Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,449cataloged exploits
35,552CVEs with public exploitation
24,695lab-tested
22,332 exploits
Referência
CVE-2017-17614
Food Order Script 1.0 has SQL Injection via the /list city parameter.
23RISK
open
Referência
CVE-2026-18646
danpros HTMLy Author Name htmly.php path traversal
33RISK
open
Referência
CVE-2026-18631
jeequan jeepay PreAuthorize SysLogController.java WebSecurityConfig authorization
33RISK
open
Referência
CVE-2017-17614
Food Order Script 1.0 has SQL Injection via the /list city parameter.
23RISK
open
Referência
CVE-2017-17616
Event Search Script 1.0 has SQL Injection via the /event-list city parameter.
23RISK
open
Referência
CVE-2017-17616
Event Search Script 1.0 has SQL Injection via the /event-list city parameter.
23RISK
open
Referência
CVE-2017-17617
Foodspotting Clone Script 1.0 has SQL Injection via the quicksearch.php q parameter.
23RISK
open
Referência
CVE-2017-17617
Foodspotting Clone Script 1.0 has SQL Injection via the quicksearch.php q parameter.
23RISK
open
Referência
CVE-2026-12586
Lenxel WP <= 1.0.31 - Unauthenticated Account Takeover via Arbitrary Password Reset
41RISK
open
Referência
CVE-2026-11872
Clever Mega Menu for Visual Composer <= 1.0.1 - Subscriber+ Menu Item Meta Update via save_clever_menu_item
33RISK
open
Referência
CVE-2026-16256
Pouco Import Users <= 1.0.0 - Unauthenticated Privilege Escalation
48RISK
open
Referência
CVE-2026-15385
RT Mega Menu < 1.5.2 - Subscriber+ Stored XSS via Menu Item CSS
33RISK
open
Referência
CVE-2026-15248
Meta Box < 5.13.1 - Contributor+ Arbitrary Attachment Deletion via IDOR
33RISK
open
Referência
CVE-2026-15241
ChatBot for eCommerce – WoowBot < 4.8.4 - Unauthenticated Gemini API Key Abuse via qcld_gemini_response
41RISK
open
Referência
CVE-2026-14920
AcyMailing < 10.11.1 - Unauthenticated SQL Injection via subscription[] Parameter
41RISK
open
Referência
CVE-2026-14864
JetEngine < 3.8.12 - Contributor+ Stored XSS via jet_engine Shortcode
33RISK
open
Referência
CVE-2026-14841
King Addons for Elementor < 51.1.76 - Reflected XSS via Posts Grid Widget
33RISK
open
Referência
CVE-2026-67298
FreeRDP 3.28.0 Heap Buffer Overflow via RAIL orderLength Underflow
41RISK
open
Referência
CVE-2026-67288
FreeRDP before 3.29.0 Denial of Service via smartcard cache
41RISK
open
Referência
CVE-2026-14839
Mapster WP Maps < 1.24.0 - Unauthenticated Private and Draft Post Content Disclosure
41RISK
open
Referência
CVE-2026-14823
Event Tickets < 5.29.0.1 - Contributor+ Seating Layout and Ticket Inventory Modification via IDOR
28RISK
open
Referência
CVE-2026-14822
Event Tickets < 5.29.0.1 - Unauthenticated PayPal Order Status Manipulation
33RISK
open
Referência
CVE-2026-14561
Authora - Easy Login with Mobile Number < 1.7.7 - Unauthenticated Account Takeover via OTP Disclosure
33RISK
open
Referência
CVE-2026-14315
Pixel Tag Manager for WooCommerce < 2.2.1 - Unauthenticated Forged Conversion Event Submission
33RISK
open
Referência
CVE-2026-14292
WordPress Download Manager < 3.3.66 - Author+ Stored XSS via Package Title
33RISK
open
Referência
CVE-2026-14214
Amelia < 2.4.4 - Amelia Manager+ Arbitrary User-Field Modification via Mass Assignment
28RISK
open
Referência
CVE-2026-14195
Brizy – Page Builder < 2.8.18 - Contributor+ Sensitive Information Disclosure via get_post_info
28RISK
open
Referência
CVE-2026-13729
Podlove Podcast Publisher < 4.5.3 - Podcast Contributor/Group/Role Creation and Deletion via CSRF
33RISK
open
Referência
CVE-2026-13725
Dynamic Pricing With Discount Rules for WooCommerce < 5.0.0 - Reflected XSS via wdpAjax
41RISK
open
Referência
CVE-2026-13604
Pixelavo < 1.5.4 - Unauthenticated Facebook CAPI Event Injection via pixelavo_event AJAX
33RISK
open
previouspage 453 / 745next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.