Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,449cataloged exploits
35,552CVEs with public exploitation
24,695lab-tested
22,367 exploits
Referência
CVE-2026-16082
Sipeed PicoClaw pipeline_execute.go ExecTool.executeRun toctou
33RISK
open
Referência
CVE-2026-16081
Sipeed PicoClaw auth.go cross-site request forgery
33RISK
open
Referência
CVE-2026-16077
AstrBotDevs AstrBot Filesystem Computer-Use Tool fs.py _normalize_rw_path link following
33RISK
open
Referência
CVE-2026-16076
AstrBotDevs AstrBot API open_api.py OpenApiRoute.chat_send authentication spoofing
33RISK
open
Referência
CVE-2026-16075
AstrBotDevs AstrBot session-listing Endpoint open_api.py OpenApiRoute.get_chat_sessions authorization
33RISK
open
Referência
CVE-2013-0807
Cross-site scripting (XSS) vulnerability in the NewSectionPrompt function in include/tool/editing_page.php in gpEasy CMS
23RISK
open
Referência
CVE-2013-0928
The NetWorker command processor in rrobotd.exe in the Device Manager in EMC AlphaStor 4.0 before build 800 allows remote
50RISK
open
Referência
CVE-2013-1080
The web server in Novell ZENworks Configuration Management (ZCM) 10.3 and 11.2 before 11.2.4 does not properly perform a
60RISK
open
Referência
Drupal 11.x-dev - Full Path Disclosure
CVE-2024-45440MEDIUMwebappsphp
core/authorize.php in Drupal 11.x-dev allows Full Path Disclosure (even when error logging is None) if the value of hash
48RISK
open
Referência
CVE-2013-1347
CVE-2013-1347HIGHunder attack
Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbit
100RISK
open
Referência
CVE-2018-5723
MASTER IPCAMERA01 3.3.4.2103 devices have a hardcoded password of cat1029 for the root account.
23RISK
open
ReferênciaVexDay Proof
32bit FTP (09.04.24) - 'Banner' Remote Buffer Overflow
CVE-2009-1592remotewindows_x86
Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a
23RISK
open
Referência
CVE-2018-8734
SQL injection vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker
50RISK
open
Referência
CVE-2010-2343
Stack-based buffer overflow in D.R. Software Audio Converter 8.1, 2007, and 8.05 allows remote attackers to execute arbi
50RISK
open
Referência
CVE-2016-0710
Multiple SQL injection vulnerabilities in the User Manager service in Apache Jetspeed before 2.3.1 allow remote attacker
50RISK
open
Referência
CVE-2019-8953
The HAProxy package before 0.59_16 for pfSense has XSS via the desc (aka Description) or table_actionsaclN parameter, re
35RISK
open
Referência
CVE-2019-13272
CVE-2019-13272HIGHunder attack
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISK
open
Referência
CVE-2017-1000486
CVE-2017-1000486CRITICALunder attack
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
100RISK
open
Referência
CVE-2015-1833
XML external entity (XXE) vulnerability in Apache Jackrabbit before 2.0.6, 2.2.x before 2.2.14, 2.4.x before 2.4.6, 2.6.
35RISK
open
Referência
CVE-2015-1833
XML external entity (XXE) vulnerability in Apache Jackrabbit before 2.0.6, 2.2.x before 2.2.14, 2.4.x before 2.4.6, 2.6.
35RISK
open
Referência
CVE-2024-7314
anji-plus AJ-Report Authentication Bypass
75RISK
open
Referência
CVE-2024-7314
anji-plus AJ-Report Authentication Bypass
75RISK
open
Referência
CVE-2024-7314
anji-plus AJ-Report Authentication Bypass
75RISK
open
Referência
CVE-2017-8496
Microsoft Edge in Windows 10 1607 and Windows Server 2016 allows an attacker to execute arbitrary code in the context of
35RISK
open
Referência
CVE-2024-53676
A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution
60RISK
open
Referência
CVE-2010-4052
Stack consumption vulnerability in the regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3,
35RISK
open
Referência
CVE-2018-14933
CVE-2018-14933CRITICALunder attack
upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir par
100RISK
open
Referência
CVE-2016-0015
DirectShow in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Wi
35RISK
open
Referência
CVE-2022-0557
OS Command Injection in microweber/microweber
53RISK
open
ReferênciaVexDay Proof
Sorinara Streaming Audio Player 0.9 - '.pla' Local Stack Overflow
CVE-2009-1644localwindows
Stack-based buffer overflow in Sorinara Streaming Audio Player 0.9 allows remote attackers to execute arbitrary code via
23RISK
open
previouspage 516 / 746next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.