Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,313cataloged exploits
34,834CVEs with public exploitation
24,695lab-tested
21,797 exploits
Referência
CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
Referência
CVE-2026-66746
Rouille 0.4.0 - 3.6.2 HTTP Response Splitting via Header Injection
33RISK
open
Referência
CVE-2026-66754
Rouille 0.1.6 - 3.6.2 Reachable Assertion DoS via remove_prefix percent-encoding
41RISK
open
Referência
CVE-2026-66753
tiny-http 0.12.0 HTTP Response Splitting via Header Injection
33RISK
open
Referência
CVE-2026-66748
Camaleon CMS 2.1.1 - 2.9.1 Authenticated RCE via select_eval Custom Field
41RISK
open
Referência
CVE-2026-66748
Camaleon CMS 2.1.1 - 2.9.1 Authenticated RCE via select_eval Custom Field
41RISK
open
Referência
CVE-2026-66748
Camaleon CMS 2.1.1 - 2.9.1 Authenticated RCE via select_eval Custom Field
41RISK
open
Referência
CVE-2026-43760
An access issue was addressed with improved access restrictions. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe
41RISK
open
Referência
CVE-2025-15662
Printcart Web to Print Product Designer for WooCommerce < 2.5.3 - Unauthenticated Arbitrary File Read and Server-Side Request Forgery
41RISK
open
Referência
CVE-2026-15193
AidanPark openclaw-android Android WebView Bridge JsBridge.kt os command injection
33RISK
open
Referência
CVE-2026-15184
GNU LibreDWG DWG File dwg.c dwg_next_entity null pointer dereference
33RISK
open
Referência
CVE-2026-14798
CodeAstro Apartment Visitor Management System visitor-entry.php sql injection
33RISK
open
Referência
CVE-2026-53359
KVM: x86: Fix shadow paging use-after-free due to unexpected role
41RISK
open
Referência
CVE-2026-14622
jairiidriss restaurant-website-php-mysql AJAX Endpoint ajax_files missing authentication
33RISK
open
Referência
CVE-2026-10820
ProfilePress < 4.16.17 - Subscriber+ Subscription Cancellation via IDOR
41RISK
open
Referência
CVE-2018-25351
Joomla! Component EkRishta 2.10 SQL Injection via username
41RISK
open
Referência
CVE-2026-9299
omec-project amf handler.go PDUSessionResourceModifyIndication memory corruption
33RISK
open
Referência
CVE-2026-9298
omec-project amf PathSwitchRequest memory corruption
33RISK
open
Referência
CVE-2026-9297
Edimax BR-6428NS POST Request formWlbasic command injection
33RISK
open
Referência
CVE-2021-44529
CVE-2021-44529CRITICALunder attackransomware
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execut
100RISK
open
Referência
CVE-2021-44596
Wondershare LTD Dr. Fone as of 2021-12-06 version is affected by Remote code execution. Due to software design flaws an
28RISK
open
Referência
Online Pre-owned/Used Car Showroom Management System 1.0 - SQLi Authentication Bypass
CVE-2021-44655webappsphp
Online Pre-owned/Used Car Showroom Management System 1.0 contains a SQL injection authentication bypass vulnerability. A
23RISK
open
Referência
CVE-2021-44848
In Cibele Thinfinity VirtualUI before 3.0, /changePassword returns different responses for invalid authentication reques
43RISK
open
Referência
CVE-2021-45092
Thinfinity VirtualUI before 3.0 has functionality in /lab.html reachable by default that could allow IFRAME injection vi
50RISK
open
Referência
CVE-2021-46379
DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through URL redirection to untrust
43RISK
open
Referência
CVE-2021-46398
A Cross-Site Request Forgery vulnerability exists in Filebrowser < 2.18.0 that allows attackers to create a backdoor use
23RISK
open
Referência
CVE-2021-46417
Insecure handling of a download function leads to disclosure of internal files due to path traversal with root privilege
50RISK
open
Referência
CVE-2021-46417
Insecure handling of a download function leads to disclosure of internal files due to path traversal with root privilege
50RISK
open
Referência
CVE-2021-46422
Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute
60RISK
open
Referência
CVE-2022-23642
Code Injection in Sourcegraph
78RISK
open
previouspage 294 / 727next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.