Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,058cataloged exploits
35,300CVEs with public exploitation
24,695lab-tested
22,166 exploits
Referência
CVE-2026-9476
Totolink A8000RU Web Management cstecgi.cgi setPasswordCfg os command injection
48RISK
open
Referência
CVE-2026-9465
Tiandy Easy7 Integrated Management Platform GetDBDataEx.jsp sql injection
33RISK
open
Referência
CVE-2018-25380
Joomla Component eXtroForms 2.1.5 SQL Injection via filter parameters
41RISK
open
Referência
CVE-2018-25378
Notebook Pro 2.0 Denial of Service via Notebook Name Field
33RISK
open
Referência
CVE-2018-25377
Flash Slideshow Maker Professional 5.20 Buffer Overflow SEH
41RISK
open
Referência
CVE-2018-25375
SocuSoft iPod Photo Slideshow 8.05 Buffer Overflow SEH
41RISK
open
Referência
CVE-2018-25374
Softneta MedDream PACS Server Premium 6.7.1.1 Directory Traversal
41RISK
open
Referência
CVE-2018-25373
DVD Photo Slideshow Professional 8.07 Buffer Overflow SEH
41RISK
open
Referência
CVE-2018-25372
MedDream PACS Server Premium 6.7.1.1 SQL Injection via email
41RISK
open
Referência
CVE-2018-25371
mooSocial Store Plugin 2.6 SQL Injection via product parameter
41RISK
open
Referência
CVE-2018-25370
Admidio 3.3.5 Cross-Site Request Forgery via roles_function.php
33RISK
open
Referência
CVE-2018-25369
Visual Ping 0.8.0.0 Buffer Overflow Denial of Service
33RISK
open
Referência
CVE-2018-25368
Nord VPN 6.14.31 Denial of Service via Password Field
41RISK
open
Referência
CVE-2016-4372
HPE iMC PLAT before 7.2 E0403P04, iMC EAD before 7.2 E0405P05, iMC APM before 7.2 E0401P04, iMC NTA before 7.2 E0401P01,
28RISK
open
Referência
CVE-2016-6854
An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code which got injected to a mail with inline
23RISK
open
Referência
CVE-2016-6854
An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code which got injected to a mail with inline
23RISK
open
Referência
Zhiyuan OA - arbitrary file upload leading
CVE-2025-34040CRITICALwebappsmultiple
Seeyon Zhiyuan OA System Path Traversal File Upload
68RISK
open
Referência
WordPress Madara - Local File Inclusion
CVE-2025-4524CRITICALwebappsmultiple
Madara – Responsive and modern WordPress theme for manga sites <= 2.2.2 - Unauthenticated Local File Inclusion
63RISK
open
Referência
CVE-2018-19862
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP POST re
28RISK
open
Referência
CVE-2018-19862
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP POST re
28RISK
open
Referência
CVE-2018-20062
CVE-2018-20062CRITICALunder attack
An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP
100RISK
open
Referência
CVE-2016-7661
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. The is
23RISK
open
ReferênciaVexDay Proof
XOOPS 2.0.13.2 - 'xoopsOption[nocommon]' Remote Command Execution
CVE-2006-2516webappsphp
mainfile.php in XOOPS 2.0.13.2 and earlier, when register_globals is enabled, allows remote attackers to overwrite varia
23RISK
open
ReferênciaVexDay Proof
phpListPro 2.0.1 - 'Language' Remote Code Execution
CVE-2006-2523webappsphp
PHP remote file inclusion vulnerability in config.php in phpListPro 2.0.1 and earlier, with magic_quotes_gpc disabled, a
23RISK
open
Referência
CVE-2017-0144
CVE-2017-0144HIGHunder attackransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Referência
Inosoft VisiWin 7 2022-2.1 - Insecure Folders Permissions
CVE-2023-31468HIGHlocalwindows
An issue was discovered in Inosoft VisiWin 7 through 2022-2.1 (Runtime RT7.3 RC3 20221209.5). The "%PROGRAMFILES(X86)%\I
41RISK
open
Referência
CVE-2023-31747
Wondershare Filmora 12 (Build 12.2.1.2088) was discovered to contain an unquoted service path vulnerability via the comp
41RISK
open
Referência
CVE-2023-31748
Insecure permissions in MobileTrans v4.0.11 allows attackers to escalate privileges to local admin via replacing the exe
41RISK
open
ReferênciaVexDay Proof
TR Newsportal 0.36tr1 - 'poll.php' Remote File Inclusion
CVE-2006-2557webappsphp
PHP remote file inclusion vulnerability in extras/poll/poll.php in Florian Amrhein NewsPortal before 0.37, and TR Newspo
28RISK
open
ReferênciaVexDay Proof
Woltlab Burning Board 2.3.5 - 'links.php' SQL Injection
CVE-2006-2569webappsphp
SQL injection vulnerability in links.php in 4R Linklist 1.0 RC2 and earlier, a module for Woltlab Burning Board, allows
23RISK
open
previouspage 362 / 739next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.