Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,724cataloged exploits
35,724CVEs with public exploitation
24,695lab-tested
22,429 exploits
Referência
CVE-2026-6618
langgenius dify ApiBasedToolSchemaParser parser.py parse_openai_plugin_json_to_tool_bundle server-side request forgery
33RISK
open
Referência
CVE-2026-6616
TransformerOptimus SuperAGI WebScraperTool webpage_extractor.py extract_with_lxml server-side request forgery
33RISK
open
Referência
CVE-2016-8021
Improper verification of cryptographic signature vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3
23RISK
open
Referência
CVE-2012-2396
VideoLAN VLC media player 2.0.1 allows remote attackers to cause a denial of service (divide-by-zero error and applicati
23RISK
open
ReferênciaVexDay Proof
Lanifex DMO 2.3b - '_incMgr' Remote File Inclusion
CVE-2006-4604webappsphp
PHP remote file inclusion vulnerability in LFXlib/access_manager.php in Lanifex Database of Managed Objects (DMO) 2.3 Be
23RISK
open
Referência
CVE-2026-7612
itsourcecode Courier Management System edit_user.php sql injection
33RISK
open
Referência
CVE-2026-7609
TRENDnet TEW-821DAP Firmware Udpate diagnostic tools_diagnostic os command injection
33RISK
open
Referência
CVE-2026-7608
TRENDnet TEW-821DAP tools_diagnostic os command injection
33RISK
open
Referência
CVE-2026-7545
SourceCodester Advanced School Management System checkEmail Endpoint commonController.php sql injection
33RISK
open
Referência
CVE-2026-7538
Totolink A8000RU CGI cstecgi.cgi vulnerability os command injection
48RISK
open
Referência
CVE-2026-7536
Open5GS BSF pcfBindings bsf_sess_add_by_ip_address denial of service
33RISK
open
Referência
CVE-2026-7535
Open5GS transfer-update denial of service
33RISK
open
Referência
CVE-2018-17128
A Persistent XSS issue was discovered in the Visual Editor in MyBB before 1.8.19 via a Video MyCode.
45RISK
open
Referência
CVE-2016-8805
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 3
23RISK
open
ReferênciaVexDay Proof
PHP-revista 1.1.2 - Remote File Inclusion / SQL Injection / Authentication Bypass / Cross-Site Scripting
CVE-2006-4605webappsphp
PHP remote file inclusion vulnerability in index.php in Longino Jacome php-Revista 1.1.2 allows remote attackers to exec
23RISK
open
Referência
CVE-2026-6182
code-projects Simple Content Management System login.php sql injection
33RISK
open
Referência
CVE-2026-6204
LibreNMS versions before 26.3.0 are affected by an authenticated remote code execution vulnerability by abusing the Bina
41RISK
open
Referência
CVE-2026-2728
LibreNMS versions before 26.3.0 are affected by an authenticated Cross-site Scripting vulnerability on the showconfig pa
33RISK
open
Referência
CVE-2025-15632
1Panel-dev MaxKB MdPreview chat.ts cross site scripting
33RISK
open
Referência
CVE-2026-6167
code-projects Faculty Management System subject-print.php sql injection
33RISK
open
Referência
CVE-2010-5236
Untrusted search path vulnerability in Roxio Easy Media Creator Home 9.0.136 allows local users to gain privileges via a
23RISK
open
Referência
CVE-2026-7407
SourceCodester Pizzafy Ecommerce System Setting ajax.php save_settings sql injection
33RISK
open
Referência
CVE-2026-7404
getsimpletool mcpo-simple-server base_manager.py delete_shared_prompt path traversal
33RISK
open
Referência
CVE-2024-58344
Carbon Forum 5.9.0 Persistent XSS via Forum Name Field
33RISK
open
Referência
CVE-2018-25272
ELBA5 5.8.0 Remote Code Execution via Database Access
48RISK
open
Referência
CVE-2018-25271
Textpad 8.1.2 Denial of Service via Run Command
33RISK
open
Referência
CVE-2018-25270
ThinkPHP 5.0.23 Remote Code Execution via invokefunction
48RISK
open
Referência
CVE-2018-25269
ICEWARP 11.0.0.0 Cross-Site Scripting via Email HTML Injection
33RISK
open
Referência
CVE-2018-25268
LanSpy 2.0.1.159 Local Buffer Overflow via Scan Field
41RISK
open
Referência
CVE-2018-25267
UltraISO 9.7.1.3519 Buffer Overflow via Output FileName
33RISK
open
previouspage 516 / 748next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.