Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,620cataloged exploits
35,647CVEs with public exploitation
24,695lab-tested
22,407 exploits
Referência
CVE-2025-71316
SQLite sqldiff remote code execution via argument injection
48RISK
open
Referência
CVE-2026-25551
Seagull Software BarTender Deserialization Privilege Escalation via .NET Remoting Service
41RISK
open
Referência
CVE-2026-10813
LMCache KV Cache utils.py hex_hash_to_int16 weak hash
28RISK
open
Referência
CVE-2018-8453
CVE-2018-8453HIGHunder attackransomware
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RISK
open
Referência
CVE-2026-10811
itsourcecode Fees Management System receipt.php sql injection
33RISK
open
Referência
CVE-2026-10550
elunez eladmin Application Deployment App.java command injection
33RISK
open
Referência
CVE-2026-10548
NousResearch hermes-agent Credential Pool Synchronization credential_pool.py _sync_anthropic_entry_from_credentials_file improper authentication
33RISK
open
Referência
CVE-2026-10301
itsourcecode Fees Management System index.php cross site scripting
33RISK
open
Referência
CVE-2026-10295
SourceCodester Customer Review App review_app.py get_all_reviews denial of service
33RISK
open
Referência
CVE-2026-10292
UTT HiPER 1200GW formTaskEdit strcpy stack-based overflow
41RISK
open
Referência
CVE-2026-10290
code-projects Hotel and Tourism Reservation System GET Parameter tour.php sql injection
33RISK
open
Referência
CVE-2026-10289
code-projects Hotel and Tourism Reservation System tour.php cross site scripting
33RISK
open
Referência
CVE-2018-8467
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
35RISK
open
Referência
CVE-2026-12189
Moovit Bus & Public Transit App com.tranzmate improper authorization in handler for custom url scheme
33RISK
open
Referência
CVE-2026-12187
GL.iNet GL-MT3000 Online Firmware Upgrade one_click_upgrade command injection
41RISK
open
Referência
CVE-2026-12186
GL.iNet GL-MT3000 Tor Proxy Service Configuration tor replace_country command injection
41RISK
open
Referência
CVE-2025-15546
Iptanus File Upload < 5.1.7 - File Overwrite via Race Condition
33RISK
open
Referência
CVE-2026-12174
D-Link DCS-935L HTTP rhea snprintf format string
41RISK
open
Referência
CVE-2026-25557
Evoluted PHP Directory Listing Script 4.0.5 Reflected XSS via dir parameter
33RISK
open
Referência
CVE-2004-0798
Buffer overflow in the _maincfgret.cgi script for Ipswitch WhatsUp Gold before 8.03 Hotfix 1 allows remote attackers to
50RISK
open
Referência
CVE-2018-8734
SQL injection vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker
50RISK
open
Referência
CVE-2026-11621
Dcat-Admin User Setting upload editorMDUpload unrestricted upload
33RISK
open
Referência
CVE-2026-11584
CodeAstro Student Attendance Management System createClass.php edit sql injection
33RISK
open
Referência
CVE-2026-11583
CodeAstro Student Attendance Management System createClass.php sql injection
33RISK
open
Referência
CVE-2019-0232
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RISK
open
Referência
CVE-2026-45585
Windows BitLocker Security Feature Bypass Vulnerability
33RISK
open
Referência
CVE-2026-41470
LIVE555 < 2026.04.22 RTSP Server Authorization Bypass via Session Token
41RISK
open
Referência
CVE-2018-25405
eNdonesia Portal 8.7 SQL Injection via mod.php
41RISK
open
Referência
CVE-2026-10115
Open5GS Shared NF-profile nnrf-handler.c denial of service
33RISK
open
Referência
CVE-2026-10114
Open5GS Shared NF-profile nnrf-handler.c handle_scp_info out-of-bounds write
33RISK
open
previouspage 493 / 747next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.