Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,542cataloged exploits
34,971CVEs with public exploitation
24,695lab-tested
21,899 exploits
Referência
CVE-2026-63080
Aptabase SQL Injection via ClickHouse query backend
41RISK
open
Referência
CVE-2026-16334
itsourcecode Hospital Management System prescriptionorder.php sql injection
33RISK
open
Referência
CVE-2026-16332
D-Link DNS-320 multi_uploadify.php unrestricted upload
33RISK
open
Referência
CVE-2026-13432
ThumbPress < 6.2.2 - Subscriber+ Plugin Deactivation
33RISK
open
Referência
CVE-2026-13156
MailerSend - Official SMTP Integration < 1.0.8 - Settings Deletion and Plugin Deactivation via CSRF
33RISK
open
Referência
CVE-2026-12972
PayPlus Payment Gateway < 8.2.2 - Unauthenticated Order Payment Metadata Tampering
33RISK
open
Referência
CVE-2026-12898
All-in-One WP Migration and Backup < 7.106 - Unauthenticated Arbitrary-Location Log File Write via Path Traversal
33RISK
open
Referência
CVE-2026-12724
Kirki < 6.0.12 - Unauthenticated HTML Injection in Password Reset Email via kirki-forgot-password
33RISK
open
Referência
CVE-2026-16220
code-projects Online Examination System account.php cross site scripting
33RISK
open
Referência
CVE-2026-16219
Croogo CMS Admin File Manager FileManager.php isEditable path traversal
33RISK
open
Referência
CVE-2026-16217
guohongze adminset Delivery Deployment Endpoint deli.py authorization
33RISK
open
Referência
CVE-2026-16216
geex-arts django-jet OAuth cross-site request forgery
33RISK
open
Referência
CVE-2026-16215
geex-arts django-jet OAuth Credential Revoke authorization
33RISK
open
Referência
CVE-2017-17595
Beauty Parlour Booking Script 1.0 has SQL Injection via the /list gender or city parameter.
23RISK
open
Referência
CVE-2018-10077
XML external entity (XXE) vulnerability in Geist WatchDog Console 3.2.2 allows remote authenticated administrators to re
23RISK
open
Referência
CVE-2018-10077
XML external entity (XXE) vulnerability in Geist WatchDog Console 3.2.2 allows remote authenticated administrators to re
23RISK
open
Referência
CVE-2026-16203
SourceCodester Class and Exam Timetabling System forCYS.php cross site scripting
33RISK
open
Referência
CVE-2013-4743
Static HTTP Server 1.0 has a Local Overflow
23RISK
open
Referência
CVE-2015-2184
ZeusCart 4 allows remote attackers to obtain configuration information via a getphpinfo action to admin/, which calls th
23RISK
open
Referência
CVE-2019-6282
ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have CSRF via the cgi-bin/webproc?getpag
23RISK
open
Referência
CVE-2019-6282
ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have CSRF via the cgi-bin/webproc?getpag
23RISK
open
Referência
CVE-2015-2055
Zhone GPON 2520 with firmware R4.0.2.566b allows remote attackers to cause a denial of service via a long string in the
23RISK
open
Referência
CVE-2017-11321
The restricted shell interface in UCOPIA Wireless Appliance before 5.1.8 allows remote authenticated users to gain 'admi
23RISK
open
Referência
CVE-2009-4365
Multiple cross-site request forgery (CSRF) vulnerabilities in admin.php in ScriptsEz Ez Blog 1.0 allow remote attackers
23RISK
open
Referência
CVE-2010-20121
EasyFTP Server <= 1.7.0.11 CWD Command Stack Buffer Overflow
63RISK
open
Referência
CVE-2010-20121
EasyFTP Server <= 1.7.0.11 CWD Command Stack Buffer Overflow
63RISK
open
Referência
CVE-2010-20121
EasyFTP Server <= 1.7.0.11 CWD Command Stack Buffer Overflow
63RISK
open
Referência
CVE-2010-20121
EasyFTP Server <= 1.7.0.11 CWD Command Stack Buffer Overflow
63RISK
open
Referência
CVE-2017-5798
A Remote Code Execution vulnerability in HPE OpenCall Media Platform (OCMP) was found. The vulnerability impacts OCMP ve
23RISK
open
Referência
CVE-2010-20121
EasyFTP Server <= 1.7.0.11 CWD Command Stack Buffer Overflow
63RISK
open
previouspage 334 / 730next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.