Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,444cataloged exploits
35,552CVEs with public exploitation
24,695lab-tested
22,367 exploits
Referência
CVE-2026-7669
sgl-project SGLang HuggingFace Transformer hf_transformers_utils.py get_tokenizer code injection
33RISK
open
Referência
CVE-2026-7668
MikroTik RouterOS SCEP Endpoint scep.p ASN1_STRING_data out-of-bounds
33RISK
open
Referência
CVE-2026-7653
r-huijts mcp-server-rijksmuseum MCP index.ts open_image_in_browser os command injection
33RISK
open
Referência
CVE-2026-56122
Winstone Servlet Engine 0.9.10 Path Traversal via HTTP Request Paths
41RISK
open
Referência
CVE-2026-56121
Feast < 0.63.0 Unauthenticated RCE via ApplyFeatureView gRPC Deserialization
48RISK
open
Referência
CVE-2026-56111
Marlin Firmware 2.1.2.7 Out-of-Bounds Write via M421 G-code Handler
41RISK
open
ReferênciaVexDay Proof
Prozilla Hosting Index - 'id' SQL Injection
CVE-2008-6115webappsphp
SQL injection vulnerability in directory.php in Prozilla Hosting Index allows remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
Joomla! Component Thyme 1.0 - SQL Injection
CVE-2008-6116webappsphp
SQL injection vulnerability in the EXtrovert Software Thyme (com_thyme) 1.0 component for Joomla! allows remote attacker
23RISK
open
ReferênciaVexDay Proof
WebBiscuits Modules Controller 1.1 - Remote File Inclusion / Remote File Disclosure
CVE-2008-6139webappsphp
Directory traversal vulnerability in faqsupport/wce.download.php in WebBiscuits Modules Controller 1.1 allows remote att
23RISK
open
Referência
CVE-2026-7384
ezequiroga mcp-bases research_server.py search_papers path traversal
33RISK
open
ReferênciaVexDay Proof
OwenPoll 1.0 - Insecure Cookie Handling
CVE-2008-6143webappsphp
OwenPoll 1.0 allows remote attackers to bypass authentication and obtain administrative access via a modified account na
23RISK
open
ReferênciaVexDay Proof
Enthrallweb emates 1.0 - 'newsdetail.asp' SQL Injection
CVE-2006-6806webappsasp
SQL injection vulnerability in newsdetail.asp in Enthrallweb eMates 1.0 allows remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
DeluxeBB 1.2 - Blind SQL Injection
CVE-2008-6146webappsphp
SQL injection vulnerability in pm.php in DeluxeBB 1.2 and earlier, when magic_quotes_gpc is disabled, allows remote atta
23RISK
open
ReferênciaVexDay Proof
Ananda Real Estate 3.4 - 'agent' SQL Injection
CVE-2006-6807webappsasp
SQL injection vulnerability in list.asp in Softwebs Nepal (aka Ananda Raj Pandey) Ananda Real Estate 3.4 and earlier all
23RISK
open
Referência
CVE-2026-9815
MagicForm <= 0.1.3 - Unauthenticated Arbitrary File Upload to RCE
33RISK
open
Referência
CVE-2026-55200
libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c
48RISK
open
Referência
CVE-2020-8260
CVE-2020-8260HIGHunder attack
A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform
100RISK
open
Referência
CVE-2020-11651
CVE-2020-11651CRITICALunder attack
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISK
open
Referência
CVE-2020-11651
CVE-2020-11651CRITICALunder attack
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISK
open
Referência
CVE-2008-7269
Open redirect vulnerability in api.php in SiteEngine 5.x allows user-assisted remote attackers to redirect users to arbi
38RISK
open
Referência
CVE-2026-8037
CVE-2026-8037CRITICALunder attack
OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF
100RISK
open
Referência
CVE-2026-10804
Streamlit Palette hashing.py weak hash
28RISK
open
Referência
CVE-2026-10803
MLflow Dataset Digest Computation digest_utils.py mlflow.data.digest_utils weak hash
28RISK
open
Referência
CVE-2026-10802
keystonejs keystone GraphQL API Endpoint output-field.ts resource consumption
33RISK
open
Referência
CVE-2026-10801
modelscope ms-swift PIL Image Cache Key base.py Template._save_pil_image weak hash
28RISK
open
Referência
CVE-2026-10288
code-projects Hotel and Tourism Reservation System Admin Login login.php password_verify improper authentication
33RISK
open
Referência
CVE-2026-10286
CodeAstro Payroll System home_employee.php sql injection
33RISK
open
Referência
CVE-2026-7229
code-projects Coaching Management System POST reply.php sql injection
33RISK
open
ReferênciaVexDay Proof
Joomla! Component Kbase 1.0 - SQL Injection
CVE-2008-6166webappsphp
SQL injection vulnerability in the KBase (com_kbase) 1.2 component for Joomla! allows remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
miniPortail 2.2 - Cross-Site Scripting / Local File Inclusion
CVE-2008-6167webappsphp
Directory traversal vulnerability in search.php in miniPortail 2.2 and earlier allows remote attackers to include and ex
23RISK
open
previouspage 503 / 746next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.