Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,231cataloged exploits
35,420CVEs with public exploitation
24,695lab-tested
22,266 exploits
Referência
CVE-2026-11568
Product Configurator for WooCommerce < 1.7.3 - Unauthenticated Private/Draft Product Data Disclosure via pc_get_data
41RISK
open
Referência
CVE-2026-11581
Kali Forms < 2.4.13 - Contributor+ Stored XSS via Form Field Caption
33RISK
open
Referência
CVE-2010-5041
SQL injection vulnerability in index.php in the NP_Gallery plugin 0.94 for Nucleus allows remote attackers to execute ar
23RISK
open
Referência
CVE-2018-12094
Cross-site scripting (XSS) vulnerability in news.php in Dimofinf CMS Version 3.0.0 allows remote attackers to inject arb
23RISK
open
Referência
CVE-2018-12114
Maccms 10 allows CSRF via admin.php/admin/admin/info.html to add user accounts.
23RISK
open
Referência
CVE-2018-12234
A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Adrenalin 5.4.0 HRMS Software. The user supplied
23RISK
open
Referência
CVE-2026-11482
SourceCodester Class and Exam Timetabling System archive5.php sql injection
33RISK
open
Referência
CVE-2026-11481
yoanbernabeu grepai Postgres Embedding Cache chunker.go PostgresStore.LookupByContentHash weak hash
28RISK
open
Referência
CVE-2021-47968
Podcast Generator 3.1 Persistent Cross-Site Scripting via long_description
33RISK
open
Referência
CVE-2021-47967
PHP Timeclock 1.04 Multiple Cross-Site Scripting via Parameters
33RISK
open
Referência
CVE-2021-47966
PHP Timeclock 1.04 SQL Injection via login.php
41RISK
open
Referência
CVE-2010-5044
SQL injection vulnerability in models/log.php in the Search Log (com_searchlog) component 3.1.0 for Joomla! allows remot
23RISK
open
ReferênciaVexDay Proof
PHP < 4.4.5/5.2.1 - 'shmop' Local Code Execution
CVE-2007-1376locallinux
The shmop functions in PHP before 4.4.5, and before 5.2.1 in the 5.x series, do not verify that their arguments correspo
28RISK
open
ReferênciaVexDay Proof
PHP < 4.4.5/5.2.1 - 'shmop' SSL RSA Private-Key Disclosure
CVE-2007-1376locallinux
The shmop functions in PHP before 4.4.5, and before 5.2.1 in the 5.x series, do not verify that their arguments correspo
28RISK
open
Referência
CVE-2018-12525
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /images/ pr
23RISK
open
Referência
CVE-2011-4572
Cross-site scripting (XSS) vulnerability in inc/tesmodrewite.php in CF Image Hosting Script 1.3.82, 1.4.1, and probably
23RISK
open
Referência
CVE-2011-4800
Directory traversal vulnerability in Serv-U FTP Server before 11.1.0.5 allows remote authenticated users to read and wri
23RISK
open
Referência
CVE-2011-4812
Cross-site scripting (XSS) vulnerability in nowosci.php in BestShopPro allows remote attackers to inject arbitrary web s
23RISK
open
Referência
CVE-2026-15622
poco-ai poco-claw Workspace API workspace.py get_workspace_file authorization
33RISK
open
ReferênciaVexDay Proof
PHP < 4.4.5/5.2.1 - PHP_binary Session Deserialization Information Leak
CVE-2007-1380localmultiple
The php_binary serialization handler in the session extension in PHP before 4.4.5, and 5.x before 5.2.1, allows context-
23RISK
open
Referência
CVE-2026-12081
Database for Contact Form 7, WPforms, Elementor forms < 1.5.2 - Unauthenticated PHP Object Injection via Entry File Field
33RISK
open
Referência
CVE-2026-11964
User Registration & Membership < 5.2.2 - Unauthenticated PayPal Webhook Signature Verification Bypass Leading to Membership Activation
48RISK
open
Referência
CVE-2018-12584
The ConnectionBase::preparseNewBytes function in resip/stack/ConnectionBase.cxx in reSIProcate through 1.10.2 allows rem
28RISK
open
Referência
CVE-2018-12584
The ConnectionBase::preparseNewBytes function in resip/stack/ConnectionBase.cxx in reSIProcate through 1.10.2 allows rem
28RISK
open
Referência
CVE-2018-12604
GreenCMS 2.3.0603 allows remote attackers to obtain sensitive information via a direct request for Data/Log/year_month_d
28RISK
open
Referência
CVE-2018-12613
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RISK
open
Referência
CVE-2018-12613
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RISK
open
Referência
CVE-2018-12613
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RISK
open
Referência
CVE-2011-5200
Multiple SQL injection vulnerabilities in DeDeCMS, possibly 5.6, allow remote attackers to execute arbitrary SQL command
23RISK
open
Referência
CVE-2011-5230
Multiple SQL injection vulnerabilities in the selectUserIdByLoginPass function in seotoaster_core/application/models/Log
23RISK
open
previouspage 446 / 743next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.