Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,866cataloged exploits
35,812CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,573GitHub PoC 14,316VulnCheck XDB 8,722Nuclei 4,320Metasploit 3,477✓ verified onlyrecentpopularrisk
22,573 exploits
Referência
CVE-2014-8493
ZTE ZXHN H108L with firmware 4.0.0d_ZRQ_GR4 allows remote attackers to modify the CWMP configuration via a crafted reque
23RISK
open ↗Referência
CVE-2012-3152
Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and
100RISK
open ↗Referência
CVE-2026-14760
radareorg radare2 regprofile disasm.c r_core_seek_arch_bits use after free
33RISK
open ↗Referência
CVE-2018-15473
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open ↗Referência
CVE-2010-4636
SQL injection vulnerability in detail.asp in Site2Nite Business e-Listings allows remote attackers to execute arbitrary
23RISK
open ↗Referência
CVE-2026-14759
radareorg radare2 RBinJava Line Number Table class.c r_bin_java_inner_classes_attr_calc_size heap-based overflow
33RISK
open ↗Referência
CVE-2025-64446
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISK
open ↗Referência
CVE-2016-1287
Buffer overflow in the IKEv1 and IKEv2 implementations in Cisco ASA Software before 8.4(7.30), 8.7 before 8.7(1.18), 9.0
45RISK
open ↗Referência
CVE-2026-14722
tiddly-gittly TidGi-Desktop Git Repository Import loadWikiTiddlersWithSubWikis.ts code injection
33RISK
open ↗Referência
CVE-2026-14719
SourceCodester Onlne Examination & Learning Management System Registration Endpoint register.php privileges management
33RISK
open ↗Referência
CVE-2026-14700
code-projects Internship Management System Employer Login Endpoint login.php sql injection
33RISK
open ↗Referência
CVE-2010-0944
Directory traversal vulnerability in the JCollection (com_jcollection) component for Joomla! allows remote attackers to
43RISK
open ↗Referência
CVE-2014-9415
Huawei eSpace Desktop before V100R001C03 allows local users to cause a denial of service (program exit) via a crafted QE
23RISK
open ↗Referência
CVE-2014-9416
Multiple untrusted search path vulnerabilities in Huawei eSpace Desktop before V200R003C00 allow local users to execute
23RISK
open ↗Referência
CVE-2014-9417
The Meeting component in Huawei eSpace Desktop before V100R001C03 allows local users to cause a denial of service (progr
23RISK
open ↗Referência
CVE-2014-9439
Cross-site scripting (XSS) vulnerability in Easy File Sharing Web Server 6.8 allows remote attackers to inject arbitrary
23RISK
open ↗Referência
CVE-2010-4830
SQL injection vulnerability in Resumes/TD_RESUME_Indlist.asp in Techno Dreams (T-Dreams) Job Career Package 3.0 allows r
23RISK
open ↗Referência
CVE-2010-4834
Multiple SQL injection vulnerabilities in index.php in OneOrZero AIMS 2.6.0 Members Edition and 2.7.0 Trial Edition allo
23RISK
open ↗Referência
CVE-2010-4850
Multiple cross-site scripting (XSS) vulnerabilities in Diferior 8.03 allow remote attackers to inject arbitrary web scri
23RISK
open ↗Referência
CVE-2010-4853
SQL injection vulnerability in the ccInvoices (com_ccinvoices) component for Joomla! allows remote attackers to execute
23RISK
open ↗Referência
CVE-2010-4853
SQL injection vulnerability in the ccInvoices (com_ccinvoices) component for Joomla! allows remote attackers to execute
23RISK
open ↗Referência
CVE-2026-13489
78 xiaozhi-esp32 MCP Response mcp_server.cc ParseMessage improper synchronization
28RISK
open ↗Referência
CVE-2026-13488
SourceCodester Class and Exam Timetabling System preview7.php sql injection
33RISK
open ↗Referência
CVE-2026-13487
SourceCodester Class and Exam Timetabling System archive.php sql injection
33RISK
open ↗Referência
CVE-2026-56786
RTKLIB 2.4.3 - Out-of-bounds Write in decode_type1033 via Crafted RTCM3 Message
48RISK
open ↗Referência
CVE-2026-56779
MaxKB < 2.10.0 - Server-Side Request Forgery via downloadCallbackUrl and download_url Parameters
33RISK
open ↗Referência
CVE-2026-56774
Kanboard - Cross-User Deletion of Persistent Login Sessions via Unvalidated Session ID
33RISK
open ↗Referência
CVE-2026-56770
libais 0.15 - Out-of-bounds Vector Access in VdmStream::AddLine via Invalid Sequential Message ID
41RISK
open ↗Referência
CVE-2026-56769
Huly Platform - Server-Side Request Forgery via /import Endpoint
33RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.