-6006
code-projects Patient Record Management System edit_hpatient.php sql injection
33RISK
open
Referência
CVE-2026-6005
code-projects Patient Record Management System hematology_print.php sql injection
33RISK
open
Referência
CVE-2026-6004
code-projects Simple IT Discussion Forum delete-category.php sql injection
33RISK
open
ReferênciaVexDay Proof
ig shop 1.0 - Code Execution / SQL Injection
CVE-2007-0134webappsphp
Multiple eval injection vulnerabilities in iGeneric iG Shop 1.0 allow remote attackers to execute arbitrary code via the
28RISK
open
ReferênciaVexDay Proof
Aratix 0.2.2b11 - '/inc/init.inc.php' Remote File Inclusion
CVE-2007-0135webappsphp
PHP remote file inclusion vulnerability in inc/init.inc.php in Aratix 0.2.2 beta 11 and earlier, when register_globals i
23RISK
open
Referência
CVE-2026-5992
Tenda F451 P2pListFilter fromP2pListFilter stack-based overflow
41RISK
open
ReferênciaVexDay Proof
Quote&Ordering System 1.0 - 'ordernum' Multiple Vulnerabilities
CVE-2007-0144webappsasp
Cross-site scripting (XSS) vulnerability in search.asp in Digitizing Quote And Ordering System 1.0 allows remote authent
23RISK
open
ReferênciaVexDay Proof
OmniWeb 5.5.1 - JavaScript alert() Remote Format String (PoC)
CVE-2007-0148dososx
Format string vulnerability in OmniGroup OmniWeb 5.5.1 allows remote attackers to cause a denial of service (application
23RISK
open
ReferênciaVexDay Proof
AllMyVisitors 0.4.0 - 'index.php' Remote File Inclusion
CVE-2007-0170webappsphp
PHP remote file inclusion vulnerability in index.php in AllMyVisitors 0.4.0 allows remote attackers to execute arbitrary
23RISK
open
Referência
CVE-2018-25293
Prime95 29.4b7 Denial of Service via Proxy Password Field
33RISK
open
Referência
CVE-2018-25292
Bome Restorator 1793 Denial of Service via Buffer Overflow
33RISK
open
Referência
CVE-2018-25291
Project64 2.3.2 Denial of Service via Plugin Directory
33RISK
open
Referência
CVE-2018-25290
Easyboot 6.6.0 Buffer Overflow Denial of Service
33RISK
open
Referência
CVE-2018-25289
Softdisk 3.0.3 Buffer Overflow Denial of Service
33RISK
open
Referência
CVE-2018-25288
StyleWriter 1.0 Denial of Service via Pattern Input
33RISK
open
Referência
CVE-2026-5970
FoundationAgents MetaGPT HumanEvalBenchmark/MBPPBenchmark check_solution code injection
33RISK
open
Referência
CVE-2026-5962
Tenda CH22 httpd R7WebsSecurityHandlerfunction path traversal
33RISK
open
Referência
CVE-2026-5961
code-projects Simple IT Discussion Forum topic-details.php sql injection
33RISK
open
Referência
CVE-2026-5960
code-projects Patient Record Management System SQL Database Backup File hcpms.sql information disclosure
33RISK
open
Referência
CVE-2016-20055
IObit Advanced SystemCare 10.0.2 Unquoted Service Path Privilege Escalation
41RISK
open
ReferênciaVexDay Proof
uniForum 4 - 'wbsearch.aspx' SQL Injection
CVE-2007-0226webappsphp
SQL injection vulnerability in wbsearch.aspx in uniForum 4 and earlier allows remote attackers to execute arbitrary SQL
23RISK
open
Referência
CVE-2018-25277
PixGPS 1.1.8 Buffer Overflow Denial of Service
33RISK
open
Referência
CVE-2018-25276
RoboImport 1.2.0.72 Denial of Service via Registration Fields
33RISK
open
Referência
CVE-2018-25275
Faleemi Plus 1.0.2 Denial of Service via Buffer Overflow
33RISK
open
Referência
CVE-2018-25274
InfraRecorder 0.53 Denial of Service via txt File Import
33RISK
open
Referência
CVE-2018-25273
CrossFont 7.5 Denial of Service via License Key Field
33RISK
open
ReferênciaVexDay Proof
sNews 1.5.30 - Remote Reset Admin Pass / Command Execution
CVE-2007-0261webappsphp
snews.php in sNews 1.5.30 and earlier does not properly exit when authentication fails, which allows remote attackers to
23RISK
open
Referência
CVE-2026-7019
Tenda F456 P2pListFilter fromP2pListFilter buffer overflow
41RISK
open
Referência
CVE-2026-7018
Datavane Datavines JWT Token TokenManager.java hard-coded key
33RISK
open
previouspage 247 / 721next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.