Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,772cataloged exploits
35,760CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,523GitHub PoC 14,289VulnCheck XDB 8,710Nuclei 4,319Metasploit 3,476✓ verified onlyrecentpopularrisk
22,523 exploits
Referência
CVE-2019-0232
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RISK
open ↗Referência
CVE-2026-41470
LIVE555 < 2026.04.22 RTSP Server Authorization Bypass via Session Token
41RISK
open ↗Referência
CVE-2026-10114
Open5GS Shared NF-profile nnrf-handler.c handle_scp_info out-of-bounds write
33RISK
open ↗Referência
CVE-2026-10112
sambitraj STUDENT-MANAGEMENT-SYSTEM Dashboard cross site scripting
33RISK
open ↗Referência
CVE-2026-10110
code-projects Student Details Management System index.php sql injection
33RISK
open ↗Referência
CVE-2026-44420
FreeRDP cliprdr server heap-buffer-overflow via undersized capabilitySetLength in CB_CLIP_CAPS
41RISK
open ↗Referência
CVE-2018-25396
Heatmiser Wifi Thermostat 1.7 Credential Disclosure via networkSetup.htm
41RISK
open ↗Referência
CVE-2019-0539
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
45RISK
open ↗Referência
CVE-2019-0539
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
45RISK
open ↗Referência
CVE-2018-25391
HaPe PKH 1.1 Missing Authorization Allows Unauthenticated Record Deletion
41RISK
open ↗Referência
CVE-2026-9603
SourceCodester eDoc Doctor Appointment System delete-session.php authorization
33RISK
open ↗Referência
CVE-2026-9484
SourceCodester Student Grades Management System classroom.php removeStudentFromClassroom improper authorization
33RISK
open ↗Referência
CVE-2026-9483
SourceCodester Student Grades Management System grades.php improper authorization
33RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.