Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,724cataloged exploits
35,724CVEs with public exploitation
24,695lab-tested
22,492 exploits
Referência
CVE-2018-25365
PCViewer vt1000 Directory Traversal via GET Request
41RISK
open
ReferênciaVexDay Proof
Aztek Forum 4.00 - Cross-Site Scripting / SQL Injection
CVE-2006-1111webappsphp
Aztek Forum 4.0 allows remote attackers to obtain sensitive information via a "*/*" in the msg parameter to index.php, w
23RISK
open
ReferênciaVexDay Proof
Aztek Forum 4.00 - Cross-Site Scripting / SQL Injection
CVE-2006-1112webappsphp
Aztek Forum 4.0 allows remote attackers to obtain sensitive information via a long login value in a register form, which
23RISK
open
Referência
CVE-2017-11918
ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to
35RISK
open
Referência
CVE-2026-15497
SonicCloudOrg sonic-agent JWT Authentication Filter ExchangeController.java code injection
33RISK
open
Referência
CVE-2026-15496
SonicCloudOrg sonic-agent Groovy Script GroovyScriptImpl.java evalIsFailed os command injection
33RISK
open
Referência
CVE-2026-11590
WP Support Plus Responsive Ticket System <= 9.1.2 - Unauthenticated SQL Injection via filter[elements] Array Keys
41RISK
open
Referência
CVE-2026-11589
WP Support Plus Responsive Ticket System <= 9.1.2 - Unauthenticated Stored XSS via File Upload
41RISK
open
Referência
CVE-2026-11484
SourceCodester Class and Exam Timetabling System archive3.php sql injection
33RISK
open
Referência
CVE-2026-11483
SourceCodester Class and Exam Timetabling System archive4.php sql injection
33RISK
open
Referência
CVE-2026-9532
Totolink CA750-PoE Setting cstecgi.cgi setUploadUserData os command injection
38RISK
open
Referência
CVE-2026-9531
Totolink CA750-PoE Setting cstecgi.cgi setUpgradeUboot os command injection
38RISK
open
Referência
CVE-2014-8739
Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery
60RISK
open
Referência
CVE-2014-8739
Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery
60RISK
open
Referência
CVE-2026-9485
SourceCodester Student Grades Management System students.php cross site scripting
33RISK
open
Referência
CVE-2026-8212
OSGeo gdal SWapi.c SWSDfldsrch heap-based overflow
33RISK
open
Referência
CVE-2026-8211
codelibs Fess JSP File AdminDesignAction.java update code injection
33RISK
open
Referência
CVE-2026-16205
Pluck CMS Albums albums.admin.php htmlspecialchars_decode cross site scripting
33RISK
open
Referência
CVE-2014-8998
lib/message.php in X7 Chat 2.0.0 through 2.0.5.1 allows remote authenticated users to execute arbitrary PHP code via a c
50RISK
open
Referência
CVE-2014-8998
lib/message.php in X7 Chat 2.0.0 through 2.0.5.1 allows remote authenticated users to execute arbitrary PHP code via a c
50RISK
open
Referência
CVE-2026-9515
Totolink CA750-PoE Setting cstecgi.cgi setUnloadUserData os command injection
38RISK
open
Referência
CVE-2026-9514
Totolink CA750-PoE Setting cstecgi.cgi setNetworkDiag os command injection
38RISK
open
Referência
CVE-2014-9613
Multiple SQL injection vulnerabilities in Netsweeper before 2.6.29.10 allow remote attackers to execute arbitrary SQL co
23RISK
open
Referência
CVE-2014-9641
The tmeext.sys driver before 2.0.0.1015 in Trend Micro Antivirus Plus, Internet Security, and Maximum Security allows lo
23RISK
open
ReferênciaVexDay Proof
Brim 1.2.1 - 'renderer' Multiple Remote File Inclusions
CVE-2006-5429webappsphp
Multiple PHP remote file inclusion vulnerabilities in Barry Nauta BRIM 1.2.1 and earlier allow remote attackers to execu
23RISK
open
ReferênciaVexDay Proof
PHPPowerCards 2.10 - 'txt.inc.php' Remote Code Execution
CVE-2006-5432webappsphp
Multiple direct static code injection vulnerabilities in db/txt.inc.php in phpPowerCards 2.10, when register_globals is
23RISK
open
Referência
CVE-2018-25376
Socusoft 3GP Photo Slideshow 8.05 Buffer Overflow SEH
41RISK
open
Referência
CVE-2019-9193
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISK
open
Referência
CVE-2019-9193
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISK
open
Referência
CVE-2026-41949
Dify < 1.14.2 Authorization Bypass via File Preview Endpoint
41RISK
open
previouspage 528 / 750next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.