Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,620cataloged exploits
35,647CVEs with public exploitation
24,695lab-tested
22,429 exploits
Referência
CVE-2019-9581
phpscheduleit Booked Scheduler 2.7.5 allows arbitrary file upload via the Favicon field, leading to execution of arbitra
28RISK
open
Referência
CVE-2026-9426
Edimax EW-7438RPn formHwSet stack-based overflow
41RISK
open
Referência
CVE-2026-9416
code-projects Employee Management System myprofile.php cross site scripting
33RISK
open
Referência
CVE-2026-9415
code-projects Employee Management System eloginwel.php cross site scripting
33RISK
open
Referência
CVE-2026-9413
SourceCodester Indian Invoicing System category.php cross site scripting
33RISK
open
Referência
CVE-2026-9412
SourceCodester Indian Invoicing System Backend Endpoint access control
33RISK
open
ReferênciaVexDay Proof
ApowerManager 3.1.7 - Phone Manager Remote Denial of Service (PoC)
CVE-2019-9601dosandroid
The ApowerManager application through 3.1.7 for Android allows remote attackers to cause a denial of service via many si
23RISK
open
Referência
CVE-2026-9411
SourceCodester Indian Invoicing System Invoice Generation IGST_Invoice.php sql injection
33RISK
open
Referência
CVE-2026-9410
Sushmi-pal Invoice-System Profile Workflow profile improper authorization
33RISK
open
Referência
CVE-2026-9409
Sushmi-pal Invoice-System User Management user improper authorization
33RISK
open
Referência
CVE-2026-9407
Totolink A8000RU Web Management cstecgi.cgi setFirewallType os command injection
48RISK
open
Referência
CVE-2026-9406
Totolink A8000RU Web Management cstecgi.cgi setRemoteCfg os command injection
48RISK
open
Referência
eBrigade ERP 4.5 - Arbitrary File Download
CVE-2019-9622webappsphp
eBrigade through 4.5 allows Arbitrary File Download via ../ directory traversal in the showfile.php file parameter, as d
23RISK
open
Referência
CVE-2019-9670
CVE-2019-9670CRITICALunder attack
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XX
100RISK
open
Referência
CVE-2019-9670
CVE-2019-9670CRITICALunder attack
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XX
100RISK
open
Referência
CVE-2026-67349
OpenCost < 1.121.0 Unauthenticated Helm Values Exposure and Admin Bypass
41RISK
open
Referência
CVE-2026-67348
Julep Insecure Direct Object Reference via GET /executions/{execution_id}
41RISK
open
Referência
CVE-2026-67347
Vendure 3.7.1 Cross-Channel Authorization Bypass via StockLocation and Asset Update
33RISK
open
Referência
CVE-2026-67345
MaxKey 4.1.12 DefaultRedirectResolver OAuth Authorization Code Theft
41RISK
open
Referência
CVE-2026-14310
Tutor LMS < 4.0.0 - Subscriber+ Cross-Course Q&A Content Disclosure and Reply Injection
33RISK
open
Referência
CVE-2026-14305
WP Delicious < 1.10.2 - Unauthenticated Arbitrary Post Meta Update via recipe_likes
33RISK
open
ReferênciaVexDay Proof
Free MP3 CD Ripper 2.6 - '.mp3' Buffer Overflow (SEH)
CVE-2019-9766localwindows_x86
Stack-based buffer overflow in Free MP3 CD Ripper 2.6, when converting a file, allows user-assisted remote attackers to
23RISK
open
ReferênciaVexDay Proof
Free MP3 CD Ripper 2.6 - '.wma' Local Buffer Overflow (SEH)
CVE-2019-9767localwindows_x86
Stack-based buffer overflow in Free MP3 CD Ripper 2.6, when converting a file, allows user-assisted remote attackers to
23RISK
open
ReferênciaVexDay Proof
AirMore 1.6.1 - Denial of Service (PoC)
CVE-2019-9831dosandroid
The AirMore application through 1.6.1 for Android allows remote attackers to cause a denial of service (system hang) via
23RISK
open
Referência
AirDrop 2.0 - Denial of Service (DoS)
CVE-2019-9832dosandroid
The AirDrop application through 2.0 for Android allows remote attackers to cause a denial of service via a client that m
23RISK
open
Referência
NetData 1.13.0 - HTML Injection
CVE-2019-9834webappsmultiple
The Netdata web application through 1.13.0 allows remote attackers to inject their own malicious HTML code into an impor
23RISK
open
Referência
CVE-2026-9368
NousResearch hermes-agent Environment Variable code_execution_tool.py execute_code sandbox
33RISK
open
Referência
CVE-2026-9365
Ettercap GG Dissector ec_gg.c FUNC_DECODER heap-based overflow
33RISK
open
Referência
CVE-2026-9364
projectworlds Online Art Gallery Shop adminHome.php sql injection
33RISK
open
Referência
CVE-2026-9363
Edimax EW-7438RPn POST Request formEZCHNwlanSetu formEZCHNwlanSetup command injection
33RISK
open
previouspage 555 / 748next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.