Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,542cataloged exploits
34,971CVEs with public exploitation
24,695lab-tested
21,899 exploits
ReferênciaVexDay Proof
Ay System CMS 2.6 - 'main.php' Remote File Inclusion
CVE-2006-4440webappsphp
PHP remote file inclusion vulnerability in main.php in Ay System Solutions CMS 2.6 and earlier allows remote attackers t
23RISK
open
ReferênciaVexDay Proof
Interact 2.2 - 'CONFIG[base_path]' Remote File Inclusion
CVE-2006-4448webappsphp
Multiple PHP remote file inclusion vulnerabilities in interact 2.2, when register_globals is enabled, allow remote attac
23RISK
open
ReferênciaVexDay Proof
XChat 2.6.7 (Windows) - Remote Denial of Service
CVE-2006-4455doswindows
Unspecified vulnerability in Xchat 2.6.7 and earlier allows remote attackers to cause a denial of service (crash) via un
23RISK
open
Referência
CVE-2026-13559
code-projects Real State Services single-list_sale.php add sql injection
33RISK
open
Referência
CVE-2026-57521
Bitwarden Server < 2026.5.0 Broken Access Control via PreviewInvoiceController
33RISK
open
Referência
CVE-2026-56774
Kanboard - Cross-User Deletion of Persistent Login Sessions via Unvalidated Session ID
33RISK
open
Referência
CVE-2026-56770
libais 0.15 - Out-of-bounds Vector Access in VdmStream::AddLine via Invalid Sequential Message ID
41RISK
open
Referência
CVE-2026-56769
Huly Platform - Server-Side Request Forgery via /import Endpoint
33RISK
open
Referência
CVE-2026-12183
Nefteprodukttekhnika BUK TS-G Gas Station Automation System Authentication Bypass via ajax-login.php Accepting Arbitrary Credentials
48RISK
open
Referência
CVE-2026-9062
Agile Store Locator < 1.6.9 - Admin+ Arbitrary File Read via Path Traversal
28RISK
open
Referência
CVE-2026-12066
PbootCMS Password MemberController.php retrieve password recovery
33RISK
open
Referência
CVE-2026-12065
Groww Stock, Mutual Fund, Gold App WebView URL improper authorization in handler for custom url scheme
28RISK
open
Referência
CVE-2026-12065
Groww Stock, Mutual Fund, Gold App WebView URL improper authorization in handler for custom url scheme
28RISK
open
Referência
CVE-2026-8589
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
41RISK
open
Referência
CVE-2026-20253
CVE-2026-20253CRITICALunder attack
Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprise
100RISK
open
Referência
CVE-2026-25860
OpenClinic GA 5.351.19 Reflected XSS via DICOM Image Upload Handler
33RISK
open
Referência
CVE-2026-25860 POC git
OpenClinic GA 5.351.19 Reflected XSS via DICOM Image Upload Handler
33RISK
open
Referência
CVE-2026-34417
OSCAL-GUI Reflected XSS via project parameter in oscal-forms.php
33RISK
open
Referência
CVE-2026-34416
OSCAL-GUI Reflected XSS via project parameter in oscal.php
33RISK
open
Referência
CVE-2017-20250
WordPress Plugin Mac Photo Gallery 3.0 Arbitrary File Download
41RISK
open
Referência
CVE-2025-55651
A NULL pointer dereference in the gf_isom_get_user_data_count function (isomedia/isom_read.c) of GPAC MP4Box v2.4 allows
33RISK
open
Referência
CVE-2026-11582
CodeAstro Student Attendance Management System index.php sql injection
33RISK
open
Referência
CVE-2026-11559
CodeAstro Payroll System view_account.php sql injection
33RISK
open
Referência
CVE-2026-25555
OpenBullet2 0.3.2 Authentication Bypass via X-Api-Key Header
63RISK
open
Referência
CVE-2021-22005
CVE-2021-22005CRITICALunder attackransomware
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RISK
open
Referência
CVE-2017-8484
Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2,
23RISK
open
Referência
CVE-2020-5902
CVE-2020-5902CRITICALunder attackransomware
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISK
open
Referência
CVE-2026-10616
nextlevelbuilder GoClaw Team Task Completion team_tasks_lifecycle.go TeamTasksTool.executeComplete authorization
33RISK
open
Referência
CVE-2026-10297
itsourcecode Fees Management System manage_course.php sql injection
33RISK
open
Referência
CVE-2026-10296
itsourcecode Fees Management System ajax.php sql injection
33RISK
open
previouspage 333 / 730next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.