Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,302cataloged exploits
35,469CVEs with public exploitation
24,695lab-tested
22,301 exploits
Referência
CVE-2018-19862
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP POST re
28RISK
open
Referência
CVE-2018-20062
CVE-2018-20062CRITICALunder attack
An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP
100RISK
open
Referência
CVE-2017-0144
CVE-2017-0144HIGHunder attackransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Referência
Inosoft VisiWin 7 2022-2.1 - Insecure Folders Permissions
CVE-2023-31468HIGHlocalwindows
An issue was discovered in Inosoft VisiWin 7 through 2022-2.1 (Runtime RT7.3 RC3 20221209.5). The "%PROGRAMFILES(X86)%\I
41RISK
open
Referência
CVE-2023-31747
Wondershare Filmora 12 (Build 12.2.1.2088) was discovered to contain an unquoted service path vulnerability via the comp
41RISK
open
Referência
CVE-2017-8601
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to execute
35RISK
open
ReferênciaVexDay Proof
Student Study Center Management System v1.0 - Stored Cross-Site Scripting (XSS)
CVE-2023-33580webappsphp
Phpgurukul Student Study Center Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in the "Admin Name" f
23RISK
open
Referência
Thruk Monitoring Web Interface 3.06 - Path Traversal
CVE-2023-34096MEDIUMwebappsperl
Thruk has Path Traversal Vulnerability in panorama.pm
45RISK
open
ReferênciaVexDay Proof
Service Provider Management System v1.0 - SQL Injection
CVE-2023-34581webappsphp
Sourcecodester Service Provider Management System v1.0 is vulnerable to SQL Injection via the ID parameter in /php-spms/
23RISK
open
Referência
CVE-2023-33592
Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lf
23RISK
open
Referência
CVE-2023-34581
Sourcecodester Service Provider Management System v1.0 is vulnerable to SQL Injection via the ID parameter in /php-spms/
23RISK
open
Referência
CVE-2023-3460
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RISK
open
Referência
CVE-2023-3845
mooSocial mooDating URL ajax_invite cross site scripting
43RISK
open
Referência
CVE-2003-0727
Multiple buffer overflows in the XML Database (XDB) functionality for Oracle 9i Database Release 2 allow local users to
50RISK
open
ReferênciaVexDay Proof
ashNews 0.83 - 'pathtoashnews' Remote File Inclusion
CVE-2003-1292webappsphp
PHP remote file include vulnerability in Derek Ashauer ashNews 0.83 allows remote attackers to include and execute arbit
23RISK
open
ReferênciaVexDay Proof
Eznet 3.5.0 - Remote Stack Overflow / Denial of Service
CVE-2003-1339remotewindows
Stack-based buffer overflow in eZnet.exe, as used in eZ (a) eZphotoshare, (b) eZmeeting, (c) eZnetwork, and (d) eZshare
35RISK
open
Referência
CVE-2026-19384
SourceCodester Simple Doctors Appointment System ajax.php set_appointment sql injection
33RISK
open
Referência
CVE-2024-57708
An issue in OneTrust SDK v.6.33.0 allows a local attacker to cause a denial of service via the Object.setPrototypeOf, __
33RISK
open
Referência
CVE-2026-67620 - Flowise SSRF via incomplete cloud-metadata deny-list (Oracle OCI 192.0.0.192 + Alibaba 100.100.100.200 bypass the DEFAULT_DENY_LIST)
Flowise 3.1.4 SSRF via fetch-links Endpoint Incomplete Deny-List
33RISK
open
Referência
CVE-2026-19268
abdullah1854 MCPGateway Claude Usage Range Endpoint claude-usage.ts getUsageByDateRange command injection
33RISK
open
Referência
CVE-2026-16955
AI Engine < 3.6.6 - Subscriber+ Arbitrary File Read via Audio Transcription
33RISK
open
Referência
CVE-2026-16953
AI Engine < 3.6.4 - Unauthenticated Cross-Session Chatbot File Deletion via Forgeable Session Cookie
33RISK
open
Referência
CVE-2026-16948
Solace Extra < 1.6.1 - Subscriber+ Multiple Missing Authorization via Site-Wide Nonce Exposure
41RISK
open
Referência
CVE-2026-16608
Download Monitor < 5.2.6 - Unauthenticated Download Log Injection
33RISK
open
Referência
CVE-2026-16595
WP Directory Kit < 1.5.5 - Subscriber+ User and Unpublished Listing Disclosure
33RISK
open
Referência
CVE-2026-16594
WP Directory Kit < 1.5.5 - Subscriber+ Plugin Settings and API Key Disclosure
41RISK
open
Referência
CVE-2026-16590
WP Directory Kit < 1.5.5 - Subscriber+ Contact Message and User Data Disclosure
33RISK
open
Referência
CVE-2026-16589
WP Directory Kit < 1.5.5 - Subscriber+ SQL Injection via data_fields_list Parameter
41RISK
open
Referência
CVE-2026-16578
Admin Safety Guard < 1.4.0 - Unauthenticated User Data Disclosure via 2fa/app/users REST Route
41RISK
open
Referência
CVE-2026-16574
Dokan < 5.0.11 - Vendor+ Cross-Vendor Downloadable Product Access Grant via Order Downloads REST Endpoint
33RISK
open
previouspage 469 / 744next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.