Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,329cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
22,573 exploits
Referência
CVE-2023-38831
CVE-2023-38831HIGHunder attackransomware
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
ReferênciaVexDay Proof
CDNetworks Nefficient Download - 'NeffyLauncher.dll' Code Execution
CVE-2008-1886remotewindows
The NeffyLauncher 1.0.5 ActiveX control (NeffyLauncher.dll) in CDNetworks Nefficient Download uses weak cryptography for
23RISK
open
Referência
CVE-2011-5211
Cross-site scripting (XSS) vulnerability in the poll module in Subrion CMS 2.0.4 allows remote attackers to inject arbit
23RISK
open
Referência
CVE-2026-7740
justdan96 tsMuxer vvc.cpp setFPS denial of service
33RISK
open
Referência
CVE-2026-7739
justdan96 tsMuxer hevc.cpp setFPS denial of service
33RISK
open
Referência
CVE-2026-7738
puchunjie doc-tools-mcp MCP mcp-server.ts open_document path traversal
33RISK
open
Referência
CVE-2026-19897
mangroup dtale Login Endpoint auth.py login excessive authentication
33RISK
open
Referência
CVE-2026-19896
mangroup dtale Flask Session Cookie app.py build_secret_key random values
33RISK
open
Referência
CVE-2026-19895
opensourcepos Open Source Point of Sale Login Endpoint Filters.php index excessive authentication
33RISK
open
Referência
CVE-2023-0777
Authentication Bypass by Primary Weakness in modoboa/modoboa
61RISK
open
ReferênciaVexDay Proof
LaserNet CMS 1.5 - SQL Injection
CVE-2008-1913webappsphp
SQL injection vulnerability in index.php in Lasernet CMS 1.5 and 1.11, when magic_quotes_gpc is disabled, allows remote
23RISK
open
Referência
CVE-2025-32433
CVE-2025-32433CRITICALunder attack
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
Referência
CVE-2026-7732
code-projects BloodBank Managing System request_blood.php unrestricted upload
33RISK
open
Referência
CVE-2026-18216
Backup Migration < 2.1.7 - Admin+ Privilege Escalation via Post-Restore Auto-Login
33RISK
open
ReferênciaVexDay Proof
BlogWorx 1.0 - 'id' SQL Injection
CVE-2008-1915webappsphp
SQL injection vulnerability in view.asp in DevWorx BlogWorx 1.0 allows remote attackers to execute arbitrary SQL command
23RISK
open
Referência
CVE-2026-16611
Product Feed PRO for WooCommerce < 13.5.7 - Unauthenticated Feed Configuration Disclosure
41RISK
open
Referência
CVE-2026-16541
Simply Schedule Appointments < 1.6.12.17 - Team Member+ User Email Disclosure via Users and Customers REST Endpoints
33RISK
open
ReferênciaVexDay Proof
5th Avenue Shopping Cart - 'category_id' SQL Injection
CVE-2008-1921webappsphp
SQL injection vulnerability in store_pages/category_list.php in 5th Avenue Shopping Cart 1.2 trial edition allows remote
23RISK
open
Referência
CVE-2019-18818
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RISK
open
ReferênciaVexDay Proof
Zune Software - ActiveX Arbitrary File Overwrite
CVE-2008-1933remotewindows
Absolute path traversal vulnerability in a certain ActiveX control in Zune allows user-assisted remote attackers to over
28RISK
open
Referência
CVE-2025-61884
CVE-2025-61884HIGHunder attackransomware
Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions
100RISK
open
Referência
CVE-2026-16007
Authenticated SQL Injection in AppFlowy
41RISK
open
Referência
CVE-2026-19834
Webkul Bagisto Admin Customer Impersonation Feature login-as-customer authorization
33RISK
open
Referência
CVE-2026-19829
648540858 wvp-GB28181-pro Log File Download Endpoint LogController.java path traversal
33RISK
open
ReferênciaVexDay Proof
Crazy Goomba 1.2.1 - 'id' SQL Injection
CVE-2008-1934webappsphp
SQL injection vulnerability in commentaires.php in Crazy Goomba 1.2.1 allows remote attackers to execute arbitrary SQL c
23RISK
open
Referência
CVE-2021-40382
An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. mjpegStreamer.cgi allo
28RISK
open
Referência
CVE-2021-3378
FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUpl
60RISK
open
Referência
CVE-2021-3378
FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUpl
60RISK
open
Referência
CVE-2026-19828
648540858 wvp-GB28181-pro Snapshot Endpoint PlayController.java path traversal
33RISK
open
ReferênciaVexDay Proof
Classifieds Caffe - 'cat_id' SQL Injection
CVE-2008-1936webappsphp
SQL injection vulnerability in index.php in Classifieds Caffe allows remote attackers to execute arbitrary SQL commands
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.