Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,449cataloged exploits
35,552CVEs with public exploitation
24,695lab-tested
22,301 exploits
Referência
CVE-2023-46453
Certain GL.iNet devices with 4.x firmware allow authentication bypass (resulting in administrative control of the device
48RISK
open
Referência
CVE-2013-6881
CRU Ditto Forensic FieldStation with firmware before 2013Oct15a allows remote attackers to execute arbitrary commands vi
28RISK
open
Referência
CVE-2024-33288
Prison Management System Using PHP v1.0 was discovered to contain a SQL injection vulnerability via the username on the
56RISK
open
Referência
CVE-2013-7025
Multiple cross-site scripting (XSS) vulnerabilities in ematStaticAlertTypes.jsp in the Alert Settings section in Dell So
23RISK
open
ReferênciaVexDay Proof
RunCMS Module Photo 3.02 - 'cid' SQL Injection
CVE-2008-1551webappsphp
SQL injection vulnerability in viewcat.php in the Photo 3.02 module for RunCMS allows remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
TopperMod 2.0 - SQL Injection
CVE-2008-1554webappsphp
SQL injection vulnerability in account/index.php in TopperMod 2.0, when magic_quotes_gpc is disabled, allows remote atta
23RISK
open
ReferênciaVexDay Proof
MPlayer 1.0 rc2 - 'sdpplin_parse()' Array Indexing Buffer Overflow (PoC)
CVE-2008-1558doslinux
Uncontrolled array index in the sdpplin_parse function in stream/realrtsp/sdpplin.c in MPlayer 1.0 rc2 allows remote att
28RISK
open
Referência
CVE-2026-7604
JeecgBoot OpenApi Service OpenApiController.java OpenApiController.call server-side request forgery
33RISK
open
Referência
CVE-2026-5657
Double Free in Wireshark
33RISK
open
Referência
CVE-2018-25299
Prime95 29.4b8 Local Buffer Overflow via SEH
41RISK
open
Referência
CVE-2018-25298
Merge PACS 7.0 Cross-Site Request Forgery via merge-viewer
33RISK
open
Referência
CVE-2026-7401
SourceCodester CET Automated Grading System with AI Predictive Analytics Registration index.php register cross site scripting
33RISK
open
Referência
CVE-2026-7400
geekgod382 filesystem-mcp-server read_file_tool/write_file_tool server.py is_path_allowed path traversal
33RISK
open
Referência
CVE-2026-7386
fatbobman mail-mcp-bridge mail_mcp_server.py path traversal
33RISK
open
Referência
CVE-2026-7319
elinsky execution-system-mcp add_action Tool server.py _get_context_file_path path traversal
33RISK
open
Referência
CVE-2026-7318
elie mcp-project research_server.py search_papers path traversal
33RISK
open
Referência
CVE-2026-7317
Grav CMS Cache Value FileCache.php doGet deserialization
28RISK
open
Referência
CVE-2026-7316
eiliyaabedini aider-mcp code_with_ai aider_mcp.py command injection
33RISK
open
Referência
CVE-2026-7314
eiceblue spire-doc-mcp-server base.py get_doc_path path traversal
33RISK
open
ReferênciaVexDay Proof
Watchfire Appscan 7.0 - ActiveX Multiple Insecure Methods
CVE-2008-2015remotewindows
Multiple absolute path traversal vulnerabilities in certain ActiveX controls in WatchFire AppScan 7.0 allow remote attac
23RISK
open
Referência
CVE-2019-0808
CVE-2019-0808HIGHunder attack
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
98RISK
open
ReferênciaVexDay Proof
Megabbs Forum 2.2 - SQL Injection / Cross-Site Scripting
CVE-2008-2023webappsasp
Multiple SQL injection vulnerabilities in PD9 Software MegaBBS 2.2 allow remote attackers to execute arbitrary SQL comma
23RISK
open
Referência
CVE-2019-1003000
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RISK
open
Referência
CVE-2014-10020
SQL injection vulnerability in login.php in Simple e-document 1.31 allows remote attackers to execute arbitrary SQL comm
23RISK
open
Referência
CVE-2014-10034
Multiple SQL injection vulnerabilities in the admin area in couponPHP before 1.2.0 allow remote administrators to execut
23RISK
open
Referência
CVE-2026-5634
projectworlds Car Rental Project Parameter book_car.php sql injection
33RISK
open
Referência
CVE-2026-5632
assafelovic gpt-researcher HTTP REST API Endpoint missing authentication
33RISK
open
Referência
CVE-2026-5631
assafelovic gpt-researcher ws Endpoint server_utils.py extract_command_data code injection
33RISK
open
Referência
CVE-2026-5630
assafelovic gpt-researcher Report API app.py cross site scripting
33RISK
open
Referência
CVE-2026-5629
Belkin F9K1015 formSetFirewall stack-based overflow
41RISK
open
previouspage 451 / 744next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.