Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,559cataloged exploits
34,978CVEs with public exploitation
24,695lab-tested
21,899 exploits
Referência
CVE-2026-14592
WP Real IP-based Access Control <= 1.3.1 - Unauthenticated Stored XSS via acl_ctrl_addr
33RISK
open
Referência
CVE-2026-14226
Easy Appointments <= 3.12.26 - Subscriber+ Sensitive Information Disclosure via REST Appointments Listing
33RISK
open
Referência
CVE-2026-14223
Easy Appointments <= 3.12.26 - Subscriber+ Customer PII Disclosure via IDOR
33RISK
open
Referência
CVE-2026-14222
Easy Appointments <= 3.12.26 - Contributor+ Connection Deletion via Missing Authorization
28RISK
open
Referência
CVE-2026-14221
Easy Appointments <= 3.12.26 - Contributor+ Appointment Data Disclosure & Modification via Missing Authorization
28RISK
open
Referência
CVE-2026-14188
Easy Appointments <= 3.12.26 - Contributor+ Customer Data Disclosure
28RISK
open
Referência
CVE-2026-41939
Care Everywhere Gateway 14.3.10 Hard-coded Credentials RCE via WildFly
48RISK
open
Referência
CVE-2026-67217
cJSON JSON Patch Non-Atomic Application Destroys Data Before Validation
33RISK
open
Referência
CVE-2026-67216
cJSON cJSON_Compare Exponential Complexity Denial of Service
41RISK
open
Referência
CVE-2026-67215
cJSON JSON Patch copy/add Uncontrolled Recursion Stack Exhaustion
41RISK
open
Referência
CVE-2026-13690
UsersWP < 1.2.67 - Two-Factor Authentication Bypass
41RISK
open
ReferênciaVexDay Proof
Mambo Component CopperminePhotoGalery - Remote File Inclusion
CVE-2006-4321webappsphp
PHP remote file inclusion vulnerability in cpg.php in the Coppermine Photo Gallery component (com_cpg) 1.0 and earlier f
23RISK
open
Referência
CVE-2026-13605
Photo Swipe <= 4.1.1.1 - Author+ Stored XSS via title Attribute
33RISK
open
Referência
CVE-2026-13423
Streamit <= 4.5.0 - Unauthenticated Remote Code Execution via Arbitrary Function Call
48RISK
open
Referência
CVE-2026-11974
Media folder Addon <= 4.1.6 - Unauthenticated Arbitrary File Download
41RISK
open
ReferênciaVexDay Proof
SFS Ez Forum - SQL Injection
CVE-2008-4754webappsphp
SQL injection vulnerability in forum.php in Scripts for Sites (SFS) Ez Forum allows remote attackers to execute arbitrar
23RISK
open
Referência
CVE-2026-67185
TinyWeb 0.0.8 Path Traversal via URL Path Component
41RISK
open
Referência
CVE-2015-9222
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MSM8909W,
23RISK
open
Referência
CVE-2012-4988
Heap-based buffer overflow in the xjpegls.dll (aka JLS, JPEG-LS, or JPEG lossless) format plugin in XnView 1.99 and 1.99
23RISK
open
Referência
CVE-2018-19782
Multiple cross-site scripting (XSS) vulnerabilities in GET requests in FreshRSS 1.11.1 allow remote attackers to inject
23RISK
open
Referência
CVE-2018-19782
Multiple cross-site scripting (XSS) vulnerabilities in GET requests in FreshRSS 1.11.1 allow remote attackers to inject
23RISK
open
Referência
CVE-2020-10385
A stored cross-site scripting (XSS) vulnerability exists in the WPForms Contact Form (aka wpforms-lite) plugin before 1.
23RISK
open
Referência
CVE-2022-4328
WooCommerce Checkout Field Manager < 18.0 - Unauthenticated Arbitrary File Upload
63RISK
open
Referência
CVE-2009-4867
Buffer overflow in Tuniac 090517c allows remote attackers to cause a denial of service (application crash) or possibly e
23RISK
open
Referência
CVE-2017-13875
An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "Intel Graph
23RISK
open
Referência
CVE-2019-9593
A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 18.82.2000.0 allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
Ext 1.0 - 'feed-proxy.php?feed' Remote File Disclosure
CVE-2007-2285webappsphp
Directory traversal vulnerability in examples/layout/feed-proxy.php in Jack Slocum Ext 1.0 alpha1 (Ext JS) allows remote
28RISK
open
ReferênciaVexDay Proof
SyndeoCMS 2.5.01 - 'cmsdir' Remote File Inclusion
CVE-2007-5840webappsphp
PHP remote file inclusion vulnerability in starnet/themes/c-sky/main.inc.php in Fred Stuurman SyndeoCMS 2.5.01 allows re
23RISK
open
ReferênciaVexDay Proof
Nokia e90/n82 (s60v3) - Remote Denial of Service
CVE-2008-4135doshardware
Symbian OS S60 3rd edition on the Nokia E90 Communicator 07.40.1.2 Ra-6 and Nseries N82 allows remote attackers to cause
23RISK
open
ReferênciaVexDay Proof
K&S Shopsysteme - Arbitrary File Upload
CVE-2008-6768webappsphp
Unrestricted file upload vulnerability in admin/editor/images.php in K&S Shopsoftware allows remote attackers to execute
23RISK
open
previouspage 336 / 730next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.