Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,401cataloged exploits
35,511CVEs with public exploitation
24,695lab-tested
22,332 exploits
Referência
CVE-2011-5173
Buffer overflow in Bugbear Entertainment FlatOut 2005 allows user-assisted remote attackers to cause a denial of service
23RISK
open
Referência
CVE-2026-19899
SourceCodester Class and Exam Timetabling System edit_teacher.php sql injection
30RISK
open
ReferênciaVexDay Proof
CodeAvalanche Directory - Database Disclosure
CVE-2008-5898webappsasp
CodeAvalanche Directory stores sensitive information under the web root with insufficient access control, which allows r
23RISK
open
ReferênciaVexDay Proof
CodeAvalanche FreeForAll - Database Disclosure
CVE-2008-5899webappsasp
CodeAvalanche FreeForAll stores sensitive information under the web root with insufficient access control, which allows
23RISK
open
ReferênciaVexDay Proof
CodeAvalanche Articles - Database Disclosure
CVE-2008-5900webappsasp
CodeAvalanche Articles stores sensitive information under the web root with insufficient access control, which allows re
23RISK
open
Referência
CVE-2022-43769
CVE-2022-43769HIGHunder attack
Hitachi Vantara Pentaho Business Analytics Server - Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)
100RISK
open
ReferênciaVexDay Proof
Active Test 2.1 - Authentication Bypass
CVE-2008-5959webappsasp
Multiple SQL injection vulnerabilities in start.asp in Active Test 2.1 allow remote attackers to execute arbitrary SQL c
23RISK
open
Referência
CVE-2026-18216
Backup Migration < 2.1.7 - Admin+ Privilege Escalation via Post-Restore Auto-Login
23RISK
open
Referência
CVE-2026-16611
Product Feed PRO for WooCommerce < 13.5.7 - Unauthenticated Feed Configuration Disclosure
23RISK
open
ReferênciaVexDay Proof
Gravity GTD 0.4.5 - Local File Inclusion / Remote Code Execution
CVE-2008-5962webappsphp
Directory traversal vulnerability in library/setup/rpc.php in Gravity Getting Things Done (GTD) 0.4.5 and earlier allows
23RISK
open
Referência
CVE-2026-16541
Simply Schedule Appointments < 1.6.12.17 - Team Member+ User Email Disclosure via Users and Customers REST Endpoints
23RISK
open
Referência
CVE-2026-14230
ECS < 4.3.8 - Contributor+ Stored XSS via Dynamic Repeater Bindings
23RISK
open
Referência
EasyNas 1.1.0 - OS Command Injection
CVE-2023-0830MEDIUMremotehardware
EasyNAS backup.pl system os command injection
38RISK
open
Referência
CVE-2019-18818
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RISK
open
ReferênciaVexDay Proof
LokiCMS 0.3.4 - 'index.php' Arbitrary Check File
CVE-2008-5965webappsphp
Directory traversal vulnerability in index.php in LokiCMS 0.3.4 and earlier, when magic_quotes_gpc is disabled, allows r
23RISK
open
Referência
CVE-2023-0902
SourceCodester Simple Food Ordering System process_order.php cross site scripting
28RISK
open
Referência
CVE-2025-61884
CVE-2025-61884HIGHunder attackransomware
Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions
100RISK
open
Referência
CVE-2026-14229
ECS < 4.3.8 - Unauthenticated Private Content Disclosure via ecsload
23RISK
open
Referência
CVE-2026-16007
Authenticated SQL Injection in AppFlowy
41RISK
open
ReferênciaVexDay Proof
PHP iCalendar 2.24 - 'cookie_language' Local File Inclusion / Arbitrary File Upload
CVE-2008-5967webappsphp
admin/index.php in PHP iCalendar 2.3.4, 2.24, and earlier does not require administrative authentication for an addupdat
23RISK
open
ReferênciaVexDay Proof
Ocean12 Mailing List Manager Gold - File Disclosure / SQL Injection / Cross-Site Scripting
CVE-2008-5978webappsphp
Multiple SQL injection vulnerabilities in Ocean12 Mailing List Manager Gold allow remote attackers to execute arbitrary
23RISK
open
Referência
CVE-2023-0912
SourceCodester Auto Dealer Management System sql injection
33RISK
open
ReferênciaVexDay Proof
Jetik Emlak ESA 2.0 - Multiple SQL Injections
CVE-2008-5992webappsphp
Multiple SQL injection vulnerabilities in Jetik Emlak Sistem A (ESA) 2.0 allow remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
I-Rater Basic - SQL Injection
CVE-2008-6017webappsphp
SQL injection vulnerability in messages.php in I-Rater Basic allows remote attackers to execute arbitrary SQL commands v
23RISK
open
Referência
CVE-2019-0230
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lea
60RISK
open
Referência
CVE-2019-0230
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lea
60RISK
open
Referência
CVE-2026-19812
TOTOLINK A800R product.so cstecgi.cgi UploadCustomModule stack-based overflow
41RISK
open
ReferênciaVexDay Proof
Uploader & Downloader 3.0 - 'id_user' SQL Injection
CVE-2006-6716webappsphp
SQL injection vulnerability in administration/administre2.php in Eric GUILLAUME uploader&downloader 3 allows remote atta
23RISK
open
Referência
CVE-2026-19811
TOTOLINK A800R firewall.so cstecgi.cgi setIpQosRules stack-based overflow
41RISK
open
Referência
CVE-2026-18039
Essential Addons for Elementor < 6.7.2 - Unauthenticated Privilege Escalation via Custom Profile Field Mass Assignment
41RISK
open
previouspage 497 / 745next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.