Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,302cataloged exploits
35,469CVEs with public exploitation
24,695lab-tested
22,266 exploits
Referência
CVE-2026-5639
PHPGurukul Online Shopping Portal Project Parameter update-image3.php sql injection
33RISK
open
Referência
CVE-2026-5638
HerikLyma CPPWebFramework path traversal
33RISK
open
Referência
CVE-2026-14733
SourceCodester Class and Exam Timetabling System edit_coursea.php sql injection
33RISK
open
Referência
CVE-2018-18322
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Command Injection via shell metacharacters in the admin/ind
28RISK
open
Referência
CVE-2018-18325
CVE-2018-18325HIGHunder attack
DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue ex
100RISK
open
Referência
CVE-2018-18326
DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expect
50RISK
open
Referência
CVE-2018-18416
LANGO Codeigniter Multilingual Script 1.0 has XSS in the input and upload sections, as demonstrated by the site_name par
23RISK
open
Referência
CVE-2018-18416
LANGO Codeigniter Multilingual Script 1.0 has XSS in the input and upload sections, as demonstrated by the site_name par
23RISK
open
Referência
CVE-2018-18417
In the 3.1 version of Ekushey Project Manager CRM, Stored XSS has been discovered in the input and upload sections, as d
23RISK
open
Referência
CVE-2026-5044
Belkin F9K1122 Setting formSetSystemSettings stack-based overflow
41RISK
open
Referência
CVE-2026-5043
Belkin F9K1122 Parameter formSetPassword stack-based overflow
41RISK
open
Referência
CVE-2026-5042
Belkin F9K1122 Parameter formCrossBandSwitch stack-based overflow
41RISK
open
Referência
CVE-2026-5041
code-projects Chamber of Commerce Membership Management System pageMail.php fwrite command injection
33RISK
open
Referência
CVE-2026-5037
mxml mxmlIndexNew mxml-index.c index_sort stack-based overflow
33RISK
open
Referência
CVE-2026-5036
Tenda 4G06 Endpoint DhcpListClient fromDhcpListClient stack-based overflow
41RISK
open
Referência
CVE-2026-5035
code-projects Accounting System Parameter view_work.php sql injection
33RISK
open
Referência
CVE-2026-5034
code-projects Accounting System Parameter edit_costumer.php sql injection
33RISK
open
Referência
CVE-2026-5033
code-projects Accounting System Parameter view_costumer.php sql injection
33RISK
open
Referência
CVE-2026-5031
BichitroGan ISP Billing Software Endpoint users-view resource injection
33RISK
open
Referência
CVE-2026-5030
Totolink NR1800X Telnet Service cstecgi.cgi NTPSyncWithHost command injection
33RISK
open
Referência
CVE-2026-5024
D-Link DIR-513 formSetEmail stack-based overflow
41RISK
open
Referência
CVE-2026-5023
DeDeveloper23 codebase-mcp RepoMix codebase.ts saveCodebase os command injection
33RISK
open
Referência
CVE-2026-5021
Tenda F453 httpd PPTPUserSetting fromPPTPUserSetting stack-based overflow
41RISK
open
Referência
CVE-2026-5020
Totolink A3600R Parameter cstecgi.cgi setNoticeCfg command injection
33RISK
open
Referência
CVE-2026-5019
code-projects Simple Food Order System Parameter all-orders.php sql injection
33RISK
open
Referência
CVE-2026-5018
code-projects Simple Food Order System Parameter register-router.php sql injection
33RISK
open
Referência
CVE-2026-5017
code-projects Simple Food Order System Parameter all-tickets.php sql injection
33RISK
open
Referência
CVE-2026-5016
elecV2 elecV2P URL mock eAxios server-side request forgery
33RISK
open
Referência
CVE-2026-5015
elecV2 elecV2P Endpoint logs cross site scripting
33RISK
open
Referência
CVE-2026-5014
elecV2 elecV2P Wildcard log path.join path traversal
33RISK
open
previouspage 457 / 743next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.