Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,020cataloged exploits
35,276CVEs with public exploitation
24,695lab-tested
22,166 exploits
Referência
CVE-2022-50966
uBidAuction 2.0.1 news manage Reflected XSS
33RISK
open
Referência
CVE-2022-50966
uBidAuction 2.0.1 news manage Reflected XSS
33RISK
open
Referência
CVE-2020-35948
An issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress. It gave authenticated atta
53RISK
open
Referência
CVE-2020-5752
Relative path traversal in Druva inSync Windows Client 6.6.3 allows a local, unauthenticated attacker to execute arbitra
38RISK
open
Referência
CVE-2020-5791
Improper neutralization of special elements used in an OS command in Nagios XI 5.7.3 allows a remote, authenticated admi
60RISK
open
Referência
CVE-2020-5791
Improper neutralization of special elements used in an OS command in Nagios XI 5.7.3 allows a remote, authenticated admi
60RISK
open
Referência
CVE-2020-5902
CVE-2020-5902CRITICALunder attackransomware
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISK
open
Referência
CVE-2020-5902
CVE-2020-5902CRITICALunder attackransomware
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISK
open
Referência
CVE-2020-5902
CVE-2020-5902CRITICALunder attackransomware
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISK
open
Referência
CVE-2020-5902
CVE-2020-5902CRITICALunder attackransomware
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISK
open
Referência
CVE-2020-5902
CVE-2020-5902CRITICALunder attackransomware
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISK
open
Referência
CVE-2026-8116
huangjunsen0406 xiaozhi-mcphub dxtController.ts path traversal
33RISK
open
Referência
CVE-2026-8115
gyoridavid short-video-maker REST API rest.ts path traversal
33RISK
open
Referência
CVE-2026-8114
JeecgBoot JSON Object loadTreeData sql injection
33RISK
open
Referência
CVE-2026-7844
chatchat-space Langchain-Chatchat Compatible File Service openai_routes.py delete_file missing authentication
33RISK
open
Referência
CVE-2026-7834
EFM ipTIME NAS1dual misc_main.cgi get_csrf_whites stack-based overflow
48RISK
open
Referência
CVE-2026-7833
EFM ipTIME C200 ApplyRestore Endpoint iux_set.cgi sub_408F90 command injection
41RISK
open
Referência
CVE-2026-7832
IObit Advanced SystemCare Service ASC.exe symlink
41RISK
open
Referência
CVE-2023-54346
WordPress Plugin Backup Migration 1.2.8 Unauthenticated Database Backup Download
41RISK
open
Referência
CVE-2023-54345
Frappe Framework ERPNext 13.4.0 Remote Code Execution
41RISK
open
Referência
CVE-2023-54344
Eclipse Equinox OSGi 3.7.2 Remote Code Execution via Console
48RISK
open
Referência
CVE-2023-54342
Eclipse Equinox OSGi 3.8-3.18 Console Remote Code Execution
48RISK
open
Referência
CVE-2021-25155
A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point (IAP) products in v
28RISK
open
Referência
CVE-2026-13597
QRcode Login for WeChat <= 1.3 - Unauthenticated Account Takeover
48RISK
open
Referência
CVE-2021-26084
CVE-2021-26084CRITICALunder attackransomware
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
Referência
CVE-2026-16489
jsforce SFDX Connection Registry sfdx.js _execCommand os command injection
33RISK
open
Referência
CVE-2026-64821
djangoSIGE 1.10 CSRF via GET-based Order Cancellation Views
33RISK
open
Referência
CVE-2026-64822
djangoSIGE 1.10 User Enumeration via ForgotPasswordView
33RISK
open
Referência
CVE-2026-16447
D-Link DNS-320 multi_uploadify.php unrestricted upload
33RISK
open
Referência
CVE-2026-14184
Academy LMS < 3.8.1 - Subscriber+ Cross-User Lesson Note and Progress Modification via IDOR
33RISK
open
previouspage 353 / 739next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.