Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,533cataloged exploits
35,607CVEs with public exploitation
24,695lab-tested
22,407 exploits
Referência
CVE-2026-12799
BerriAI litellm Incomplete Fix CVE-2025-0628 internal_user_endpoints.py ui_view_users improper authorization
33RISK
open
Referência
CVE-2026-12796
BerriAI litellm SSO Authentication Flow ui_sso.py get_redirect_response_from_openid session expiration
33RISK
open
Referência
CVE-2026-12795
BerriAI litellm SSO Debug Flow ui_sso.py json.dumps missing authentication
33RISK
open
Referência
CVE-2026-12788
zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 XML Parser import xml external entity reference
33RISK
open
ReferênciaVexDay Proof
2532/Gigs 1.2.2 Stable - Remote Authentication Bypass
CVE-2008-6907webappsphp
Multiple SQL injection vulnerabilities in checkuser.php in 2532designs 2532|Gigs 1.2.2 Stable, when magic_quotes_gpc is
23RISK
open
ReferênciaVexDay Proof
Zeeways Shaadi Clone 2.0 - Authentication Bypass (1)
CVE-2008-6912webappsphp
Zeeways SHAADICLONE 2.0 allows remote attackers to bypass authentication and gain administrative privileges via a direct
23RISK
open
Referência
CVE-2012-5388
Cross-site scripting (XSS) vulnerability in wlcms-plugin.php in the White Label CMS plugin 1.5 for WordPress allows remo
23RISK
open
Referência
CVE-2026-12183
Nefteprodukttekhnika BUK TS-G Gas Station Automation System Authentication Bypass via ajax-login.php Accepting Arbitrary Credentials
48RISK
open
Referência
CVE-2026-12066
PbootCMS Password MemberController.php retrieve password recovery
33RISK
open
Referência
CVE-2026-8589
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
41RISK
open
Referência
CVE-2026-25860
OpenClinic GA 5.351.19 Reflected XSS via DICOM Image Upload Handler
33RISK
open
Referência
CVE-2026-25860 POC git
OpenClinic GA 5.351.19 Reflected XSS via DICOM Image Upload Handler
33RISK
open
Referência
CVE-2026-34417
OSCAL-GUI Reflected XSS via project parameter in oscal-forms.php
33RISK
open
Referência
CVE-2026-34416
OSCAL-GUI Reflected XSS via project parameter in oscal.php
33RISK
open
Referência
CVE-2017-20250
WordPress Plugin Mac Photo Gallery 3.0 Arbitrary File Download
41RISK
open
Referência
CVE-2025-55651
A NULL pointer dereference in the gf_isom_get_user_data_count function (isomedia/isom_read.c) of GPAC MP4Box v2.4 allows
33RISK
open
Referência
CVE-2026-11582
CodeAstro Student Attendance Management System index.php sql injection
33RISK
open
Referência
CVE-2026-11559
CodeAstro Payroll System view_account.php sql injection
33RISK
open
Referência
CVE-2026-25555
OpenBullet2 0.3.2 Authentication Bypass via X-Api-Key Header
63RISK
open
ReferênciaVexDay Proof
AJ Article 1.0 - Remote Authentication Bypass
CVE-2008-7051webappsphp
AJ Square AJ Article allows remote attackers to bypass authentication and access administrator functionality via a direc
23RISK
open
ReferênciaVexDay Proof
Pre Real Estate Listings - Arbitrary File Upload
CVE-2008-7052webappsphp
Unrestricted file upload vulnerability in profile.php in Pre Projects Pre Real Estate Listings allows remote authenticat
23RISK
open
Referência
CVE-2012-6045
Cross-site scripting (XSS) vulnerability in gb/user/index.php in Ramui Forum, possibly 1.0 Beta, allows remote attackers
23RISK
open
Referência
CVE-2012-6047
Cross-site request forgery (CSRF) vulnerability in X7 Chat 2.0.5.1 and earlier allows remote attackers to hijack the aut
23RISK
open
ReferênciaVexDay Proof
Nero ShowTime 5.0.15.0 - '.m3u' Playlist File Remote Buffer Overflow (PoC)
CVE-2008-7079doswindows
Buffer overflow in Nero ShowTime 5.0.15.0 allows remote attackers to cause a denial of service (crash) and possibly exec
23RISK
open
ReferênciaVexDay Proof
ReVou Twitter Clone - Authentication Bypass
CVE-2008-7083webappsphp
Multiple SQL injection vulnerabilities in ReVou Micro Blogging Twitter clone allow remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
HockeySTATS Online 2.0 - Multiple SQL Injections
CVE-2008-7085webappsphp
Multiple SQL injection vulnerabilities in TheHockeyStop HockeySTATS Online 2.0 Basic and Advanced allow remote attackers
23RISK
open
ReferênciaVexDay Proof
Maian Greetings 2.1 - Insecure Cookie Handling
CVE-2008-7086webappsphp
Maian Greetings 2.1 allows remote attackers to bypass authentication and gain administrative privileges by setting the m
23RISK
open
ReferênciaVexDay Proof
PhotoPost vBGallery 2.4.2 - Arbitrary File Upload
CVE-2008-7088webappsphp
Unrestricted file upload vulnerability in upload.php in PhotoPost vBGallery 2.4.2 allows remote authenticated users to e
23RISK
open
ReferênciaVexDay Proof
Pligg CMS 9.9.0 - Cross-Site Scripting / Local File Inclusion / SQL Injection
CVE-2008-7090webappsphp
Multiple directory traversal vulnerabilities in Pligg 9.9 and earlier allow remote attackers to (1) determine the existe
23RISK
open
ReferênciaVexDay Proof
Pligg CMS 9.9.0 - Cross-Site Scripting / Local File Inclusion / SQL Injection
CVE-2008-7091webappsphp
Multiple SQL injection vulnerabilities in Pligg 9.9 and earlier allow remote attackers to execute arbitrary SQL commands
23RISK
open
previouspage 484 / 747next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.