Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,620cataloged exploits
35,647CVEs with public exploitation
24,695lab-tested
22,429 exploits
Referência
CVE-2026-58166
OpenBMB ChatDev - Unauthenticated Path Traversal in Upload Handler Allows Arbitrary File Write and Delete
41RISK
open
Referência
CVE-2026-58116
LLaMA-Factory 0.9.5 Remote Code Execution via WebUI Model Path
48RISK
open
Referência
CVE-2026-13580
Edimax EW-7478APC POST Request formQoS buffer overflow
41RISK
open
Referência
CVE-2026-13545
D-Link DCS-935L POST Parameter setconf.cgi sub_400E40 os command injection
41RISK
open
Referência
CVE-2026-13544
Feehi CMS API users access control
33RISK
open
Referência
CVE-2026-13541
itsourcecode Hospital Management System doctorchangepassword.php sql injection
33RISK
open
Referência
CVE-2026-13515
Tenda JD12L SetPptpServerCfg formSetPPTPServer stack-based overflow
41RISK
open
Referência
CVE-2025-12669
Improper Control of Generation of Code ('Code Injection') in GitLab
33RISK
open
Referência
CVE-2020-37236
NewsLister Authenticated Persistent Cross-Site Scripting via Admin Panel
33RISK
open
Referência
CVE-2020-37235
WordPress Theme Wibar 1.1.8 Stored Cross-Site Scripting via Brand Component
33RISK
open
Referência
CVE-2020-37234
Internet Download Manager 6.38.12 Scheduler Buffer Overflow
33RISK
open
Referência
CVE-2020-37233
WordPress Plugin Buddypress 6.2.0 Persistent Cross-Site Scripting
33RISK
open
Referência
CVE-2020-37230
Syncplify.me Server! 5.0.37 Unquoted Service Path Privilege Escalation
41RISK
open
Referência
CVE-2020-37229
OKI sPSV Port Manager 1.0.41 Unquoted Service Path Privilege Escalation
41RISK
open
Referência
CVE-2021-47965
WordPress Plugin WP Super Edit 2.5.4 Unrestricted File Upload
48RISK
open
Referência
CVE-2025-13874
Authorization Bypass Through User-Controlled Key in GitLab
33RISK
open
Referência
CVE-2025-14869
Improper Validation of Specified Quantity in Input in GitLab
41RISK
open
Referência
CVE-2025-14870
Allocation of Resources Without Limits or Throttling in GitLab
41RISK
open
Referência
CVE-2026-3607
Access Control Check Implemented After Asset is Accessed in GitLab
33RISK
open
Referência
CVE-2019-25744
WordPress Popup Builder 3.49 Persistent Cross-Site Scripting
33RISK
open
Referência
CVE-2019-25743
WordPress Soliloquy Lite 2.5.6 Persistent Cross-Site Scripting
33RISK
open
Referência
CVE-2019-25742
WordPress Theme Zoner Real Estate 4.1.1 Persistent XSS
33RISK
open
Referência
CVE-2019-25741
Mobatek MobaXterm 12.1 Buffer Overflow via Sessions File
48RISK
open
Referência
CVE-2019-25740
Joomla com_jsjobs 1.2.6 Arbitrary File Deletion
41RISK
open
Referência
CVE-2019-25739
GigToDo Freelance Marketplace Script 1.3 Persistent XSS
33RISK
open
Referência
CVE-2019-25738
WordPress Hybrid Composer 1.4.6 Unauthenticated Settings Change
48RISK
open
Referência
CVE-2019-25737
Live Chat Unlimited 2.8.3 Stored Cross-Site Scripting
33RISK
open
Referência
CVE-2019-25736
LabF nfsAxe 3.7 Ping Client Buffer Overflow
41RISK
open
Referência
CVE-2026-10529
westboy CicadasCMS Task Scheduling Management ScheduleJobController.java cross site scripting
33RISK
open
Referência
CVE-2026-10276
hekmon8 Jenkins-server-mcp get_build_status/get_build_log/trigger_build index.ts jobPath server-side request forgery
33RISK
open
previouspage 560 / 748next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.