Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,647cataloged exploits
34,986CVEs with public exploitation
24,695lab-tested
21,899 exploits
Referência
CVE-2020-7247
CVE-2020-7247CRITICALunder attack
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISK
open
Referência
CVE-2020-7247
CVE-2020-7247CRITICALunder attack
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISK
open
Referência
CVE-2020-7247
CVE-2020-7247CRITICALunder attack
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISK
open
ReferênciaVexDay Proof
phpBB Mod FileBase 2.0 - 'id' SQL Injection
CVE-2008-1305webappsphp
SQL injection vulnerability in filebase.php in the Filebase mod for phpBB allows remote attackers to execute arbitrary S
23RISK
open
Referência
CVE-2023-32560
An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disrup
78RISK
open
Referência
CVE-2023-32560
An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disrup
78RISK
open
ReferênciaVexDay Proof
Bloo 1.00 - Multiple SQL Injections
CVE-2008-1313webappsphp
Multiple SQL injection vulnerabilities in index.php in Bloo 1.00 and earlier allow remote attackers to execute arbitrary
23RISK
open
Referência
CVE-2020-7209
LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2.
60RISK
open
Referência
CVE-2020-7209
LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2.
60RISK
open
Referência
CVE-2026-61514
Puwell IP Camera 2.x - 4.x Unauthenticated Access via TCP Port 23456
48RISK
open
Referência
CVE-2026-61515
Puwell IP Camera 2.x - 4.x Unauthenticated Command Injection via DebugShell
48RISK
open
Referência
CVE-2026-16548
Bit Assist < 1.8.2 - Unauthenticated Arbitrary File Upload via Response Endpoint
33RISK
open
Referência
CVE-2026-16547
REST API Log < 1.7.1 - Unauthenticated Sensitive Log Data Disclosure via Download Endpoint
33RISK
open
Referência
CVE-2026-16546
Wired Impact Volunteer Management < 2.8.2 - Subscriber+ Arbitrary RSVP Removal via wivm_remove_rsvp
33RISK
open
Referência
CVE-2026-16296
Clearfy < 2.4.3 - Open Redirect via Cyrlitera 404 Handler
33RISK
open
Referência
CVE-2026-16295
Clearfy < 2.4.3 - Subscriber+ Sensitive Information Disclosure via Factory Page-Action Dispatcher
33RISK
open
ReferênciaVexDay Proof
Versant Object Database 7.0.1.3 - Commands Execution
CVE-2008-1319remotewindows
Untrusted search path and argument injection vulnerability in the VersantD service in Versant Object Database 7.0.1.3 an
23RISK
open
ReferênciaVexDay Proof
EasyCalendar 4.0tr - Multiple Vulnerabilities
CVE-2008-1344webappsphp
Multiple SQL injection vulnerabilities in MyioSoft EasyCalendar 4.0tr and earlier allow remote attackers to execute arbi
23RISK
open
Referência
CVE-2012-3152
CVE-2012-3152CRITICALunder attack
Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and
100RISK
open
ReferênciaVexDay Proof
EasyCalendar 4.0tr - Multiple Vulnerabilities
CVE-2008-1345webappsphp
Cross-site scripting (XSS) vulnerability in plugins/calendar/calendar_backend.php in MyioSoft EasyCalendar 4.0tr and ear
23RISK
open
Referência
CVE-2018-15473
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open
Referência
CVE-2026-16293
Blubrry PowerPress < 11.16.11 - Contributor+ Stored XSS via Podcast Episode Chapters URL
33RISK
open
Referência
CVE-2015-1427
CVE-2015-1427CRITICALunder attack
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the s
100RISK
open
Referência
Online Magazine Management System 1.0 - SQLi Authentication Bypass
CVE-2021-44653webappsphp
Online Magazine Management System 1.0 contains a SQL injection authentication bypass vulnerability. The Admin panel auth
23RISK
open
Referência
CVE-2010-1980
Directory traversal vulnerability in joomlaflickr.php in the Joomla Flickr (com_joomlaflickr) component 1.0.3 for Joomla
43RISK
open
Referência
CVE-2019-1003000
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RISK
open
Referência
CVE-2019-1003000
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RISK
open
Referência
CVE-2019-1003000
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RISK
open
Referência
CVE-2018-12613
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RISK
open
Referência
CVE-2018-12613
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RISK
open
previouspage 360 / 730next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.