Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,020cataloged exploits
35,276CVEs with public exploitation
24,695lab-tested
22,166 exploits
Referência
CVE-2020-14946
downloadFile.ashx in the Administrator section of the Surveillance module in Global RADAR BSA Radar 1.6.7234.24750 and e
23RISK
open
Referência
CVE-2015-1725
Buffer overflow in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows S
23RISK
open
Referência
CVE-2015-2051
CVE-2015-2051HIGHunder attack
The D-Link DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute ar
100RISK
open
Referência
CVE-2015-2102
SQL injection vulnerability in view_item.php in ClipBucket 2.7 RC3 (2.7.0.4.v2929-rc3) allows remote attackers to execut
23RISK
open
Referência
CVE-2015-2102
SQL injection vulnerability in view_item.php in ClipBucket 2.7 RC3 (2.7.0.4.v2929-rc3) allows remote attackers to execut
23RISK
open
Referência
CVE-2021-47929
WordPress Plugin Filterable Portfolio Gallery 1.0 Stored XSS
33RISK
open
Referência
CVE-2021-47928
Opencart TMD Vendor System 3.x Blind SQL Injection via product route
41RISK
open
Referência
CVE-2021-47923
OpenCart 3.0.3.8 Session Fixation via OCSESSID Cookie
48RISK
open
Referência
CVE-2011-5204
Akiva WebBoard 8.x stores passwords in plaintext, which allows local users to obtain sensitive information by reading fr
23RISK
open
Referência
Anuko Time Tracker 1.19.23.5325 - CSV/Formula Injection
CVE-2020-15255HIGHwebappsphp
CSV injection in Anuko Time Tracker
41RISK
open
Referência
CVE-2026-8207
Gibbon versions before v30.0.01 are affected by an authenticated SQL Injection vulnerability by abusing the Tracking/gr
41RISK
open
ReferênciaVexDay Proof
Gallery 2.0.3 - 'stepOrder[]' Remote Command Execution
CVE-2006-1219webappsphp
Directory traversal vulnerability in Gallery 2.0.3 and earlier, and 2.1 before RC-2a, allows remote attackers to include
23RISK
open
ReferênciaVexDay Proof
crossfire-server 1.9.0 - 'SetUp()' Remote Buffer Overflow
CVE-2006-1236remotelinux
Buffer overflow in the SetUp function in socket/request.c in CrossFire 1.9.0 allows remote attackers to execute arbitrar
28RISK
open
Referência
CVE-2011-5207
Cross-site scripting (XSS) vulnerability in admin/OptionsPostsList.php in the TheCartPress plugin for WordPress before 1
23RISK
open
Referência
CVE-2021-47952
python jsonpickle 2.0.0 Remote Code Execution via py/repr
48RISK
open
Referência
CVE-2021-47934
MyBB Timeline Plugin 1.0 Cross-Site Scripting and CSRF
33RISK
open
Referência
CVE-2020-37247
Kite 4.2.0.1 U1 Unquoted Service Path Privilege Escalation
41RISK
open
Referência
CVE-2020-37246
WordPress Plugin Supsystic Backup 2.3.9 Local File Inclusion
33RISK
open
Referência
CVE-2020-37245
WordPress Plugin Supsystic Digital Publications 1.6.9 Path Traversal XSS
41RISK
open
Referência
CVE-2020-37240
Queue Management System 4.0.0 Stored XSS via Add User
33RISK
open
ReferênciaVexDay Proof
chCounter 3.1.3 - Authentication Bypass
CVE-2009-1347webappsphp
Multiple SQL injection vulnerabilities in stats/index.php in chCounter 3.1.3 allow remote attackers to execute arbitrary
23RISK
open
Referência
Victor CMS 1.0 - 'user_firstname' Persistent Cross-Site Scripting
CVE-2020-15599webappsphp
Victor CMS through 2019-02-28 allows XSS via the register.php user_firstname or user_lastname field.
23RISK
open
Referência
CVE-2026-16484
SourceCodester Class and Exam Timetabling System edit_subjecta.php sql injection
33RISK
open
Referência
CVE-2020-15920
There is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Executi
60RISK
open
Referência
CVE-2026-42881
STIGQter: Arbitrary File Write leading to Local Code Execution via Export HTML
41RISK
open
Referência
CVE-2016-20096
Linknat VOS3000/VOS2009 2.1.2.0 SQL Injection via login.jsp
48RISK
open
Referência
CVE-2020-16040
Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially explo
60RISK
open
Referência
CVE-2015-2216
SQL injection vulnerability in ecomm-sizes.php in the Photocrati theme 4.x for WordPress allows remote attackers to exec
23RISK
open
Referência
CVE-2026-8082
Bpost Shipping Platform < 3.2.3 - Unauthenticated SQL Injection
41RISK
open
Referência
CVE-2026-14185
WPBot AI ChatBot < 8.2.0 - Subscriber+ RAG Settings Update
33RISK
open
previouspage 350 / 739next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.