Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,302cataloged exploits
35,469CVEs with public exploitation
24,695lab-tested
22,301 exploits
Referência
CVE-2018-16763
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISK
open
Referência
CVE-2024-6039
Feng Office Workspaces sql injection
33RISK
open
Referência
CVE-2018-17310
On the RICOH MP C1803 JPN printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of add
23RISK
open
Referência
CVE-2018-17313
On the RICOH MP C307 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding a
23RISK
open
Referência
CVE-2018-17313
On the RICOH MP C307 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding a
23RISK
open
Referência
CVE-2004-2502
im-switch before 11.4-46.1 in Fedora Core 2 allows local users to overwrite arbitrary files via a symlink attack on the
23RISK
open
Referência
CVE-2024-6244
pz-frontend-manager < 1.0.6 - CSRF change user profile picture
41RISK
open
Referência
CVE-2024-6387
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
Referência
CVE-2018-18803
Curriculum Evaluation System 1.0 allows SQL Injection via the login screen, related to frmCourse.vb and includes/user.vb
23RISK
open
Referência
CVE-2018-19113
The Pronestor PNHM (aka Health Monitoring or HealthMonitor) add-in before 8.1.13.0 for Outlook has "BUILTIN\Users:(I)(F)
23RISK
open
Referência
CVE-2018-19246
PHP-Proxy 5.1.0 allows remote attackers to read local files if the default "pre-installed version" (intended for users w
28RISK
open
Referência
CVE-2018-19276
OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated use
85RISK
open
Referência
CVE-2018-19276
OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated use
85RISK
open
Referência
CVE-2018-19518
University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh c
60RISK
open
Referência
Windows 10.0.17763.7009 - spoofing vulnerability
CVE-2025-24054MEDIUMunder attackremotewindows
NTLM Hash Disclosure Spoofing Vulnerability
75RISK
open
Referência
windows 10/11 - NTLM Hash Disclosure Spoofing
CVE-2025-24054MEDIUMunder attackremotewindows
NTLM Hash Disclosure Spoofing Vulnerability
75RISK
open
Referência
CVE-2014-8682
Multiple SQL injection vulnerabilities in Gogs (aka Go Git Service) 0.3.1-9 through 0.5.x before 0.5.6.1105 Beta allow r
50RISK
open
Referência
CVE-2026-67201
V 0.5.2 SSRF Bypass via Parser Differential in net.urllib and net.http
41RISK
open
Referência
CVE-2026-67182
Rouille 0.3.3 - 3.6.2 HTTP Request Smuggling via proxy Header Injection
33RISK
open
Referência64
FortiWeb CVE-2025-25257 exploit
CVE-2025-25257CRITICALunder attack
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RISK
open
Referência
CVE-2026-14568
WP User Frontend < 4.3.8 - Unauthenticated Author-less Attachment Deletion
33RISK
open
Referência
CVE-2026-14289
WP FacturaONE < 5.37 - Unauthenticated Remote Code Execution
48RISK
open
Referência
CVE-2026-14236
Contact Form 7 – PayPal & Stripe Add-on < 2.5 - Open Redirect
33RISK
open
Referência
CVE-2026-14235
WordPress Download Manager < 3.3.62 - Unauthorized Protected File Download via Reusable Download Key
41RISK
open
Referência
CVE-2026-14203
Smart Manager < 8.92.0 - Contributor+ Stored XSS via Post Title
33RISK
open
Referência
CVE-2026-14190
Sina Extension for Elementor < 3.10.2 - Reflected XSS
33RISK
open
Referência
CVE-2026-15513
Wavlink WL-NU516U1 adm.cgi wlink_uci_set_value os command injection
33RISK
open
Referência
CVE-2026-15512
pig-mesh Pig pig-codegen GeneratorServiceImpl.java code injection
33RISK
open
Referência
CVE-2026-14778
SourceCodester Onlne Examination & Learning Management System Enrollment Management ajax_enroll.php improper authorization
33RISK
open
Referência
CVE-2025-32432
CVE-2025-32432CRITICALunder attack
Craft CMS Allows Remote Code Execution
100RISK
open
previouspage 473 / 744next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.