Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,056cataloged exploits
35,925CVEs with public exploitation
24,695lab-tested
22,640 exploits
Referência
CVE-2016-0099
CVE-2016-0099HIGHunder attackransomware
The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8
98RISK
open
Referência
CVE-2012-2572
Cross-site scripting (XSS) vulnerability in the ThreeWP Email Reflector plugin before 1.16 for WordPress allows remote a
23RISK
open
Referência
CVE-2016-0168
GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012
35RISK
open
Referência
CVE-2016-0189
CVE-2016-0189HIGHunder attackransomware
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other
100RISK
open
Referência
CVE-2012-2576
SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Prof
50RISK
open
Referência
CVE-2010-1060
Directory traversal vulnerability in staff/app/common.inc.php in Phpkobo Short URL 1.01, when magic_quotes_gpc is disabl
23RISK
open
Referência
CVE-2012-2580
Cross-site scripting (XSS) vulnerability in the Postie plugin 1.4.3, and possibly before 1.5.15, for WordPress allows re
23RISK
open
Referência
CVE-2012-2583
Cross-site scripting (XSS) vulnerability in Mini Mail Dashboard Widget plugin 1.42 for WordPress allows remote attackers
23RISK
open
Referência
CVE-2026-61511
vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php
75RISK
open
Referência
CVE-2012-2584
Multiple cross-site scripting (XSS) vulnerabilities in Alt-N MDaemon Free 12.5.4 allow remote attackers to inject arbitr
23RISK
open
Referência
CVE-2026-14189
WPBot AI ChatBot < 8.5.2 - Admin+ Second-Order SQL Injection via qc_bot_str_fields
28RISK
open
Referência
CVE-2012-2591
Multiple cross-site scripting (XSS) vulnerabilities in EmailArchitect Email Server 10.0 and 10.0.0.3 allow remote attack
23RISK
open
Referência
CVE-2025-71408
NLTK < 3.9.3 Eval Injection via collocations.py Command-Line Arguments
41RISK
open
Referência
CVE-2026-65709
sysPass 3.2.11 Missing Object-Level Authorization via JSON-RPC API
41RISK
open
Referência
CVE-2012-2601
SQL injection vulnerability in WrVMwareHostList.asp in Ipswitch WhatsUp Gold 15.02 allows remote attackers to execute ar
23RISK
open
Referência
CVE-2026-63087
Grafana OnCall 1.16.11 Unauthenticated Token Hijack via Plugin Install Endpoint
48RISK
open
Referência
CVE-2010-0711
Cross-site request forgery (CSRF) vulnerability in default.asp in ASPCode CMS 1.5.8, 2.0.0 Build 103, and possibly other
23RISK
open
Referência
CVE-2023-28771
CVE-2023-28771CRITICALunder attack
Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware vers
100RISK
open
Referência
CVE-2014-6332
CVE-2014-6332HIGHunder attack
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RISK
open
Referência
CVE-2014-6332
CVE-2014-6332HIGHunder attack
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RISK
open
ReferênciaVexDay Proof
PHP Live! 3.2.2 - 'questid' SQL Injection (1)
CVE-2008-0821webappsphp
SQL injection vulnerability in admin/traffic/knowledge_searchm.php in OSI Codes Inc. PHP Live! 3.2.2 allows remote attac
23RISK
open
ReferênciaVexDay Proof
Simple CMS 1.0.3 - 'area' SQL Injection
CVE-2008-0835webappsphp
SQL injection vulnerability in indexen.php in Simple CMS 1.0.3 and earlier allows remote attackers to execute arbitrary
23RISK
open
Referência
CVE-2010-2334
Directory traversal vulnerability in themes/default/download.php in Yamamah Photo Gallery 1.00, as distributed before 20
23RISK
open
Referência
CVE-2010-2358
PHP remote file inclusion vulnerability in modules/catalog/upload_photo.php in Nakid CMS 0.5.2, when magic_quotes_gpc is
23RISK
open
Referência
CVE-2010-2458
Cross-site scripting (XSS) vulnerability in video.php in 2daybiz Video Community Portal Script 1.0 allows remote attacke
23RISK
open
Referência
CVE-2010-2461
SQL injection vulnerability in storecat.php in JCE-Tech Overstock 1 allows remote attackers to execute arbitrary SQL com
23RISK
open
Referência
CVE-2010-2461
SQL injection vulnerability in storecat.php in JCE-Tech Overstock 1 allows remote attackers to execute arbitrary SQL com
23RISK
open
Referência
CVE-2021-40539
CVE-2021-40539CRITICALunder attackransomware
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resulta
100RISK
open
Referência
CVE-2019-3929
CVE-2019-3929CRITICALunder attack
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Ba
100RISK
open
Referência
CVE-2019-3929
CVE-2019-3929CRITICALunder attack
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Ba
100RISK
open
previouspage 617 / 755next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.