Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,020cataloged exploits
35,276CVEs with public exploitation
24,695lab-tested
22,166 exploits
Referência
CVE-2017-20251
WordPress Insert PHP Plugin 4.7.0 PHP Code Injection via REST API
48RISK
open
Referência
CVE-2026-25856
OpenBullet2 0.3.2 Authenticated RCE via Job Configuration Interface
41RISK
open
Referência
CVE-2026-11529
designcomputer mysql-mcp-server mysql URI server.py read_resource sql injection
33RISK
open
Referência
CVE-2020-14882
CVE-2020-14882CRITICALunder attack
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
Referência
CVE-2026-10232
Assimp ASE File scene.cpp ~aiNode use after free
33RISK
open
Referência
CVE-2026-10231
Assimp Half-Life 1 MDL Loader HL1MDLLoader.cpp extract_anim_value heap-based overflow
33RISK
open
Referência
CVE-2026-10229
Assimp Half-Life 1 MDL Loader HL1MDLLoader.cpp read_meshes heap-based overflow
33RISK
open
Referência
CVE-2026-10228
raisulislamg4 student_management_system_by_php admission_form_check.php cross site scripting
33RISK
open
Referência
CVE-2026-10227
raisulislamg4 student_management_system_by_php User Creation add_user_check.php sql injection
33RISK
open
Referência
CVE-2026-10124
Shibby Tomato Zserv ripd rip_zebra_read_ipv4 stack-based overflow
41RISK
open
Referência
CVE-2020-20139
Cross Site Scripting (XSS) vulnerability in the Remote JSON component Under the Connect menu in Flexmonster Pivot Table
23RISK
open
Referência
CVE-2020-20141
Cross Site Scripting (XSS) vulnerability in the To OLAP (XMLA) component Under the Connect menu in Flexmonster Pivot Tab
23RISK
open
Referência
CVE-2020-2038
PAN-OS: OS command injection vulnerability in the management web interface
78RISK
open
Referência
CVE-2020-2096
Jenkins Gitlab Hook Plugin 1.4.2 and earlier does not escape project names in the build_now endpoint, resulting in a ref
60RISK
open
Referência
CVE-2026-9631
UTT HiPER 1250GW Web Management formConfigFastDirectionW strcpy stack-based overflow
41RISK
open
Referência
CVE-2026-9628
UTT HiPER 1200GW Web Management formPptpClientConfig stack-based overflow
41RISK
open
Referência
CVE-2026-9609
QianFox FoxCMS Admin.php edit password recovery
33RISK
open
Referência
CVE-2026-9566
teableio teable Sign-up LoginPage.tsx cross site scripting
33RISK
open
Referência
CVE-2026-9504
GNU LibreDWG Dwggrep Utility dwggrep.c bit_convert_TU out-of-bounds
33RISK
open
Referência
CVE-2020-5752
Relative path traversal in Druva inSync Windows Client 6.6.3 allows a local, unauthenticated attacker to execute arbitra
38RISK
open
Referência
CVE-2020-5791
Improper neutralization of special elements used in an OS command in Nagios XI 5.7.3 allows a remote, authenticated admi
60RISK
open
Referência
CVE-2020-5791
Improper neutralization of special elements used in an OS command in Nagios XI 5.7.3 allows a remote, authenticated admi
60RISK
open
Referência
CVE-2020-5902
CVE-2020-5902CRITICALunder attackransomware
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISK
open
Referência
CVE-2020-5902
CVE-2020-5902CRITICALunder attackransomware
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISK
open
Referência
CVE-2020-5902
CVE-2020-5902CRITICALunder attackransomware
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISK
open
Referência
CVE-2020-5902
CVE-2020-5902CRITICALunder attackransomware
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISK
open
Referência
CVE-2020-5902
CVE-2020-5902CRITICALunder attackransomware
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISK
open
Referência
CVE-2026-8116
huangjunsen0406 xiaozhi-mcphub dxtController.ts path traversal
33RISK
open
Referência
CVE-2026-8115
gyoridavid short-video-maker REST API rest.ts path traversal
33RISK
open
Referência
CVE-2026-8114
JeecgBoot JSON Object loadTreeData sql injection
33RISK
open
previouspage 356 / 739next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.