Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,313cataloged exploits
34,834CVEs with public exploitation
24,695lab-tested
21,797 exploits
Referência
CVE-2026-50232
Lyrion Music Server 9.2.0 Stored XSS via Metadata Tags
33RISK
open
Referência
CVE-2024-0723
freeSSHd denial of service
33RISK
open
Referência
CVE-2009-4581
Directory traversal vulnerability in modules/admincp.php in RoseOnlineCMS 3 B1 and earlier, when magic_quotes_gpc is dis
23RISK
open
Referência
CVE-2017-5638
CVE-2017-5638CRITICALunder attackransomware
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
Referência
CVE-2026-11312
bytedance InfiniStore KV Map infinistore.h purge_kv_map algorithmic complexity
33RISK
open
Referência
CVE-2026-10878
D-Link DWR-M920 formSmsManage sub_41C8E8 command injection
33RISK
open
ReferênciaVexDay Proof
Limbo CMS 1.0.4.2L - 'com_contact' Remote Code Execution
CVE-2006-4859webappsphp
Unrestricted file upload vulnerability in contact.html.php in the Contact (com_contact) component in Limbo (aka Lite Mam
23RISK
open
Referência
CVE-2026-10873
Shibby Tomato Web UI rstats rstats_path os command injection
41RISK
open
Referência
CVE-2026-10872
Shibby Tomato Web UI rc start_vpnserver os command injection
41RISK
open
Referência
CVE-2026-10871
Shibby Tomato Web UI rc start_6rd_tunnel os command injection
41RISK
open
Referência
CVE-2026-50266
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another p
28RISK
open
Referência
CVE-2026-10815
LakshayD02 Hostel-Management-System-PHP Admin Dashboard index.php authorization
33RISK
open
Referência
CVE-2026-10814
milvus-io milvus Grantee ID Hash kv_catalog.go weak hash
28RISK
open
Referência
CVE-2026-10812
zilliztech GPTCache Cache Key pre.py BufferedReader.peek weak hash
28RISK
open
Referência
CVE-2019-25735
AllPlayer 7.4 Local Buffer Overflow via SEH Unicode
41RISK
open
Referência
CVE-2019-25734
Contact Form by WD 1.13.1 CSRF to Local File Inclusion
33RISK
open
Referência
CVE-2026-8037
OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF
85RISK
open
Referência
CVE-2026-10804
Streamlit Palette hashing.py weak hash
28RISK
open
Referência
CVE-2026-10803
MLflow Dataset Digest Computation digest_utils.py mlflow.data.digest_utils weak hash
28RISK
open
Referência
CVE-2026-10802
keystonejs keystone GraphQL API Endpoint output-field.ts resource consumption
33RISK
open
Referência
CVE-2026-10801
modelscope ms-swift PIL Image Cache Key base.py Template._save_pil_image weak hash
28RISK
open
Referência
CVE-2026-10662
ahujasid blender-mcp ZIP File server.py requests.get server-side request forgery
33RISK
open
Referência
CVE-2026-10661
ahujasid blender-mcp server.py open injection
33RISK
open
Referência
CVE-2026-10650
warmcat libwebsockets SSH Protocol sshd.c lws_ssh_parse_plaintext resource consumption
33RISK
open
Referência
CVE-2026-10650
warmcat libwebsockets SSH Protocol sshd.c lws_ssh_parse_plaintext resource consumption
33RISK
open
Referência
CVE-2026-10624
SourceCodester Human Resource Management Employee View detailview.php resource injection
33RISK
open
Referência
CVE-2026-10619
sayan365 student-management-system improper authentication
33RISK
open
Referência
CVE-2021-22005
CVE-2021-22005CRITICALunder attackransomware
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISK
open
Referência
CVE-2017-8484
Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2,
23RISK
open
Referência
CVE-2020-5902
CVE-2020-5902CRITICALunder attackransomware
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISK
open
previouspage 302 / 727next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.