Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,107cataloged exploits
34,679CVEs with public exploitation
24,695lab-tested
21,692 exploits
Referência
CVE-2017-20246
KittyCatfish 2.2 Plugin for WordPress SQL Injection
41RISK
open
Referência
CVE-2017-20245
Wow Viral Signups 2.1 WordPress Plugin SQL Injection
41RISK
open
Referência
CVE-2017-20244
Wow Forms WordPress Plugin 2.1 SQL Injection
41RISK
open
Referência
CVE-2017-20243
WordPress Car Park Booking Plugin SQL Injection via space_id
41RISK
open
Referência
CVE-2016-20065
Product Catalog 8 1.2 Plugin WordPress SQL Injection
41RISK
open
Referência
CVE-2026-49494
Xcitium Client Security / Comodo Internet Security Remote Denial of Service
41RISK
open
Referência
CVE-2026-11459
SecureAge CatchPulse IOCTL saappctl.sys information disclosure
33RISK
open
Referência
CVE-2026-11459
SecureAge CatchPulse IOCTL saappctl.sys information disclosure
33RISK
open
Referência
CVE-2026-11458
erzhongxmu JeeWMS Boot Actuator Endpoint actuator information disclosure
33RISK
open
Referência
CVE-2026-11457
erzhongxmu JeeWMS JimuReport test-connection Endpoint testConnection injection
33RISK
open
Referência
CVE-2026-11411
iAI Lab PDF AI App chatpdf.pro getExternalCacheDir path traversal
33RISK
open
ReferênciaVexDay Proof
FastStone Image Viewer 3.6 - '.BMP' Image Crash
CVE-2008-5870doswindows
FastStone Image Viewer 3.6 allows user-assisted attackers to cause a denial of service (application crash) via a malform
23RISK
open
Referência
CVE-2026-15525
kLOsk adloop write.py _validate_urls server-side request forgery
33RISK
open
Referência
CVE-2026-15524
alioshr memory-bank-mcp list-project-files-validation-factory.ts path traversal
33RISK
open
Referência
CVE-2026-15523
CodeAstro Simple Online Leave Management System dashboard.php sql injection
33RISK
open
Referência
CVE-2026-15522
tugcantopaloglu godot-mcp run_project index.js validatePath path traversal
33RISK
open
Referência
CVE-2026-15521
makafeli n8n-workflow-builder update_node_from_file server.cjs path traversal
33RISK
open
Referência
CVE-2026-15520
GNU LibreDWG R2004 Section Decompression decode.c decompress_R2004_section heap-based overflow
33RISK
open
Referência
CVE-2011-4062
Buffer overflow in the kernel in FreeBSD 7.3 through 9.0-RC1 allows local users to cause a denial of service (panic) or
23RISK
open
ReferênciaVexDay Proof
Joomla! Component 5starhotels - SQL Injection
CVE-2008-5874webappsphp
Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System (aka HBS) for Joomla! allow remote attack
23RISK
open
ReferênciaVexDay Proof
Joomla! Component com_allhotels - Blind SQL Injection
CVE-2008-5874webappsphp
Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System (aka HBS) for Joomla! allow remote attack
23RISK
open
Referência
CVE-2026-15478
IceHRM UserReport Endpoint EmployeeAttendanceReport.php sql injection
33RISK
open
Referência
CVE-2026-15474
Eleveo Call Recording Software audio.jsp improper authorization
33RISK
open
Referência
CVE-2026-15473
Eleveo Call Recording Software Recorded Calls restoreCallAction.do improper authorization
33RISK
open
Referência
CVE-2026-15472
Eleveo Call Recording Software composeEmailAction.do improper authorization
33RISK
open
ReferênciaVexDay Proof
Joomla! Component com_lowcosthotels - Blind SQL Injection
CVE-2008-5875webappsphp
SQL injection vulnerability in the com_lowcosthotels component in the Hotel Booking Reservation System (aka HBS) for Joo
23RISK
open
Referência
CVE-2026-15471
Eleveo Call Recording Software pci_dss_status.jsp improper authorization
33RISK
open
Referência
CVE-2026-15470
Eleveo Call Recording Software group.jsp improper authorization
33RISK
open
Referência
CVE-2026-15311
NousResearch hermes-agent Matrix Adapter matrix.py MatrixAdapter._markdown_to_html cross site scripting
33RISK
open
Referência
CVE-2008-5923
SQL injection vulnerability in default.asp in ASP-DEv XM Events Diary allows remote attackers to execute arbitrary SQL c
23RISK
open
previouspage 293 / 724next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.