Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,449cataloged exploits
35,552CVEs with public exploitation
24,695lab-tested
22,367 exploits
Referência
CVE-2014-5144
Cross-site scripting (XSS) vulnerability in Telescope before 0.9.3 allows remote authenticated users to inject arbitrary
23RISK
open
ReferênciaVexDay Proof
Microsoft Windows - '.png' IHDR Block Denial of Service (PoC) (2)
CVE-2006-7210doswindows
Microsoft Windows 2000, XP, and Server 2003 allows remote attackers to cause a denial of service (cpu consumption) via a
28RISK
open
ReferênciaVexDay Proof
Microsoft Windows - '.png' IHDR Block Denial of Service (PoC) (3)
CVE-2006-7210doswindows
Microsoft Windows 2000, XP, and Server 2003 allows remote attackers to cause a denial of service (cpu consumption) via a
28RISK
open
Referência
CVE-2015-8429
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RISK
open
Referência
CVE-2015-8430
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RISK
open
Referência
CVE-2026-14322
Timetics < 1.0.57 - Unauthenticated Booking Auto-Approval via Arbitrary payment_method
33RISK
open
Referência
CVE-2016-0173
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
23RISK
open
Referência
CVE-2016-0173
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
23RISK
open
Referência
CVE-2026-63769
Huginn 2022.08.18 SSRF via ScenarioImport fetch_url Method
33RISK
open
Referência
CVE-2016-0492
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12
60RISK
open
Referência
CVE-2016-0492
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12
60RISK
open
Referência
CVE-2021-43857
Gerapy may contain remote code execution vulnerability
60RISK
open
Referência
CVE-2026-8987
Authenticated Heap Overflow
48RISK
open
ReferênciaVexDay Proof
Acunetix WVS 4.0 20060717 - HTTP Sniffer Component Remote Denial of Service
CVE-2007-0120doswindows
Acunetix Web Vulnerability Scanner (WVS) 4.0 Build 20060717 and earlier allows remote attackers to cause a denial of ser
23RISK
open
Referência
CVE-2026-69110
OpenCode Studio < 2.4.4 Unauthenticated File Read via /api/tmp and /api/music
48RISK
open
Referência
CVE-2016-1525
Directory traversal vulnerability in data/config/image.do in NETGEAR Management System NMS300 1.5.0.11 and earlier allow
60RISK
open
Referência
CVE-2007-0134
Multiple eval injection vulnerabilities in iGeneric iG Shop 1.0 allow remote attackers to execute arbitrary code via the
28RISK
open
ReferênciaVexDay Proof
ig shop 1.0 - Code Execution / SQL Injection
CVE-2007-0134webappsphp
Multiple eval injection vulnerabilities in iGeneric iG Shop 1.0 allow remote attackers to execute arbitrary code via the
28RISK
open
Referência
CVE-2026-63764
LMDeploy Server-Side Request Forgery via HTTP Redirect Bypass
41RISK
open
ReferênciaVexDay Proof
Aratix 0.2.2b11 - '/inc/init.inc.php' Remote File Inclusion
CVE-2007-0135webappsphp
PHP remote file inclusion vulnerability in inc/init.inc.php in Aratix 0.2.2 beta 11 and earlier, when register_globals i
23RISK
open
ReferênciaVexDay Proof
Quote&Ordering System 1.0 - 'ordernum' Multiple Vulnerabilities
CVE-2007-0144webappsasp
Cross-site scripting (XSS) vulnerability in search.asp in Digitizing Quote And Ordering System 1.0 allows remote authent
23RISK
open
Referência
CVE-2016-1721
The kernel in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges o
23RISK
open
Referência
CVE-2026-17433
nanocoai NanoClaw MCP Server Approval chat-sdk-bridge.ts createChatSdkBridge.setup improper authorization
33RISK
open
Referência
CVE-2026-65698
Void 1.3.4 Path Traversal via AI Agent File-Reading Tools
33RISK
open
Referência
CVE-2026-9066
WP Compress < 7.10.04 - Reflected XSS via test_zone
33RISK
open
Referência
CVE-2026-14291
Security Ninja (Premium) < 5.290 - Two-Factor Authentication Bypass via secnin_skip_2fa
41RISK
open
ReferênciaVexDay Proof
OmniWeb 5.5.1 - JavaScript alert() Remote Format String (PoC)
CVE-2007-0148dososx
Format string vulnerability in OmniGroup OmniWeb 5.5.1 allows remote attackers to cause a denial of service (application
23RISK
open
ReferênciaVexDay Proof
AllMyVisitors 0.4.0 - 'index.php' Remote File Inclusion
CVE-2007-0170webappsphp
PHP remote file inclusion vulnerability in index.php in AllMyVisitors 0.4.0 allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
AllMyLinks 0.5.0 - 'index.php' Remote File Inclusion
CVE-2007-0171webappsphp
PHP remote file inclusion vulnerability in index.php in AllMyLinks 0.5.0 and earlier allows remote attackers to execute
23RISK
open
Referência
CVE-2026-16130
nearai ironclaw write_file path_utils.rs validate_path link following
33RISK
open
previouspage 462 / 746next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.