Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,302cataloged exploits
35,469CVEs with public exploitation
24,695lab-tested
22,266 exploits
Referência
CVE-2012-5898
Cross-site request forgery (CSRF) vulnerability in SAMEDIA LandShop 0.9.2 allows remote attackers to hijack the authenti
23RISK
open
Referência
CVE-2018-5983
SQL Injection exists in the JquickContact 1.3.2.2.1 component for Joomla! via a task=refresh&sid= request.
23RISK
open
Referência
CVE-2018-5984
SQL Injection exists in the Tumder (An Arcade Games Platform) 2.1 component for Joomla! via the PATH_INFO to the categor
23RISK
open
Referência
CVE-2026-8033
PicoTronica e-Clinic Healthcare System ECHS Response Header v2 information disclosure
33RISK
open
Referência
CVE-2026-8032
PicoTronica e-Clinic Healthcare System ECHS echs.js hard-coded credentials
33RISK
open
Referência
CVE-2023-54349
AmazCart CMS 3.4 Reflected Cross-Site Scripting via Search
33RISK
open
Referência
CVE-2023-54348
ERPGo SaaS 3.9 CSV Injection via Vendor Creation
41RISK
open
Referência
CVE-2012-6555
Cross-site scripting (XSS) vulnerability in the LatestComment plugin 1.1 for Vanilla Forums allows remote attackers to i
23RISK
open
Referência
CVE-2012-6559
Multiple cross-site scripting (XSS) vulnerabilities in FreeNAC 3.02 allow remote attackers to inject arbitrary web scrip
23RISK
open
ReferênciaVexDay Proof
nuseo PHP enterprise 1.6 - Remote File Inclusion
CVE-2007-5409webappsphp
PHP remote file inclusion vulnerability in admin/nuseo_admin_d.php in NuSEO PHP Enterprise 1.6 (NuSEO.PHP), when registe
23RISK
open
Referência
CVE-2018-6367
SQL Injection exists in Vastal I-Tech Buddy Zone Facebook Clone 2.9.9 via the /chat_im/chat_window.php request_id parame
23RISK
open
Referência
CVE-2018-6368
SQL Injection exists in the JomEstate PRO through 3.7 component for Joomla! via the id parameter in a task=detailed acti
23RISK
open
Referência
CVE-2018-6370
SQL Injection exists in the NeoRecruit 4.1 component for Joomla! via the (1) PATH_INFO or (2) name of a .html file under
23RISK
open
Referência
CVE-2012-6560
SQL injection vulnerability in deviceadd.php in FreeNAC 3.02 allows remote attackers to execute arbitrary SQL commands v
23RISK
open
Referência
CVE-2012-6568
Buffer overflow in the back-end component in Huawei UTPS 1.0 allows local users to gain privileges via a long IDS_PLUGIN
23RISK
open
Referência
CVE-2012-6584
Multiple SQL injection vulnerabilities in MYRE Realty Manager allow remote attackers to execute arbitrary SQL commands v
23RISK
open
Referência
CVE-2012-6586
Multiple SQL injection vulnerabilities in MYRE Vacation Rental Software allow remote attackers to execute arbitrary SQL
23RISK
open
Referência
CVE-2015-1478
Cross-site scripting (XSS) vulnerability in the CMSJunkie J-ClassifiedsManager component for Joomla! allows remote attac
23RISK
open
Referência
CVE-2012-6587
Cross-site scripting (XSS) vulnerability in vacation/1_mobile/alert_members.php in MYRE Vacation Rental Software allows
23RISK
open
Referência
CVE-2012-6608
Cross-site scripting (XSS) vulnerability in xmlservices/E_book.php in Elastix 2.3.0 allows remote attackers to inject ar
23RISK
open
Referência
CVE-2018-6398
SQL Injection exists in the CP Event Calendar 3.0.1 component for Joomla! via the id parameter in a task=load action.
23RISK
open
Referência
CVE-2018-6481
A buffer overflow vulnerability in the control protocol of Disk Savvy Enterprise v10.4.18 allows remote attackers to exe
28RISK
open
Referência
CVE-2018-6481
A buffer overflow vulnerability in the control protocol of Disk Savvy Enterprise v10.4.18 allows remote attackers to exe
28RISK
open
Referência
CVE-2026-6981
IhateCreatingUserNames2 AiraHub2 Endpoint AiraHub.py sync_agents server-side request forgery
33RISK
open
Referência
CVE-2026-6980
Divyanshu-hash GitPilot-MCP main.py repo_path command injection
33RISK
open
Referência
CVE-2026-6979
devlikeapro WAHA API Request media.controller.ts server-side request forgery
33RISK
open
Referência
CVE-2026-6978
JiZhiCMS addcache.html htmlspecialchars_decode sql injection
33RISK
open
Referência
CVE-2026-6977
vanna-ai vanna Legacy Flask API improper authorization
33RISK
open
Referência
CVE-2026-41473
CyberPanel < 2.4.5 Unauthenticated API Access via AI Scanner Endpoints
41RISK
open
Referência
CVE-2026-41472
CyberPanel < 2.4.5 Stored XSS via AI Scanner Dashboard
33RISK
open
previouspage 465 / 743next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.