Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,533cataloged exploits
35,607CVEs with public exploitation
24,695lab-tested
22,407 exploits
Referência
CVE-2018-9106
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcySMS extensio
23RISK
open
Referência
CVE-2026-10877
SourceCodester Ship Ferry Ticket Reservation System Admin Login login.php sql injection
33RISK
open
Referência
CVE-2026-10876
SourceCodester Ship Ferry Ticket Reservation System admin improper authorization
33RISK
open
Referência
CVE-2026-10870
Shibby Tomato Web UI rc start_dhcpc os command injection
41RISK
open
Referência
CVE-2025-71316
SQLite sqldiff remote code execution via argument injection
48RISK
open
Referência
CVE-2026-25551
Seagull Software BarTender Deserialization Privilege Escalation via .NET Remoting Service
41RISK
open
Referência
CVE-2026-10813
LMCache KV Cache utils.py hex_hash_to_int16 weak hash
28RISK
open
Referência
CVE-2018-8453
CVE-2018-8453HIGHunder attackransomware
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RISK
open
Referência
CVE-2026-10181
TRENDnet TEW-432BRP formSysCmd stack-based overflow
41RISK
open
Referência
CVE-2026-11333
tittuvarghese CollegeManagementSystem Student Data Upload Endpoint upload_student_data.php unrestricted upload
33RISK
open
Referência
CVE-2026-50232
Lyrion Music Server 9.2.0 Stored XSS via Metadata Tags
33RISK
open
Referência
CVE-2018-9059
Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 7.2 allows remote attackers to execute arbitrary code
60RISK
open
Referência
CVE-2018-9128
DVD X Player Standard 5.5.3.9 has a Buffer Overflow via a crafted .plf file, a related issue to CVE-2007-3068.
23RISK
open
Referência
CVE-2018-9155
Cross-site scripting (XSS) vulnerability in Open-AudIT Professional 2.1.1 allows remote attackers to inject arbitrary we
23RISK
open
Referência
CVE-2026-49130
Music Player Daemon < 0.24.11 CRLF Injection via XspfPlaylistPlugin.cxx
33RISK
open
Referência
CVE-2026-49129
Music Player Daemon < 0.24.11 SSRF via CurlInputPlugin
33RISK
open
Referência
CVE-2026-49128
Music Player Daemon < 0.24.11 Path Traversal via LocalStorage URI Handling
41RISK
open
Referência
CVE-2018-9206
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
60RISK
open
Referência
CVE-2026-11554
TOTOLINK CP450 vsftpd vsftpd.conf least privilege violation
33RISK
open
Referência
CVE-2026-11517
UTT HiPER 2610G formConfigDnsFilterGlobal strcpy buffer overflow
41RISK
open
Referência
CVE-2026-11512
itsourcecode Hospital Management System billing.php cross site scripting
33RISK
open
Referência
CVE-2026-11495
CodeAstro Ingredients Stock Management System add_stock.php sql injection
33RISK
open
Referência
CVE-2026-11494
TOTOLINK AC1200 T8 vsftpd vsftpd.conf least privilege violation
33RISK
open
Referência
CVE-2026-11493
Tenda AC15 Samba smb.conf weak password
28RISK
open
Referência
CVE-2026-11492
D-Link DIR-823G vsftpd vsftpd.conf least privilege violation
33RISK
open
Referência
CVE-2026-11491
CodeAstro Human Resource Management System Notice Board Management All_notice cross site scripting
33RISK
open
Referência
CVE-2026-11489
code-projects Online Music Site AdminDeleteAlbum.php sql injection
33RISK
open
Referência
CVE-2019-0232
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RISK
open
Referência
CVE-2026-45585
Windows BitLocker Security Feature Bypass Vulnerability
33RISK
open
Referência
CVE-2026-41470
LIVE555 < 2026.04.22 RTSP Server Authorization Bypass via Session Token
41RISK
open
previouspage 487 / 747next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.