Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,008cataloged exploits
34,638CVEs with public exploitation
24,695lab-tested
21,662 exploits
Referência
CVE-2019-3396
CVE-2019-3396CRITICALunder attackransomware
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISK
open
Referência
CVE-2018-0296
CVE-2018-0296HIGHunder attack
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remo
100RISK
open
Referência
CVE-2018-0296
CVE-2018-0296HIGHunder attack
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remo
100RISK
open
Referência
CVE-2021-22986
CVE-2021-22986CRITICALunder attackransomware
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISK
open
Referência
CVE-2021-22986
CVE-2021-22986CRITICALunder attackransomware
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISK
open
Referência
CVE-2019-1653
CVE-2019-1653HIGHunder attack
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RISK
open
Referência
CVE-2019-1653
CVE-2019-1653HIGHunder attack
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RISK
open
Referência
CVE-2021-33044
CVE-2021-33044CRITICALunder attack
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RISK
open
Referência
CVE-2021-36260
CVE-2021-36260CRITICALunder attack
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISK
open
Referência
CVE-2021-36260
CVE-2021-36260CRITICALunder attack
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISK
open
Referência
CVE-2020-13379
The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows
60RISK
open
Referência
CVE-2023-0600
WP Visitor Statistics (Real Time Traffic) < 6.9 - Unauthenticated SQLi
63RISK
open
Referência
CVE-2017-8917
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RISK
open
Referência
CVE-2017-8917
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RISK
open
Referência
CVE-2017-7269
CVE-2017-7269CRITICALunder attack
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open
Referência
CVE-2025-34103
WePresent WiPG-1000 Unauthenticated Command Injection in via rdfs.cgi
63RISK
open
Referência
CVE-2023-21839
CVE-2023-21839HIGHunder attack
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
100RISK
open
Referência
CVE-2022-1040
CVE-2022-1040CRITICALunder attack
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sopho
100RISK
open
Referência
CVE-2020-7961
CVE-2020-7961CRITICALunder attack
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RISK
open
Referência
CVE-2020-7961
CVE-2020-7961CRITICALunder attack
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RISK
open
Referência
CVE-2021-31207
CVE-2021-31207MEDIUMunder attackransomware
Microsoft Exchange Server Security Feature Bypass Vulnerability
100RISK
open
Referência
CVE-2019-15107
CVE-2019-15107CRITICALunder attackransomware
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
Referência
CVE-2019-15107
CVE-2019-15107CRITICALunder attackransomware
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
Referência
CVE-2019-15107
CVE-2019-15107CRITICALunder attackransomware
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
Referência
CVE-2025-34103
WePresent WiPG-1000 Unauthenticated Command Injection in via rdfs.cgi
63RISK
open
Referência
CVE-2019-15107
CVE-2019-15107CRITICALunder attackransomware
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
Referência
Sophos XG115w Firewall 17.0.10 MR-10 - Authentication Bypass
CVE-2022-1040CRITICALunder attackwebappshardware
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sopho
100RISK
open
Referência
CVE-2024-13159
CVE-2024-13159CRITICALunder attack
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up
100RISK
open
Referência
CVE-2021-34527
CVE-2021-34527HIGHunder attackransomware
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
Referência
CVE-2022-47966
CVE-2022-47966CRITICALunder attackransomware
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RISK
open
previouspage 262 / 723next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.