Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,302cataloged exploits
35,469CVEs with public exploitation
24,695lab-tested
22,301 exploits
Referência
CVE-2026-7152
Totolink A8000RU CGI cstecgi.cgi setTelnetCfg os command injection
48RISK
open
Referência
CVE-2026-7151
Tenda HG3 formIPv6Routing formUploadConfig stack-based overflow
41RISK
open
Referência
CVE-2026-7150
dh1011 auto-favicon MCP Tool server.py generate_favicon_from_url server-side request forgery
33RISK
open
Referência
CVE-2026-7149
dexhunter kaggle-mcp server.py prepare_kaggle_dataset path traversal
33RISK
open
Referência
CVE-2026-7148
CodeAstro Online Classroom addnewfaculty sql injection
33RISK
open
Referência
CVE-2026-7147
JoeCastrom mcp-chat-studio LLM Models API llm.js server-side request forgery
33RISK
open
Referência
CVE-2019-1003001
A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.61 and earlier in src/main/java/org/jenkinsci/plugins
60RISK
open
Referência
CVE-2019-12181
A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux.
50RISK
open
Referência
CVE-2019-12372
Petraware pTransformer ADC before 2.1.7.22827 allows SQL Injection via the User ID parameter to the login form.
23RISK
open
Referência
CVE-2019-12477
Supra Smart Cloud TV allows remote file inclusion in the openLiveURL function, which allows a local attacker to broadcas
43RISK
open
Referência
CVE-2019-12725
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RISK
open
Referência
CVE-2014-2008
SQL injection vulnerability in confirm.php in the mPAY24 payment module before 1.6 for PrestaShop allows remote attacker
23RISK
open
Referência
CVE-2014-2008
SQL injection vulnerability in confirm.php in the mPAY24 payment module before 1.6 for PrestaShop allows remote attacker
23RISK
open
Referência
CVE-2026-34101
Guardian Language-System Unauthenticated SQL Injection via id Parameter in text_file.php
48RISK
open
ReferênciaVexDay Proof
Atom Photoblog 1.1.5b1 - 'photoId' SQL Injection
CVE-2008-3351webappsphp
SQL injection vulnerability in atomPhotoBlog.php in Atom PhotoBlog 1.0.9.1 and 1.1.5b1 allows remote attackers to execut
23RISK
open
ReferênciaVexDay Proof
Webmin 1.910 - 'Package Updates' Remote Command Execution (Metasploit)
CVE-2019-12840remotelinux
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root pr
60RISK
open
Referência
phpMyAdmin 4.9.0.1 - Cross-Site Request Forgery
CVE-2019-12922webappsphp
A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in the Setup page.
28RISK
open
Referência
CVE-2019-13235
In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the Login form.
23RISK
open
Referência
CVE-2014-2299
Buffer overflow in the mpeg_read function in wiretap/mpeg.c in the MPEG parser in Wireshark 1.8.x before 1.8.13 and 1.10
50RISK
open
Referência
CVE-2014-2303
Multiple SQL injection vulnerabilities in the file browser component (we_fs.php) in webEdition CMS before 6.2.7-s1.2 and
23RISK
open
Referência
CVE-2014-2364
Advantech WebAccess Stack-Based Buffer Overflow
68RISK
open
Referência
CVE-2014-2399
Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 2.2.2 allows remote attacker
23RISK
open
Referência
CVE-2025-71326
AVAST Antivirus 25.11 Unquoted Service Path Privilege Escalation
41RISK
open
ReferênciaVexDay Proof
F-PROT AntiVirus 6.2.1.4252 - Malformed Archive Infinite Loop Denial of Service
CVE-2008-3447dosmultiple
The scanning engine in F-Prot Antivirus 6.2.1 4252 allows remote attackers to cause a denial of service (infinite loop)
23RISK
open
Referência
CVE-2014-2424
Unspecified vulnerability in the Oracle Event Processing component in Oracle Fusion Middleware 11.1.1.7.0 allows remote
50RISK
open
ReferênciaVexDay Proof
eNdonesia 8.4 (Calendar Module) - SQL Injection
CVE-2008-3452webappsphp
SQL injection vulnerability in the Calendar module in eNdonesia 8.4 allows remote attackers to execute arbitrary SQL com
23RISK
open
Referência
CVE-2019-13272
CVE-2019-13272HIGHunder attack
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISK
open
Referência
CVE-2019-13272
CVE-2019-13272HIGHunder attack
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISK
open
ReferênciaVexDay Proof
PHP Hosting Directory 2.0 - Insecure Cookie Handling
CVE-2008-3454webappsphp
JnSHosts PHP Hosting Directory 2.0 allows remote attackers to bypass authentication and gain administrative access by se
23RISK
open
Referência
CVE-2019-13272
CVE-2019-13272HIGHunder attack
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISK
open
previouspage 467 / 744next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.