Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,449cataloged exploits
35,552CVEs with public exploitation
24,695lab-tested
22,301 exploits
Referência
CVE-2021-41773
CVE-2021-41773HIGHunder attackransomware
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
Referência
CVE-2026-8268
Open5GS SMF OpenAPI_list_create denial of service
33RISK
open
Referência
CVE-2026-8265
Tenda AC6 httpd getLogFile get_log_file os command injection
33RISK
open
Referência
CVE-2026-8264
Tenda AC6 httpd WifiApScan formWifiApScan os command injection
33RISK
open
Referência
CVE-2026-8263
Tenda AC6 httpd WifiExtraSet fromSetWirelessRepeat os command injection
33RISK
open
Referência
CVE-2026-8262
Devs Palace ERP Online chart-save cross site scripting
33RISK
open
Referência
CVE-2026-8261
Squirrel sqobject.cpp Load heap-based overflow
33RISK
open
Referência
CVE-2026-8258
Squirrel sqstdstring.cpp validate_format stack-based overflow
33RISK
open
Referência
CVE-2026-8250
Open5GS SMF n4-build.c smf_n4_build_qos_flow_to_modify_list denial of service
33RISK
open
Referência
CVE-2026-8249
Open5GS SMF npcf-handler.c update_authorized_pcc_rule_and_qos denial of service
33RISK
open
Referência
CVE-2021-47930
Balbooa Joomla Forms Builder 2.0.6 SQL Injection Unauthenticated
41RISK
open
Referência
CVE-2021-47910
WordPress Plugin AccessPress Social Icons 1.8.2 Stored XSS
33RISK
open
Referência
CVE-2022-50969
uBidAuction 2.0.1 mailingLog manage Reflected XSS
33RISK
open
Referência
CVE-2022-50968
uBidAuction 2.0.1 auctions manage Reflected XSS
33RISK
open
Referência
CVE-2022-50967
uBidAuction 2.0.1 tickets manage Reflected XSS
33RISK
open
Referência
CVE-2015-7898
Samsung Gallery in the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).
23RISK
open
Referência
CVE-2015-7898
Samsung Gallery in the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).
23RISK
open
Referência
CVE-2015-7985
Valve Steam 2.10.91.91 uses weak permissions (Users: read and write) for the Install folder, which allows local users to
23RISK
open
Referência
CVE-2015-8103
The Jenkins CLI subsystem in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to execute arbitrary co
60RISK
open
Referência
CVE-2015-8103
The Jenkins CLI subsystem in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to execute arbitrary co
60RISK
open
Referência
CVE-2015-8412
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RISK
open
Referência
CVE-2022-50964
uBidAuction 2.0.1 myAuctions loose Reflected XSS
33RISK
open
Referência
CVE-2022-50964
uBidAuction 2.0.1 myAuctions loose Reflected XSS
33RISK
open
Referência
CVE-2022-50963
uBidAuction 2.0.1 myAuctions active Reflected XSS
33RISK
open
Referência
CVE-2022-50963
uBidAuction 2.0.1 myAuctions active Reflected XSS
33RISK
open
Referência
CVE-2022-50960
WordPress International Sms Contact Form 7 Integration 1.2 XSS
33RISK
open
Referência
CVE-2022-50959
WordPress Contact Form Builder 1.6.1 Cross-Site Scripting via code_generator.php
33RISK
open
Referência
CVE-2022-50958
WordPress Plugin Jetpack 9.1 Cross Site Scripting via grunion-form-view.php
33RISK
open
Referência
CVE-2022-50957
Drupal avatar_uploader 7.x-1.0-beta8 Reflected XSS
33RISK
open
Referência
CVE-2022-50956
WordPress Plugin amministrazione-aperta 3.7.3 Local File Read
33RISK
open
previouspage 452 / 744next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.