Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,533cataloged exploits
35,607CVEs with public exploitation
24,695lab-tested
22,407 exploits
Referência
CVE-2018-0946
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft
35RISK
open
Referência
CVE-2015-4632
Multiple directory traversal vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08
50RISK
open
Referência
CVE-2015-4632
Multiple directory traversal vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08
50RISK
open
Referência
CVE-2016-3288
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code via a crafted web page, aka "Internet E
35RISK
open
Referência
CVE-2014-5468
A File Inclusion vulnerability exists in Railo 4.2.1 and earlier via a specially-crafted URL request to the thumbnail.cf
50RISK
open
Referência
CVE-2026-14749
mjperpinosa stumasy calculate.php eval code injection
33RISK
open
Referência
CVE-2026-14748
AIAnytime Awesome-MCP-Server mcp-wiki/wiki-summary server.py server-side request forgery
33RISK
open
Referência
CVE-2015-2097
Multiple buffer overflows in WebGate Embedded Standard Protocol (WESP) SDK allow remote attackers to execute arbitrary c
28RISK
open
Referência
CVE-2015-2097
Multiple buffer overflows in WebGate Embedded Standard Protocol (WESP) SDK allow remote attackers to execute arbitrary c
28RISK
open
Referência
CVE-2020-15261
Unquoted service path vulnerability on Veyon
46RISK
open
Referência
CVE-2013-4625
Cross-site scripting (XSS) vulnerability in files/installer.cleanup.php in the Duplicator plugin before 0.4.5 for WordPr
43RISK
open
Referência
CVE-2016-8020
Improper control of generation of code vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earl
28RISK
open
Referência
CVE-2022-25090
Printix Secure Cloud Print Management through 1.3.1106.0 creates a temporary temp.ini file in a directory with insecure
28RISK
open
Referência
CVE-2022-25090
Printix Secure Cloud Print Management through 1.3.1106.0 creates a temporary temp.ini file in a directory with insecure
28RISK
open
Referência
UltimateHG/CVE-2025-52689-PoC
Weak Session ID Check in the OmniAccess Stellar Web Management Interface
53RISK
open
Referência
CVE-2015-6023
ping.cgi in NetCommWireless HSPA 3G10WVE wireless routers with firmware before 3G10WVE-L101-S306ETS-C01_R05 allows remot
28RISK
open
Referência
CVE-2015-6023
ping.cgi in NetCommWireless HSPA 3G10WVE wireless routers with firmware before 3G10WVE-L101-S306ETS-C01_R05 allows remot
28RISK
open
Referência
CVE-2013-1670
The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbi
28RISK
open
Referência
CVE-2018-5407
Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks
23RISK
open
Referência
CVE-2011-5212
SQL injection vulnerability in admin/index.php in Subrion CMS 2.0.4 allows remote attackers to execute arbitrary SQL com
23RISK
open
Referência
CVE-2014-7221
TeamSpeak Client 3.0.14 and earlier allows remote authenticated users to cause a denial of service (buffer overflow and
28RISK
open
ReferênciaVexDay Proof
CA BrightStor ARCserve 11.5.2.0 - 'catirpc.dll' RPC Server Denial of Service
CVE-2007-0816doswindows
The RPC Server service (catirpc.exe) in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 SP2 and earlie
28RISK
open
Referência
CVE-2020-13144
Studio in Open edX Ironwood 2.5, when CodeJail is not used, allows a user to go to the "Create New course>New section>Ne
28RISK
open
Referência
CVE-2020-11060
Remote Code Execution in GLPI
46RISK
open
Referência
CVE-2010-3145
Untrusted search path vulnerability in the BitLocker Drive Encryption API, as used in sdclt.exe in Backup Manager in Mic
28RISK
open
Referência
CVE-2010-2259
Directory traversal vulnerability in the BF Survey (com_bfsurvey) component for Joomla! allows remote attackers to inclu
43RISK
open
Referência
CVE-2010-2263
nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or
60RISK
open
Referência
CVE-2021-38648
CVE-2021-38648HIGHunder attack
Open Management Infrastructure Elevation of Privilege Vulnerability
91RISK
open
Referência
CVE-2010-2310
SolarWinds TFTP Server 10.4.0.13 allows remote attackers to cause a denial of service (crash) via a long write request.
28RISK
open
Referência
CVE-2013-6227
Unrestricted file upload vulnerability in plugins/editor.zoho/agent/save_zoho.php in the Zoho plugin in Pydio (formerly
23RISK
open
previouspage 543 / 747next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.