Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,533cataloged exploits
35,607CVEs with public exploitation
24,695lab-tested
22,407 exploits
Referência
CVE-2022-50968
uBidAuction 2.0.1 auctions manage Reflected XSS
33RISK
open
Referência
CVE-2022-50967
uBidAuction 2.0.1 tickets manage Reflected XSS
33RISK
open
Referência
CVE-2022-50966
uBidAuction 2.0.1 news manage Reflected XSS
33RISK
open
Referência
CVE-2022-50966
uBidAuction 2.0.1 news manage Reflected XSS
33RISK
open
Referência
CVE-2026-7823
Totolink A8000RU cstecgi.cgi setAppFilterCfg os command injection
48RISK
open
Referência
CVE-2026-7822
itsourcecode Courier Management System print_pdets.php sql injection
33RISK
open
Referência
CVE-2026-7812
54yyyu code-mcp MCP Tool server.py git_operation command injection
33RISK
open
Referência
CVE-2026-7811
54yyyu code-mcp MCP File server.py is_safe_path path traversal
33RISK
open
Referência
CVE-2026-7741
CodeAstro Online Classroom studentlogin sql injection
33RISK
open
Referência
CVE-2026-7725
PrefectHQ prefect GitRepository Pull storage.py argument injection
33RISK
open
Referência
CVE-2026-7724
PrefectHQ prefect Webhook/Notification validate_restricted_url toctou
28RISK
open
Referência
CVE-2020-6519
Policy bypass in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy
28RISK
open
Referência
CVE-2019-2729
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
85RISK
open
Referência
CVE-2019-3396
CVE-2019-3396CRITICALunder attackransomware
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISK
open
Referência
CVE-2019-3396
CVE-2019-3396CRITICALunder attackransomware
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISK
open
Referência
CVE-2026-34115
Guardian Language-System Unauthenticated OS Command Injection via id Parameter in transcribe_amazon.php
48RISK
open
Referência
CVE-2026-11794
Advanced Form Integration < 2.1.1 - Unauthenticated Privilege Escalation via Breakdance Form Role Mapping
41RISK
open
Referência
CVE-2026-13582
Edimax EW-7478APC POST Request formUSBAccount buffer overflow
41RISK
open
Referência
CVE-2026-13581
Edimax EW-7478APC POST Request formStaDrvSetup os command injection
33RISK
open
Referência
CVE-2026-40522
FrontAccounting < 2.4.20 SQL Injection via rep601.php
41RISK
open
Referência
CVE-2026-13509
RAGapp Knowledge File files.py FileHandler.remove_file path traversal
33RISK
open
Referência
CVE-2026-13508
khoj-ai khoj Conversation Sharing api_chat.py authorization
33RISK
open
Referência
CVE-2026-13504
code-projects Project Management System Mail Compose mail.php cross site scripting
33RISK
open
Referência
CVE-2022-50971
Malwarebytes 4.5 Unquoted Service Path Privilege Escalation
41RISK
open
Referência
CVE-2021-47985
Brother SAPSprint 7.60 Unquoted Service Path Privilege Escalation
41RISK
open
Referência
CVE-2020-37254
Wondershare PDFelement 5.2.9 Privilege Escalation via Unquoted Service Path
41RISK
open
Referência
CVE-2020-37253
Winstep 18.06.0096 Unquoted Service Path Privilege Escalation
41RISK
open
Referência
CVE-2019-25747
Network Inventory Advisor 5.0.26.0 Unquoted Service Path Privilege Escalation
41RISK
open
Referência
CVE-2019-5392
A disclosure of information vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than ve
23RISK
open
Referência
CVE-2019-5418
CVE-2019-5418HIGHunder attack
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISK
open
previouspage 485 / 747next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.