Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,401cataloged exploits
35,511CVEs with public exploitation
24,695lab-tested
22,301 exploits
Referência
CVE-2026-14738
exo-explore exo Vision Feature Cache vision.py _image_cache_key weak hash
33RISK
open
Referência
CVE-2026-14737
Hanwang e-Face General Management Platform querySysAuthStr.do sql injection
33RISK
open
Referência
CVE-2026-14736
Ruijie RG-UAC user_auth_commit.php unrestricted upload
33RISK
open
Referência
CVE-2026-14731
itsourcecode Hospital Management System patientreport.php sql injection
33RISK
open
Referência
CVE-2026-14730
itsourcecode Hospital Management System patientprofile.php sql injection
33RISK
open
Referência
CVE-2026-14722
tiddly-gittly TidGi-Desktop Git Repository Import loadWikiTiddlersWithSubWikis.ts code injection
33RISK
open
Referência
CVE-2026-14635
kirilkirkov Ecommerce-CodeIgniter-Bootstrap Vendor Multi-Image Endpoint AddProduct.php path traversal
33RISK
open
Referência
CVE-2026-14634
kirilkirkov Ecommerce-CodeIgniter-Bootstrap Subscribed Emails Admin MY_Controller.php checkForPostRequests cross site scripting
33RISK
open
Referência
CVE-2026-14629
RT-Thread Parameter lwp_syscall.c sys_ioctl divide by zero
33RISK
open
Referência
CVE-2026-14628
NousResearch hermes-agent Live Webhook Endpoint base.py extract_media path traversal
33RISK
open
Referência
CVE-2026-14627
NousResearch hermes-agent Discord Platform Integration discord.py DiscordAdapter._is_allowed_user improper authentication
33RISK
open
Referência
CVE-2026-12196
HestiaCP Admin Takeover
41RISK
open
Referência
CVE-2026-14626
NousResearch hermes-agent HTTP API run_agent.py AIAgent.run_conversation denial of service
33RISK
open
Referência
CVE-2023-31748
Insecure permissions in MobileTrans v4.0.11 allows attackers to escalate privileges to local admin via replacing the exe
41RISK
open
Referência
CVE-2023-3184
SourceCodester Sales Tracker Management System cross site scripting
28RISK
open
Referência
CVE-2023-3187
PHPGurukul Teachers Record Management System Profile Picture changeimage.php unrestricted upload
33RISK
open
Referência
CVE-2023-31873
Gin 0.7.4 allows execution of arbitrary code when a crafted file is opened, e.g., via require('child_process').
41RISK
open
Referência
CVE-2023-33580
Phpgurukul Student Study Center Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in the "Admin Name" f
23RISK
open
Referência
CVE-2017-8601
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to execute
35RISK
open
ReferênciaVexDay Proof
Student Study Center Management System v1.0 - Stored Cross-Site Scripting (XSS)
CVE-2023-33580webappsphp
Phpgurukul Student Study Center Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in the "Admin Name" f
23RISK
open
Referência
Thruk Monitoring Web Interface 3.06 - Path Traversal
CVE-2023-34096MEDIUMwebappsperl
Thruk has Path Traversal Vulnerability in panorama.pm
45RISK
open
ReferênciaVexDay Proof
Service Provider Management System v1.0 - SQL Injection
CVE-2023-34581webappsphp
Sourcecodester Service Provider Management System v1.0 is vulnerable to SQL Injection via the ID parameter in /php-spms/
23RISK
open
Referência
CVE-2023-33592
Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lf
23RISK
open
Referência
CVE-2023-34581
Sourcecodester Service Provider Management System v1.0 is vulnerable to SQL Injection via the ID parameter in /php-spms/
23RISK
open
Referência
CVE-2023-3460
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RISK
open
Referência
CVE-2018-17383
SQL Injection exists in the Collection Factory 4.1.9 component for Joomla! via the filter_order or filter_order_Dir para
23RISK
open
Referência
CVE-2002-1230
NetDDE Agent on Windows NT 4.0, 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute
23RISK
open
Referência
CVE-2023-37979
WordPress Ninja Forms Plugin <= 3.6.25 is vulnerable to Cross Site Scripting (XSS)
56RISK
open
Referência
CVE-2023-3845
mooSocial mooDating URL ajax_invite cross site scripting
43RISK
open
Referência
Campcodes Online Matrimonial Website System v3.3 - Code Execution via malicious SVG file upload
CVE-2023-39115webappsphp
install/aiz-uploader/upload in Campcodes Online Matrimonial Website System Script 3.3 allows XSS via a crafted SVG docum
23RISK
open
previouspage 486 / 744next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.