Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,044cataloged exploits
35,296CVEs with public exploitation
24,695lab-tested
22,166 exploits
Referência
CVE-2022-50958
WordPress Plugin Jetpack 9.1 Cross Site Scripting via grunion-form-view.php
33RISK
open
Referência
CVE-2022-50957
Drupal avatar_uploader 7.x-1.0-beta8 Reflected XSS
33RISK
open
Referência
CVE-2022-50956
WordPress Plugin amministrazione-aperta 3.7.3 Local File Read
33RISK
open
Referência
CVE-2022-50955
WordPress Plugin Curtain 1.0.2 Cross-site Request Forgery
33RISK
open
Referência
CVE-2022-50954
WordPress Plugin cab-fare-calculator 1.0.3 Local File Inclusion
33RISK
open
Referência
CVE-2022-50949
WordPress Plugin Videos sync PDF 1.7.4 Stored XSS
33RISK
open
Referência
CVE-2022-50948
Motopress Hotel Booking Lite 4.2.4 Stored Cross-Site Scripting
33RISK
open
Referência
CVE-2022-50947
WordPress Plugin Testimonial Slider and Showcase 2.2.6 Stored XSS
33RISK
open
Referência
CVE-2022-50946
WordPress Plugin Netroics Blog Posts Grid 1.0 Stored XSS
33RISK
open
Referência
CVE-2022-50945
WordPress 3dady Real-Time Web Stats 1.0 Stored XSS
33RISK
open
Referência
CVE-2022-50943
Moodle LMS 4.0 Cross-Site Scripting via course search.php
33RISK
open
Referência
CVE-2026-8244
Industrial Application Software IAS Canias ERP Login RMI improper authentication
33RISK
open
Referência
CVE-2026-8242
Industrial Application Software IAS Canias ERP Login RMI doAction response discrepancy
33RISK
open
Referência
CVE-2026-8241
Industrial Application Software IAS Canias ERP RMI iasGetServerInfoEvent improper authorization
33RISK
open
Referência
CVE-2026-8235
8421bit MiniClaw System kernel.ts resolveSkillScriptPath os command injection
33RISK
open
Referência
CVE-2026-8229
Wavlink NU516U1 wireless.cgi WifiBasic os command injection
33RISK
open
Referência
CVE-2026-8228
Wavlink NU516U1 wireless.cgi advance os command injection
33RISK
open
Referência
CVE-2026-8227
Wavlink NU516U1 adm.cgi wzdapMesh os command injection
33RISK
open
Referência
CVE-2026-8226
Open5GS types.c ogs_pcc_rule_install_flow_from_media denial of service
33RISK
open
Referência
CVE-2026-8225
Open5GS delete Endpoint sm-sm.c pcf_npcf_smpolicycontrol_handle_delete denial of service
33RISK
open
Referência
CVE-2026-8195
JeecgBoot SVG File CommonController.java cross site scripting
33RISK
open
Referência
CVE-2026-8190
Wavlink NU516U1 adm.cgi wan os command injection
33RISK
open
Referência
CVE-2026-8209
Gibbon versions before v30.0.01 are affected by a path traversal vulnerability resulting in DOS by attempting extraction
33RISK
open
ReferênciaVexDay Proof
OCE 3121/3122 Printer - 'parser.exe' Denial of Service
CVE-2006-2108doshardware
parser.exe in Océ (OCE) 3121/3122 Printer allows remote attackers to cause a denial of service (crash or reboot) via a l
23RISK
open
Referência
CVE-2026-14322
Timetics < 1.0.57 - Unauthenticated Booking Auto-Approval via Arbitrary payment_method
33RISK
open
Referência
CVE-2016-0173
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
23RISK
open
Referência
CVE-2016-0173
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
23RISK
open
Referência
CVE-2016-0491
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12
60RISK
open
Referência
CVE-2026-63769
Huginn 2022.08.18 SSRF via ScenarioImport fetch_url Method
33RISK
open
Referência
CVE-2016-0492
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12
60RISK
open
previouspage 359 / 739next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.