Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,545cataloged exploits
35,609CVEs with public exploitation
24,695lab-tested
22,407 exploits
Referência
LSoft ListServ < 16.5-2018a - Cross-Site Scripting
CVE-2019-15501webappswindows
Reflected cross site scripting (XSS) in L-Soft LISTSERV before 16.5-2018a exists via the /scripts/wa.exe OK parameter.
38RISK
open
Referência
CVE-2019-15637
Numerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data source, leading to informat
46RISK
open
Referência
CVE-2019-15752
CVE-2019-15752HIGHunder attack
Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-c
98RISK
open
Referência
CVE-2019-15889
The download-manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by t
53RISK
open
Referência
CVE-2019-15975
Cisco Data Center Network Manager Authentication Bypass Vulnerabilities
85RISK
open
Referência
CVE-2019-15977
Cisco Data Center Network Manager Authentication Bypass Vulnerabilities
60RISK
open
Referência
CVE-2026-19210
SourceCodester Photo Share Website ajax.php save_upload unrestricted upload
33RISK
open
Referência
CVE-2026-19209
SourceCodester Photo Share Website index.php home cross site scripting
33RISK
open
Referência
CVE-2026-19208
WonderTrader TraderDD.cpp queryTrades behavioral workflow
33RISK
open
Referência
CVE-2026-65707
Likeshop 3.0.5 Authenticated SQL Injection via adjustAccount Endpoint
41RISK
open
Referência
CVE-2026-12689
ProfileGrid < 5.9.9.7 - Subscriber+ Cross-User Private Message Thread Deletion and Tampering via Missing Authorization
33RISK
open
Referência
CVE-2019-1663
Cisco RV110W, RV130W, and RV215W Routers Management Interface Remote Command Execution Vulnerability
85RISK
open
ReferênciaVexDay Proof
AspWebCalendar 4.5 - 'eventid' SQL Injection
CVE-2004-1552webappsasp
SQL injection vulnerability in aspWebCalendar allows remote attackers to execute arbitrary SQL statements via (1) the us
23RISK
open
Referência
CVE-2026-16486
SourceCodester Class and Exam Timetabling System BSIS.php cross site scripting
33RISK
open
Referência
CVE-2026-16252
Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display System Staffshinel Ds.jsp sql injection
33RISK
open
Referência
CVE-2019-1663
Cisco RV110W, RV130W, and RV215W Routers Management Interface Remote Command Execution Vulnerability
85RISK
open
Referência
CVE-2019-1663
Cisco RV110W, RV130W, and RV215W Routers Management Interface Remote Command Execution Vulnerability
85RISK
open
ReferênciaVexDay Proof
aspwebalbum 3.2 - Multiple Vulnerabilities
CVE-2004-1553webappsasp
SQL injection vulnerability in aspWebAlbum allows remote attackers to execute arbitrary SQL statements via (1) the usern
23RISK
open
ReferênciaVexDay Proof
aspwebalbum 3.2 - Arbitrary File Upload / SQL Injection / Cross-Site Scripting
CVE-2004-1553webappsphp
SQL injection vulnerability in aspWebAlbum allows remote attackers to execute arbitrary SQL statements via (1) the usern
23RISK
open
Referência
CVE-2026-11466
zilliztech deep-searcher collection_router.py CollectionRouter.invoke access control
33RISK
open
Referência
CVE-2026-11462
Chengdu Everbrite Network Technology BeikeShop Stripe Plugin StripeController.php callback improper authorization
33RISK
open
Referência
CVE-2026-11461
NousResearch hermes-agent resume Endpoint hermes_state.py resolve_session_by_title authorization
33RISK
open
Referência
CVE-2026-11460
Boost Serialization improper validation of specified type of input
33RISK
open
Referência
CVE-2026-49494
Xcitium Client Security / Comodo Internet Security Remote Denial of Service
41RISK
open
Referência
CVE-2026-11456
Chanjet CRM HTTP GET Request jxf_dump_systable.php sql injection
33RISK
open
Referência
CVE-2026-11453
Tiobon Employee Self-Service System Login Endpoint BlogSearch.aspx sql injection
33RISK
open
Referência
CVE-2026-13514
Chess Play and Learn App com.chess AndroidManifest.xml backup
28RISK
open
Referência
CVE-2026-13513
MyScale MyScaleDB SegmentId.h getCacheKey data authenticity
28RISK
open
Referência
CVE-2026-13512
Databend Tenant client_session_manager.rs state_key authorization
33RISK
open
Referência
CVE-2019-17558
CVE-2019-17558HIGHunder attack
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A V
100RISK
open
previouspage 491 / 747next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.