Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,008cataloged exploits
34,638CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,662GitHub PoC 13,743VulnCheck XDB 8,460Nuclei 4,233Metasploit 3,467✓ verified onlyrecentpopularrisk
21,662 exploits
Referência
CVE-2018-25317
Tenda W3002R/A302/W309R V5.07.64_en Cookie Session Weakness DNS Change
48RISK
open ↗Referência
CVE-2018-25315
Alloksoft Video joiner 4.6.1217 Buffer Overflow via License Name
41RISK
open ↗Referência
CVE-2018-25314
Allok soft WMV to AVI MPEG DVD WMV Converter 4.6.1217 Buffer Overflow
41RISK
open ↗Referência
CVE-2026-14734
SourceCodester Class and Exam Timetabling System edit_product.php sql injection
33RISK
open ↗Referência
CVE-2026-14733
SourceCodester Class and Exam Timetabling System edit_coursea.php sql injection
33RISK
open ↗Referência
CVE-2026-14732
SourceCodester Class and Exam Timetabling System edit_exam.php sql injection
33RISK
open ↗Referência✓ VexDay Proof
Sun Board 1.00.00 alpha - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Sun Board 1.00.00 Alpha allow remote attackers to execute arbitrar
45RISK
open ↗Referência✓ VexDay Proof
NCTAudioEditor2 ActiveX DLL 'NCTWMAFile2.dll 2.6.2.157' - File Write
The NCTAudioEditor2 ActiveX control in NCTWMAFile2.dll 2.6.2.157, as distributed in NCTAudioEditor and NCTAudioStudio 2.
23RISK
open ↗Referência✓ VexDay Proof
phpTrafficA 1.4.2 - 'pageid' SQL Injection
Cross-site scripting (XSS) vulnerability in index.php in phpTrafficA 1.4.2 and earlier allows remote attackers to inject
23RISK
open ↗Referência✓ VexDay Proof
phpTrafficA 1.4.2 - 'pageid' SQL Injection
SQL injection vulnerability in index.php in phpTrafficA 1.4.2 and earlier allows remote attackers to execute arbitrary S
23RISK
open ↗Referência✓ VexDay Proof
Pharmacy System 2.0 - 'index.php?ID' SQL Injection
SQL injection vulnerability in index.php in Pharmacy System 2 and earlier allows remote attackers to execute arbitrary S
23RISK
open ↗Referência
CVE-2026-66749
Let's Chat 0.4.0 - 0.4.8 Denial of Service via Null Dereference in Room Lookup
41RISK
open ↗Referência
CVE-2026-18038
nextlevelbuilder GoClaw jq Handler tools_invoke.go ExecTool.Execute information disclosure
33RISK
open ↗Referência
CVE-2026-14926
FluentCart < 1.4.0 - Subscriber+ Subscription Payment-Method Tampering via IDOR
33RISK
open ↗Referência
CVE-2026-14924
Tablesome < 1.1.31 - Unauthenticated Post Creation and Modification
41RISK
open ↗Referência
CVE-2026-14870
Database for Contact Form 7, WPforms, Elementor forms < 1.5.3 - Reflected XSS via form_id
41RISK
open ↗Referência
CVE-2026-14821
Quiz And Survey Master < 11.1.5 - Contributor+ Arbitrary Template Deletion
28RISK
open ↗Referência✓ VexDay Proof
RKD Software BarCode ActiveX Control 'BarCodeAx.dll' 4.9 - Remote Overflow
Stack-based buffer overflow in the BeginPrint method in a certain ActiveX control in RKD Software (barcodetools.com) Bar
50RISK
open ↗Referência✓ VexDay Proof
bugmall shopping cart 2.5 - SQL Injection / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in BugMall Shopping Cart 2.5 and earlier allows remote attackers t
23RISK
open ↗Referência
CVE-2026-66029
Ekushey Project Manager CRM 5.0 Stored XSS via Client Name Field
33RISK
open ↗Referência
CVE-2026-5659
pytries datrie trie File datrie.pyx Trie.__setstate__ deserialization
33RISK
open ↗Referência
CVE-2026-5650
code-projects Online Application System for Admission oas.sql sensitive information
33RISK
open ↗Referência
CVE-2026-5649
code-projects Online Application System for Admission Endpoint admsnform.php sql injection
33RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.