Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,008cataloged exploits
34,638CVEs with public exploitation
24,695lab-tested
21,662 exploits
Referência
CVE-2018-25318
Tenda FH303/A300 V5.07.68_EN Cookie Session Weakness DNS Change
48RISK
open
Referência
CVE-2018-25317
Tenda W3002R/A302/W309R V5.07.64_en Cookie Session Weakness DNS Change
48RISK
open
Referência
CVE-2018-25316
Tenda W308R v2 V5.07.48 Cookie Session Weakness DNS Change
48RISK
open
Referência
CVE-2018-25315
Alloksoft Video joiner 4.6.1217 Buffer Overflow via License Name
41RISK
open
Referência
CVE-2018-25314
Allok soft WMV to AVI MPEG DVD WMV Converter 4.6.1217 Buffer Overflow
41RISK
open
Referência
CVE-2018-25313
SysGauge 4.5.18 Local Denial of Service via Proxy Configuration
33RISK
open
Referência
CVE-2018-25304
Free Download Manager 2.0 Build 417 Local Buffer Overflow SEH
41RISK
open
Referência
CVE-2026-14736
Ruijie RG-UAC user_auth_commit.php unrestricted upload
33RISK
open
Referência
CVE-2026-14735
code-projects Smart Parking System parkings.php sql injection
33RISK
open
Referência
CVE-2026-14734
SourceCodester Class and Exam Timetabling System edit_product.php sql injection
33RISK
open
Referência
CVE-2026-14733
SourceCodester Class and Exam Timetabling System edit_coursea.php sql injection
33RISK
open
Referência
CVE-2026-14732
SourceCodester Class and Exam Timetabling System edit_exam.php sql injection
33RISK
open
ReferênciaVexDay Proof
Sun Board 1.00.00 alpha - Remote File Inclusion
CVE-2007-3370webappsphp
Multiple PHP remote file inclusion vulnerabilities in Sun Board 1.00.00 Alpha allow remote attackers to execute arbitrar
45RISK
open
ReferênciaVexDay Proof
NCTAudioEditor2 ActiveX DLL 'NCTWMAFile2.dll 2.6.2.157' - File Write
CVE-2007-3400remotewindows
The NCTAudioEditor2 ActiveX control in NCTWMAFile2.dll 2.6.2.157, as distributed in NCTAudioEditor and NCTAudioStudio 2.
23RISK
open
ReferênciaVexDay Proof
phpTrafficA 1.4.2 - 'pageid' SQL Injection
CVE-2007-3426webappsphp
Cross-site scripting (XSS) vulnerability in index.php in phpTrafficA 1.4.2 and earlier allows remote attackers to inject
23RISK
open
ReferênciaVexDay Proof
phpTrafficA 1.4.2 - 'pageid' SQL Injection
CVE-2007-3427webappsphp
SQL injection vulnerability in index.php in phpTrafficA 1.4.2 and earlier allows remote attackers to execute arbitrary S
23RISK
open
ReferênciaVexDay Proof
Pharmacy System 2.0 - 'index.php?ID' SQL Injection
CVE-2007-3433webappsphp
SQL injection vulnerability in index.php in Pharmacy System 2 and earlier allows remote attackers to execute arbitrary S
23RISK
open
Referência
CVE-2026-66749
Let's Chat 0.4.0 - 0.4.8 Denial of Service via Null Dereference in Room Lookup
41RISK
open
Referência
CVE-2026-18038
nextlevelbuilder GoClaw jq Handler tools_invoke.go ExecTool.Execute information disclosure
33RISK
open
Referência
CVE-2026-14926
FluentCart < 1.4.0 - Subscriber+ Subscription Payment-Method Tampering via IDOR
33RISK
open
Referência
CVE-2026-14924
Tablesome < 1.1.31 - Unauthenticated Post Creation and Modification
41RISK
open
Referência
CVE-2026-14870
Database for Contact Form 7, WPforms, Elementor forms < 1.5.3 - Reflected XSS via form_id
41RISK
open
Referência
CVE-2026-14821
Quiz And Survey Master < 11.1.5 - Contributor+ Arbitrary Template Deletion
28RISK
open
ReferênciaVexDay Proof
RKD Software BarCode ActiveX Control 'BarCodeAx.dll' 4.9 - Remote Overflow
CVE-2007-3435remotewindows
Stack-based buffer overflow in the BeginPrint method in a certain ActiveX control in RKD Software (barcodetools.com) Bar
50RISK
open
Referência
CVE-2026-14819
Event Tickets < 5.28.4 - Editor+ Stored XSS via Ticket Move
28RISK
open
ReferênciaVexDay Proof
bugmall shopping cart 2.5 - SQL Injection / Cross-Site Scripting
CVE-2007-3448webappsphp
Cross-site scripting (XSS) vulnerability in index.php in BugMall Shopping Cart 2.5 and earlier allows remote attackers t
23RISK
open
Referência
CVE-2026-66029
Ekushey Project Manager CRM 5.0 Stored XSS via Client Name Field
33RISK
open
Referência
CVE-2026-5659
pytries datrie trie File datrie.pyx Trie.__setstate__ deserialization
33RISK
open
Referência
CVE-2026-5650
code-projects Online Application System for Admission oas.sql sensitive information
33RISK
open
Referência
CVE-2026-5649
code-projects Online Application System for Admission Endpoint admsnform.php sql injection
33RISK
open
previouspage 277 / 723next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.