Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,900cataloged exploits
35,840CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,600GitHub PoC 14,323VulnCheck XDB 8,722Nuclei 4,320Metasploit 3,477✓ verified onlyrecentpopularrisk
22,573 exploits
Referência
CVE-2026-17533
All-in-One WP Migration and Backup < 7.108 - Multisite Subsite Admin+ Network-Wide PHP Code Execution via REST Import
41RISK
open ↗Referência
CVE-2026-15384
Manual Image Crop < 1.15 - Subscriber+ Arbitrary Attachment Image Overwrite via IDOR
33RISK
open ↗Referência
CVE-2026-13712
Divi 5.0 - 5.8.1 - Contributor+ Stored XSS via Social Media Follow Skype URL
33RISK
open ↗Referência
CVE-2026-19934
itsourcecode Hospital Management System vieworder.php sql injection
33RISK
open ↗Referência
CVE-2010-1952
Directory traversal vulnerability in the BeeHeard (com_beeheard) and BeeHeard Lite (com_beeheardlite) component 1.0 for
43RISK
open ↗Referência
CVE-2026-19918
SpaceX Starlink Router Gen 3 gRPC Management get_status access control
33RISK
open ↗Referência
CVE-2015-3864
Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in A
60RISK
open ↗Referência
CVE-2026-19894
itsourcecode Hospital Management System viewmedicine.php sql injection
33RISK
open ↗Referência
CVE-2026-18807
ECS < 4.3.8 - Contributor+ Arbitrary Post Binding and Global Preset Modification via Dynamic Repeater Handlers
33RISK
open ↗Referência
CVE-2012-0895
Cross-site scripting (XSS) vulnerability in map/map.php in the Count Per Day module before 3.1.1 for WordPress allows re
23RISK
open ↗Referência
CVE-2012-0895
Cross-site scripting (XSS) vulnerability in map/map.php in the Count Per Day module before 3.1.1 for WordPress allows re
23RISK
open ↗Referência
CVE-2012-0911
TikiWiki CMS/Groupware before 6.7 LTS and before 8.4 allows remote attackers to execute arbitrary PHP code via a crafted
50RISK
open ↗Referência
CVE-2014-3961
SQL injection vulnerability in the Export CSV page in the Participants Database plugin before 1.5.4.9 for WordPress allo
23RISK
open ↗Referência✓ VexDay Proof
NagiosQL 2005 2.00 - 'prepend_adm.php' Remote File Inclusion
PHP remote file inclusion vulnerability in functions/prepend_adm.php in NagiosQL 2005 2.00 allows remote attackers to ex
23RISK
open ↗Referência✓ VexDay Proof
Snaps! Gallery 1.4.4 - Remote User Pass Change
Admin/users.php in Snaps! Gallery 1.4.4 allows remote attackers to change arbitrary usernames and passwords via the (1)
28RISK
open ↗Referência
CVE-2009-4381
Cross-site scripting (XSS) vulnerability in index.php in texmedia Million Pixel Script 3 allows remote attackers to inje
23RISK
open ↗Referência
CVE-2009-4381
Cross-site scripting (XSS) vulnerability in index.php in texmedia Million Pixel Script 3 allows remote attackers to inje
23RISK
open ↗Referência
CVE-2014-4613
Cross-site request forgery (CSRF) vulnerability in the administration panel in Piwigo before 2.6.2 allows remote attacke
23RISK
open ↗Referência
CVE-2014-4663
TimThumb 2.8.13 and WordThumb 1.07, when Webshot (aka Webshots) is enabled, allows remote attackers to execute arbitrary
23RISK
open ↗Referência
CVE-2014-4852
SQL injection vulnerability in admin/uploads.php in The Digital Craft AtomCMS, possibly 2.0, allows remote attackers to
23RISK
open ↗Referência
CVE-2009-4596
Cross-site scripting (XSS) vulnerability in index.php in PHP Inventory 1.2 allows remote attackers to inject arbitrary w
23RISK
open ↗Referência
CVE-2026-19821
Tenda AC12 httpd web management interface SetSysAutoRebbotCfg formSetRebootTimer buffer overflow
41RISK
open ↗Referência
CVE-2026-19815
TOTOLINK A800R firewall.so cstecgi.cgi setParentalRules stack-based overflow
41RISK
open ↗Referência
CVE-2015-4027
The AcuWVSSchedulerv10 service in Acunetix Web Vulnerability Scanner (WVS) before 10 build 20151125 allows local users t
23RISK
open ↗Referência
CVE-2015-4039
Multiple cross-site scripting (XSS) vulnerabilities in the WP Membership plugin 1.2.3 for WordPress allow remote authent
23RISK
open ↗Referência
CVE-2026-19814
TOTOLINK A800R firewall.so cstecgi.cgi setMacQos stack-based overflow
41RISK
open ↗Referência
CVE-2026-19813
TOTOLINK A800R firewall.so cstecgi.cgi setMacFilterRules stack-based overflow
41RISK
open ↗Referência
CVE-2026-19792
Tenda G0 httpd web management interface module setPortMapping buffer overflow
41RISK
open ↗Referência
CVE-2026-19787
SourceCodester Air Cargo Management System Master.php save_cargo_type sql injection
33RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.