Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,533cataloged exploits
35,607CVEs with public exploitation
24,695lab-tested
22,367 exploits
Referência
CVE-2017-0145
CVE-2017-0145HIGHunder attackransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Referência
CVE-2017-0145
CVE-2017-0145HIGHunder attackransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Referência
CVE-2017-0146
CVE-2017-0146HIGHunder attackransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Referência
CVE-2011-0515
KisKrnl.sys 2011.1.13.89 and earlier in Kingsoft AntiVirus 2011 SP5.2 allows local users to cause a denial of service (c
23RISK
open
Referência
CVE-2026-9584
code-projects Project Management System Login chk.php sql injection
33RISK
open
Referência
CVE-2017-0147
CVE-2017-0147HIGHunder attackransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Referência
CVE-2011-0517
Stack-based buffer overflow in Sielco Sistemi Winlog Pro 2.07.00 and earlier, when Run TCP/IP server is enabled, allows
50RISK
open
Referência
CVE-2017-0147
CVE-2017-0147HIGHunder attackransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Referência
CVE-2013-2586
XAMPP 1.8.1 does not properly restrict access to xampp/lang.php, which allows remote attackers to modify xampp/lang.tmp
23RISK
open
Referência
CVE-2017-0147
CVE-2017-0147HIGHunder attackransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Referência
CVE-2017-0147
CVE-2017-0147HIGHunder attackransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Referência
CVE-2018-7756
RunExeFile.exe in the installer for DEWESoft X3 SP1 (64-bit) devices does not require authentication for sessions on TCP
35RISK
open
Referência
CVE-2026-58450
Invoice Ninja 5.13.26 - Open Redirect in Client Portal Login via intended Parameter
33RISK
open
Referência
CVE-2011-4825
Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinym
50RISK
open
Referência
CVE-2014-9456
Buffer overflow in NotePad++ 6.6.9 allows remote attackers to have unspecified impact via a long Time attribute in an Ev
28RISK
open
ReferênciaVexDay Proof
PHP AMX 0.90 - '/plugins/main.php' Remote File Inclusion
CVE-2006-5427webappsphp
PHP remote file inclusion vulnerability in plugins/main.php in Php AMX 0.9.0, when register_globals is enabled or magic_
23RISK
open
Referência
CVE-2026-9468
dazeb cline-mcp-memory-bank index.ts handleInitializeMemoryBank path traversal
33RISK
open
Referência
CVE-2014-9613
Multiple SQL injection vulnerabilities in Netsweeper before 2.6.29.10 allow remote attackers to execute arbitrary SQL co
23RISK
open
Referência
CVE-2014-9641
The tmeext.sys driver before 2.0.0.1015 in Trend Micro Antivirus Plus, Internet Security, and Maximum Security allows lo
23RISK
open
ReferênciaVexDay Proof
Brim 1.2.1 - 'renderer' Multiple Remote File Inclusions
CVE-2006-5429webappsphp
Multiple PHP remote file inclusion vulnerabilities in Barry Nauta BRIM 1.2.1 and earlier allow remote attackers to execu
23RISK
open
ReferênciaVexDay Proof
PHPPowerCards 2.10 - 'txt.inc.php' Remote Code Execution
CVE-2006-5432webappsphp
Multiple direct static code injection vulnerabilities in db/txt.inc.php in phpPowerCards 2.10, when register_globals is
23RISK
open
Referência
CVE-2018-25376
Socusoft 3GP Photo Slideshow 8.05 Buffer Overflow SEH
41RISK
open
Referência
CVE-2019-9193
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISK
open
Referência
CVE-2019-9193
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISK
open
Referência
CVE-2026-9810
AI Chatbot & Workflow Automation by AIWU < 1.5.4 - Unauthenticated Privilege Escalation via MCP OAuth
48RISK
open
Referência
Booked Scheduler 2.7.5 - Remote Command Execution (Metasploit)
CVE-2019-9581webappsphp
phpscheduleit Booked Scheduler 2.7.5 allows arbitrary file upload via the Favicon field, leading to execution of arbitra
28RISK
open
Referência
CVE-2026-15594
waooAI waoowaoo Media hash.ts stablePublicIdFromStorageKey improper authorization
33RISK
open
Referência
CVE-2026-13578
itsourcecode Hospital Management System patientdetail.php sql injection
33RISK
open
Referência
CVE-2026-13574
llvm llvm-project Bitcode File IntrinsicInst.cpp getBasePtr heap-based overflow
33RISK
open
Referência
AirDroid 4.2.1.6 - Denial of Service
CVE-2019-9599dosandroid
The AirDroid application through 4.2.1.6 for Android allows remote attackers to cause a denial of service (service crash
28RISK
open
previouspage 476 / 746next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.