Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,401cataloged exploits
35,511CVEs with public exploitation
24,695lab-tested
22,301 exploits
Referência
CVE-2017-20264
Joomla! Component Sponsor Wall 8.0 SQL Injection
41RISK
open
Referência
CVE-2026-10181
TRENDnet TEW-432BRP formSysCmd stack-based overflow
41RISK
open
Referência
CVE-2026-10175
Aider-AI Aider Architect Mode auth.py editor_coder.run code injection
33RISK
open
Referência
CVE-2026-10174
Aider-AI Aider Pre-commit Hook args.py protection mechanism
33RISK
open
Referência
CVE-2026-10173
Orthanc Explorer 2 URL StudyList.vue cross site scripting
33RISK
open
Referência
CVE-2026-10172
Bdtask Multi-Store Inventory Management System Component Module.php upload unrestricted upload
33RISK
open
Referência
CVE-2019-0541
CVE-2019-0541HIGHunder attack
A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML E
83RISK
open
Referência
CVE-2026-9562
sambitraj STUDENT-MANAGEMENT-SYSTEM Dashboard access control
33RISK
open
Referência
CVE-2026-11312
bytedance InfiniStore KV Map infinistore.h purge_kv_map algorithmic complexity
33RISK
open
Referência
CVE-2026-10878
D-Link DWR-M920 formSmsManage sub_41C8E8 command injection
33RISK
open
Referência
CVE-2026-9544
Shenzhen Sixun Software Sixun Shanghui Group Business Management System PayConfig sql injection
33RISK
open
Referência
CVE-2026-9543
Totolink N300RH Web Management cstecgi.cgi setPasswordCfg os command injection
48RISK
open
Referência
CVE-2026-10783
gradio-app gradio Audio Cache Key save_audio_to_cache weak hash
28RISK
open
Referência
CVE-2026-10722
cilium ebpf LoadCollectionSpec/LoadCollectionSpecFromReader btf.go loadRawSpec integer overflow
33RISK
open
Referência
CVE-2026-10704
SourceCodester Pizzafy E-Commerce System Administrative Control Panel admin_class_novo.php login sql injection
33RISK
open
Referência
CVE-2026-10703
EIPStackGroup OpENer SendRRData cipmessagerouter.c CreateMessageRouterRequestStructure use after free
33RISK
open
Referência
CVE-2026-10692
johnhuang316 code-index-mcp search_code_advanced is_safe_regex_pattern redos
33RISK
open
Referência
CVE-2026-10691
wonderwhy-er DesktopCommanderMCP start_search search-manager.ts redos
33RISK
open
Referência
CVE-2026-10688
ahujasid blender-mcp server.py execute_blender_code code injection
33RISK
open
Referência
CVE-2019-0708
CVE-2019-0708CRITICALunder attackransomware
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
Referência
CVE-2019-0708
CVE-2019-0708CRITICALunder attackransomware
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
Referência
CVE-2019-0708
CVE-2019-0708CRITICALunder attackransomware
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
Referência
CVE-2026-10294
PackageKit API pk-transaction.c g_file_test improper authorization
33RISK
open
Referência
CVE-2026-10287
SourceCodester SEO Meta Tag Extractor index.php get_headers server-side request forgery
33RISK
open
Referência
CVE-2026-10258
itsourcecode Content Management System add_sub_topic.php sql injection
33RISK
open
Referência
CVE-2026-10253
itsourcecode Online House Rental System manage_payment.php sql injection
33RISK
open
Referência
CVE-2026-10251
itsourcecode Online House Rental System ajax.php login sql injection
33RISK
open
Referência
CVE-2026-10250
itsourcecode Online Blood Bank Management System campsdetails.php sql injection
33RISK
open
Referência
CVE-2026-10219
nextlevelbuilder GoClaw write_file Tool fsbridge.go FsBridge.WriteFile os command injection
33RISK
open
Referência
CVE-2026-10218
nextlevelbuilder GoClaw evolution_handlers.go auth improper authorization
33RISK
open
previouspage 484 / 744next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.