Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,107cataloged exploits
34,679CVEs with public exploitation
24,695lab-tested
21,692 exploits
Referência
CVE-2015-2097
Multiple buffer overflows in WebGate Embedded Standard Protocol (WESP) SDK allow remote attackers to execute arbitrary c
28RISK
open
Referência
CVE-2026-14737
Hanwang e-Face General Management Platform querySysAuthStr.do sql injection
33RISK
open
Referência
CVE-2015-2097
Multiple buffer overflows in WebGate Embedded Standard Protocol (WESP) SDK allow remote attackers to execute arbitrary c
28RISK
open
Referência
CVE-2026-14717
itsourcecode Hospital Management System patientlogin.php sql injection
33RISK
open
Referência
CVE-2026-14716
nextlevelbuilder GoClaw WebSocket RPC router.go MethodRouter.Handle authorization
33RISK
open
Referência
CVE-2026-14714
zhayujie chatgpt-on-wechat CowAgent wx Endpoint common.py verify_server missing authentication
33RISK
open
Referência
CVE-2020-15261
Unquoted service path vulnerability on Veyon
46RISK
open
Referência
CVE-2026-14713
SourceCodester Pizzafy E-Commerce System ajax.php confirm_order sql injection
33RISK
open
Referência
CVE-2026-14706
code-projects Online Examination Quiz Creation Feature update.php sql injection
33RISK
open
Referência
CVE-2013-4625
Cross-site scripting (XSS) vulnerability in files/installer.cleanup.php in the Duplicator plugin before 0.4.5 for WordPr
43RISK
open
Referência
CVE-2026-14705
code-projects Online Examination head.php sql injection
33RISK
open
Referência
CVE-2016-8020
Improper control of generation of code vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earl
28RISK
open
Referência
CVE-2026-14701
code-projects Internship Management System Password Change Endpoint change_password.php sql injection
33RISK
open
Referência
CVE-2026-14630
ForceInjection AI-fundermentals Memory Recall smart_customer_service.py get_conversation_history weak hash
28RISK
open
Referência
CVE-2009-4805
Multiple SQL injection vulnerabilities in EZ-Blog Beta 1, when magic_quotes_gpc is disabled, allow remote attackers to e
23RISK
open
Referência
CVE-2009-4807
Multiple SQL injection vulnerabilities in Graugon PHP Article Publisher 1.0 allow remote attackers to execute arbitrary
23RISK
open
Referência
CVE-2011-1761
Multiple stack-based buffer overflows in the (1) abc_new_macro and (2) abc_new_umacro functions in src/load_abc.cpp in l
28RISK
open
Referência
CVE-2017-6320
A remote command injection vulnerability exists in the Barracuda Load Balancer product line (confirmed on v5.4.0.004 (20
28RISK
open
Referência
CVE-2017-17867
Inteno iopsys 2.0-3.14 and 4.0 devices allow remote authenticated users to execute arbitrary OS commands by modifying th
28RISK
open
Referência
CVE-2017-7397
BackBox Linux 4.6 allows remote attackers to cause a denial of service (ksoftirqd CPU consumption) via a flood of packet
28RISK
open
Referência
CVE-2019-6208
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Moja
23RISK
open
Referência
CVE-2015-2097
Multiple buffer overflows in WebGate Embedded Standard Protocol (WESP) SDK allow remote attackers to execute arbitrary c
28RISK
open
Referência
CVE-2009-2891
SQL injection vulnerability in list.php in PHP Scripts Now Riddles allows remote attackers to execute arbitrary SQL comm
23RISK
open
Referência
CVE-2021-27973
SQL injection exists in Piwigo before 11.4.0 via the language parameter to admin.php?page=languages.
28RISK
open
Referência
CVE-2018-12053
Arbitrary File Deletion exists in PHP Scripts Mall Schools Alert Management Script via the img parameter in delete_img.p
28RISK
open
Referência
CVE-2010-2310
SolarWinds TFTP Server 10.4.0.13 allows remote attackers to cause a denial of service (crash) via a long write request.
28RISK
open
ReferênciaVexDay Proof
VideoLAN VLC Media Player 0.8.6i - Mms Protocol Handling Heap Overflow (PoC)
CVE-2008-3794dosmultiple
Integer signedness error in the mms_ReceiveCommand function in modules/access/mms/mmstu.c in VLC Media Player 0.8.6i all
28RISK
open
Referência
CVE-2022-25090
Printix Secure Cloud Print Management through 1.3.1106.0 creates a temporary temp.ini file in a directory with insecure
28RISK
open
Referência
CVE-2022-25090
Printix Secure Cloud Print Management through 1.3.1106.0 creates a temporary temp.ini file in a directory with insecure
28RISK
open
Referência
UltimateHG/CVE-2025-52689-PoC
Weak Session ID Check in the OmniAccess Stellar Web Management Interface
53RISK
open
previouspage 277 / 724next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.