Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,302cataloged exploits
35,469CVEs with public exploitation
24,695lab-tested
22,301 exploits
Referência
CVE-2026-13578
itsourcecode Hospital Management System patientdetail.php sql injection
33RISK
open
Referência
CVE-2026-13574
llvm llvm-project Bitcode File IntrinsicInst.cpp getBasePtr heap-based overflow
33RISK
open
Referência
CVE-2026-13569
weng-xianhu EyouCMS API index.php sql injection
33RISK
open
ReferênciaVexDay Proof
Openfire Server 3.6.0a - Authentication Bypass / SQL Injection / Cross-Site Scripting
CVE-2008-6508webappsjsp
Directory traversal vulnerability in the AuthCheck filter in the Admin Console in Openfire 3.6.0a and earlier allows rem
60RISK
open
ReferênciaVexDay Proof
Openfire Server 3.6.0a - Authentication Bypass / SQL Injection / Cross-Site Scripting
CVE-2008-6511webappsjsp
Open redirect vulnerability in login.jsp in Openfire 3.6.0a and earlier allows remote attackers to redirect users to arb
23RISK
open
Referência
Booked Scheduler 2.7.5 - Remote Command Execution (Metasploit)
CVE-2019-9581webappsphp
phpscheduleit Booked Scheduler 2.7.5 allows arbitrary file upload via the Favicon field, leading to execution of arbitra
28RISK
open
Referência
AirDroid 4.2.1.6 - Denial of Service
CVE-2019-9599dosandroid
The AirDroid application through 4.2.1.6 for Android allows remote attackers to cause a denial of service (service crash
28RISK
open
Referência
CVE-2026-10263
SourceCodester Computer Repair Shop Management System manage_product.php sql injection
33RISK
open
Referência
CVE-2026-10245
SourceCodester Pharmacy Sales and Inventory System main create_supplier cross site scripting
33RISK
open
Referência
CVE-2026-10244
SourceCodester Pharmacy Sales and Inventory System main create_medicine_name cross site scripting
33RISK
open
Referência
CVE-2026-10243
code-projects Smart Parking System Admin Endpoint missing authentication
33RISK
open
Referência
CVE-2026-9456
Totolink A8000RU Web Management cstecgi.cgi setOpenVpnCfg os command injection
48RISK
open
Referência
CVE-2026-9455
Totolink A8000RU Web Management cstecgi.cgi UploadOpenVpnCert os command injection
48RISK
open
Referência
CVE-2026-9454
Totolink A8000RU Web Management cstecgi.cgi setOpenVpnCertGenerationCfg os command injection
48RISK
open
Referência
CVE-2026-9452
FoundDream miniclawd exec.ts ExecTool.execute os command injection
33RISK
open
Referência
CVE-2011-5139
SQL injection vulnerability in page.php in Pre Studio Business Cards Designer allows remote attackers to execute arbitra
23RISK
open
Referência
CVE-2011-5139
SQL injection vulnerability in page.php in Pre Studio Business Cards Designer allows remote attackers to execute arbitra
23RISK
open
Referência
CVE-2011-5161
Unrestricted file upload vulnerability in the patient photograph functionality in OpenEMR 4 allows remote attackers to e
23RISK
open
Referência
CVE-2011-5165
Stack-based buffer overflow in Free MP3 CD Ripper 1.1, 2.6 and earlier, when converting a file, allows user-assisted rem
50RISK
open
Referência
CVE-2011-5165
Stack-based buffer overflow in Free MP3 CD Ripper 1.1, 2.6 and earlier, when converting a file, allows user-assisted rem
50RISK
open
Referência
CVE-2018-25326
Google Drive for WordPress 2.2 Path Traversal RCE via gdrive-ajaxs.php
41RISK
open
Referência
CVE-2018-25325
Woocommerce CSV Importer 3.3.6 Path Traversal File Deletion
41RISK
open
Referência
CVE-2018-25322
Allok Fast AVI MPEG Splitter 1.2 Stack Based Buffer Overflow
41RISK
open
Referência
CVE-2018-25321
TP-Link TL-WR720N CSRF via Administrative Interfaces (firmware V1_130719)
33RISK
open
Referência
CVE-2018-25320
ACL Analytics 11.x - 13.0.0.579 Arbitrary Code Execution
48RISK
open
Referência
CVE-2018-25319
Redaxo CMS Addon MyEvents 2.2.1 SQL Injection via event_add.php
41RISK
open
Referência
CVE-2026-8753
kalcaddle Kodbox fileThumb Plugin VideoResize.class.php parseVideoInfo command injection
33RISK
open
Referência
CVE-2026-8752
h2oai h2o-3 Rapids setproperty Primitive AstSetProperty.java exec access control
33RISK
open
Referência
CVE-2026-8751
h2oai h2o-3 JAR Model.java importBinaryModel deserialization
33RISK
open
Referência
CVE-2026-8750
h2oai h2o-3 ImportFile API PersistNFS.java importFiles information disclosure
33RISK
open
previouspage 468 / 744next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.