Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,900cataloged exploits
35,840CVEs with public exploitation
24,695lab-tested
22,600 exploits
Referência
CVE-2026-19207
PHPGurukul Company Visitor Management System manage-newvisitors.php cross site scripting
33RISK
open
Referência
CVE-2022-4995
Weaver E-cology 9.0 File Upload RCE via uploaderOperate.jsp
48RISK
open
Referência
CVE-2022-4995
Weaver E-cology 9.0 File Upload RCE via uploaderOperate.jsp
48RISK
open
Referência
CVE-2026-15148
WP Events Manager < 2.2.5 - Unauthenticated Payment Bypass and Booking Status Update via IDOR
33RISK
open
Referência
CVE-2015-7257
ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated non-administrato
23RISK
open
Referência
CVE-2012-1790
Absolute path traversal vulnerability in Webgrind 1.0 and 1.0.2 allows remote attackers to read arbitrary files via a fu
23RISK
open
Referência
CVE-2012-1790
Absolute path traversal vulnerability in Webgrind 1.0 and 1.0.2 allows remote attackers to read arbitrary files via a fu
23RISK
open
Referência
CVE-2026-18790
Systerel S2OPC DeleteMonitoredItemsRequest state_machine.c out-of-bounds
33RISK
open
Referência
CVE-2015-7857
SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.p
60RISK
open
Referência
CVE-2010-0467
Directory traversal vulnerability in the ccNewsletter (com_ccnewsletter) component 1.0.5 for Joomla! allows remote attac
50RISK
open
Referência
CVE-2012-1979
Cross-site scripting (XSS) vulnerability in starnet/index.php in SyndeoCMS 3.0.01 and earlier allows remote authenticate
23RISK
open
Referência
CVE-2012-2095
The SetWiredProperty function in the D-Bus interface in WICD before 1.7.2 allows local users to write arbitrary configur
23RISK
open
Referência
CVE-2012-2110
The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in OpenSSL before 0.9.8v, 1.0.0 before 1.0.0i, and 1.0.1 before
35RISK
open
Referência
CVE-2012-2206
The Web Gateway component in IBM WebSphere MQ File Transfer Edition 7.0.4 and earlier allows remote authenticated users
23RISK
open
Referência
CVE-2021-33045
CVE-2021-33045CRITICALunder attack
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RISK
open
Referência52
Scanner for CVE-2024-4040
CVE-2024-4040CRITICALunder attack
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISK
open
Referência
CVE-2015-8770
Directory traversal vulnerability in the set_skin function in program/include/rcmail_output_html.php in Roundcube before
28RISK
open
Referência
CVE-2010-0607
Cross-site scripting (XSS) vulnerability in Forms/status_statistics_1 in the Sterlite SAM300 AX Router allows remote att
23RISK
open
Referência
CVE-2016-0099
CVE-2016-0099HIGHunder attackransomware
The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8
98RISK
open
Referência
CVE-2016-0099
CVE-2016-0099HIGHunder attackransomware
The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8
98RISK
open
Referência
CVE-2012-2572
Cross-site scripting (XSS) vulnerability in the ThreeWP Email Reflector plugin before 1.16 for WordPress allows remote a
23RISK
open
Referência
CVE-2016-0168
GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012
28RISK
open
Referência
CVE-2016-0189
CVE-2016-0189HIGHunder attackransomware
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other
100RISK
open
Referência
CVE-2012-2576
SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Prof
50RISK
open
Referência
CVE-2023-3519
CVE-2023-3519CRITICALunder attackransomware
Unauthenticated remote code execution
100RISK
open
Referência
CVE-2010-1472
Directory traversal vulnerability in the Daily Horoscope (com_horoscope) component 1.5.0 for Joomla! allows remote attac
43RISK
open
Referência
CVE-2026-8189
Wavlink NU516U1 adm.cgi wzdrepeater os command injection
33RISK
open
Referência
CVE-2026-8188
Wavlink NU516U1 adm.cgi change_wifi_password os command injection
33RISK
open
Referência
CVE-2010-0672
SQL injection vulnerability in index.php in WSN Guest 1.02 allows remote attackers to execute arbitrary SQL commands via
23RISK
open
Referência
CVE-2010-1723
Directory traversal vulnerability in the iNetLanka Contact Us Draw Root Map (com_drawroot) component 1.1 for Joomla! all
38RISK
open
previouspage 613 / 754next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.