Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,533cataloged exploits
35,607CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,407GitHub PoC 14,247VulnCheck XDB 8,663Nuclei 4,287Metasploit 3,474✓ verified onlyrecentpopularrisk
22,407 exploits
Referência
CVE-2018-9106
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcySMS extensio
23RISK
open ↗Referência
CVE-2026-10877
SourceCodester Ship Ferry Ticket Reservation System Admin Login login.php sql injection
33RISK
open ↗Referência
CVE-2026-10876
SourceCodester Ship Ferry Ticket Reservation System admin improper authorization
33RISK
open ↗Referência
CVE-2026-25551
Seagull Software BarTender Deserialization Privilege Escalation via .NET Remoting Service
41RISK
open ↗Referência
CVE-2018-8453
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RISK
open ↗Referência
CVE-2026-11333
tittuvarghese CollegeManagementSystem Student Data Upload Endpoint upload_student_data.php unrestricted upload
33RISK
open ↗Referência
CVE-2018-9059
Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 7.2 allows remote attackers to execute arbitrary code
60RISK
open ↗Referência
CVE-2018-9128
DVD X Player Standard 5.5.3.9 has a Buffer Overflow via a crafted .plf file, a related issue to CVE-2007-3068.
23RISK
open ↗Referência
CVE-2018-9155
Cross-site scripting (XSS) vulnerability in Open-AudIT Professional 2.1.1 allows remote attackers to inject arbitrary we
23RISK
open ↗Referência
CVE-2026-49130
Music Player Daemon < 0.24.11 CRLF Injection via XspfPlaylistPlugin.cxx
33RISK
open ↗Referência
CVE-2026-49128
Music Player Daemon < 0.24.11 Path Traversal via LocalStorage URI Handling
41RISK
open ↗Referência
CVE-2018-9206
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
60RISK
open ↗Referência
CVE-2026-11517
UTT HiPER 2610G formConfigDnsFilterGlobal strcpy buffer overflow
41RISK
open ↗Referência
CVE-2026-11512
itsourcecode Hospital Management System billing.php cross site scripting
33RISK
open ↗Referência
CVE-2026-11495
CodeAstro Ingredients Stock Management System add_stock.php sql injection
33RISK
open ↗Referência
CVE-2026-11491
CodeAstro Human Resource Management System Notice Board Management All_notice cross site scripting
33RISK
open ↗Referência
CVE-2026-11489
code-projects Online Music Site AdminDeleteAlbum.php sql injection
33RISK
open ↗Referência
CVE-2019-0232
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RISK
open ↗Referência
CVE-2026-41470
LIVE555 < 2026.04.22 RTSP Server Authorization Bypass via Session Token
41RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.