Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,900cataloged exploits
35,840CVEs with public exploitation
24,695lab-tested
22,600 exploits
Referência
CVE-2015-6104
The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window
35RISK
open
Referência
CVE-2015-6104
The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window
35RISK
open
Referência
CVE-2015-6152
Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory co
35RISK
open
Referência
CVE-2015-6541
Multiple cross-site request forgery (CSRF) vulnerabilities in the Mail interface in Zimbra Collaboration Server (ZCS) be
23RISK
open
Referência
CVE-2026-15245
BNE Testimonials < 2.0.8.2 - Contributor+ Stored XSS via Slider Shortcode
33RISK
open
Referência
CVE-2012-1259
Multiple SQL injection vulnerabilities in Plixer International Scrutinizer NetFlow & sFlow Analyzer 8.6.2.16204, and pos
23RISK
open
Referência
CVE-2012-1259
Multiple SQL injection vulnerabilities in Plixer International Scrutinizer NetFlow & sFlow Analyzer 8.6.2.16204, and pos
23RISK
open
Referência
CVE-2012-1260
Cross-site scripting (XSS) vulnerability in cgi-bin/userprefs.cgi in Plixer International Scrutinizer NetFlow & sFlow An
23RISK
open
Referência
CVE-2014-6271
CVE-2014-6271CRITICALunder attack
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
Referência
CVE-2014-6271
CVE-2014-6271CRITICALunder attack
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
Referência
CVE-2014-6271
CVE-2014-6271CRITICALunder attack
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
Referência
CVE-2014-6271
CVE-2014-6271CRITICALunder attack
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
Referência
CVE-2014-6271
CVE-2014-6271CRITICALunder attack
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
Referência
CVE-2012-1261
Cross-site scripting (XSS) vulnerability in cgi-bin/scrut_fa_exclusions.cgi in Plixer International Scrutinizer NetFlow
23RISK
open
Referência
CVE-2026-19071
itsourcecode Hospital Management System viewappointment.php sql injection
33RISK
open
Referência
CVE-2026-19070
itsourcecode Hospital Management System viewadmin.php sql injection
33RISK
open
Referência
CVE-2015-6923
The ndvbs module in VBox Communications Satellite Express Protocol 2.3.17.3 allows local users to write to arbitrary phy
23RISK
open
Referência
CVE-2012-1466
The Traffic Grapher Server for NetMechanica NetDecision before 4.6.1 allows remote attackers to obtain the source code o
23RISK
open
Referência
CVE-2026-70637
LightFTP 2.4 Data Race Condition via ABOR Command in ftpserv.c
41RISK
open
ReferênciaVexDay Proof
WebCalendar 1.2.4 - Remote Code Execution
CVE-2012-1495webappsphp
install/index.php in WebCalendar before 1.2.5 allows remote attackers to execute arbitrary code via the form_single_user
60RISK
open
Referência
jira 4.4.3 / greenhopper < 5.9.8 - Multiple Vulnerabilities
CVE-2012-1500webappsjsp
Stored XSS vulnerability in UpdateFieldJson.jspa in JIRA 4.4.3 and GreenHopper before 5.9.8 allows an attacker to inject
23RISK
open
Referência
CVE-2010-0373
SQL injection vulnerability in the libros (com_libros) component for Joomla! allows remote attackers to execute arbitrar
23RISK
open
Referência
CVE-2012-1503
Cross-site scripting (XSS) vulnerability in Six Apart (formerly Six Apart KK) Movable Type (MT) Pro 5.13 allows remote a
23RISK
open
Referência
CVE-2026-19019
poco-ai poco-agent Claude File workspace.py WorkspaceManager._setup_session_persistence cleanup
33RISK
open
Referência
CVE-2026-19019
poco-ai poco-agent Claude File workspace.py WorkspaceManager._setup_session_persistence cleanup
33RISK
open
Referência
CVE-2026-19011
TinyAGI agents.ts buildSystemPrompt file inclusion
33RISK
open
Referência
CVE-2026-19010
TinyAGI Message API Endpoint index.ts processMessage authorization
33RISK
open
Referência
CVE-2012-1900
Cross-site request forgery (CSRF) vulnerability in admin/index.php in RazorCMS 1.2.1 and earlier allows remote attackers
23RISK
open
Referência
CVE-2012-1900
Cross-site request forgery (CSRF) vulnerability in admin/index.php in RazorCMS 1.2.1 and earlier allows remote attackers
23RISK
open
Referência
CVE-2026-67617
Microweber CMS 2.0.20 Stored XSS via tag_names Parameter
33RISK
open
previouspage 607 / 754next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.