Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,151cataloged exploits
35,370CVEs with public exploitation
24,695lab-tested
22,233 exploits
Referência
CVE-2018-25281
iCash 7.6.5 Denial of Service via Connect to Server
33RISK
open
Referência
CVE-2018-25280
Infiltrator Network Security Scanner 4.6 Denial of Service
33RISK
open
Referência
CVE-2018-25279
jiNa OCR Image to Text 1.0 Denial of Service via PNG
33RISK
open
Referência
CVE-2018-25278
PicaJet FX 2.6.5 Denial of Service via Registration Fields
33RISK
open
Referência
CVE-2018-0752
The Windows Kernel API in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709
23RISK
open
Referência
CVE-2018-0823
The Named Pipe File System in Windows 10 version 1709 and Windows Server, version 1709 allows an elevation of privilege
23RISK
open
Referência
CVE-2026-5806
code-projects Easy Blog Site update.php cross site scripting
33RISK
open
Referência
CVE-2026-5805
code-projects Easy Blog Site contact_us.php sql injection
33RISK
open
Referência
CVE-2026-5803
bigsk1 openai-realtime-ui API Proxy Endpoint server.js server-side request forgery
33RISK
open
Referência
CVE-2026-5802
idachev mcp-javadc HTTP os command injection
33RISK
open
Referência
CVE-2026-4338
ActivityPub Routing < 8.0.2 - Unauthenticated Drafts/Scheduled/Pending Posts Disclosure
41RISK
open
Referência
CVE-2026-5741
suvarchal docker-mcp-server HTTP index.ts pull_image os command injection
33RISK
open
Referência
CVE-2018-0838
Microsoft Edge and ChakraCore in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remot
35RISK
open
Referência
CVE-2018-0860
Microsoft Edge and ChakraCore in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remot
35RISK
open
Referência
CVE-2018-25277
PixGPS 1.1.8 Buffer Overflow Denial of Service
33RISK
open
Referência
CVE-2018-25276
RoboImport 1.2.0.72 Denial of Service via Registration Fields
33RISK
open
Referência
CVE-2018-25275
Faleemi Plus 1.0.2 Denial of Service via Buffer Overflow
33RISK
open
Referência
CVE-2018-25274
InfraRecorder 0.53 Denial of Service via txt File Import
33RISK
open
Referência
CVE-2018-25273
CrossFont 7.5 Denial of Service via License Key Field
33RISK
open
Referência
CVE-2018-0897
The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Serve
23RISK
open
Referência
CVE-2026-7019
Tenda F456 P2pListFilter fromP2pListFilter buffer overflow
41RISK
open
Referência
CVE-2026-7018
Datavane Datavines JWT Token TokenManager.java hard-coded key
33RISK
open
Referência
CVE-2026-7016
MaxSite CMS ushki Plugin cross site scripting
33RISK
open
Referência
CVE-2026-7015
MaxSite CMS Guestbook Plugin cross site scripting
33RISK
open
Referência
CVE-2026-7014
MaxSite CMS down_count Plugin cross site scripting
33RISK
open
Referência
CVE-2026-7013
MaxSite CMS mail_send Plugin cross site scripting
33RISK
open
Referência
CVE-2026-7012
MaxSite CMS Redirect Plugin cross site scripting
33RISK
open
Referência
CVE-2024-14032
Twitch Studio LauncherHelper XPC Missing Authorization to Root File Write
41RISK
open
Referência
CVE-2026-5666
code-projects Online FIR System SQL Database Backup File complaints.sql sensitive information
33RISK
open
Referência
CVE-2026-5665
code-projects Online FIR System Login checklogin.php sql injection
33RISK
open
previouspage 421 / 742next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.