Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,772cataloged exploits
35,760CVEs with public exploitation
24,695lab-tested
22,492 exploits
Referência
CVE-2026-19230
SourceCodester Photo Share Website Comment Input Box ajax.php save_upload cross site scripting
33RISK
open
Referência
CVE-2026-19207
PHPGurukul Company Visitor Management System manage-newvisitors.php cross site scripting
33RISK
open
Referência
CVE-2022-4995
Weaver E-cology 9.0 File Upload RCE via uploaderOperate.jsp
48RISK
open
Referência
CVE-2022-4995
Weaver E-cology 9.0 File Upload RCE via uploaderOperate.jsp
48RISK
open
Referência
CVE-2026-15148
WP Events Manager < 2.2.5 - Unauthenticated Payment Bypass and Booking Status Update via IDOR
33RISK
open
Referência
CVE-2015-6104
The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window
35RISK
open
Referência
CVE-2015-6104
The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window
35RISK
open
Referência
CVE-2015-6152
Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory co
35RISK
open
Referência
CVE-2015-6541
Multiple cross-site request forgery (CSRF) vulnerabilities in the Mail interface in Zimbra Collaboration Server (ZCS) be
23RISK
open
Referência
CVE-2026-15245
BNE Testimonials < 2.0.8.2 - Contributor+ Stored XSS via Slider Shortcode
33RISK
open
Referência
CVE-2026-15215
Subscriptions for WooCommerce < 2.0.1 - Shop Manager+ Arbitrary Plugin Installation
41RISK
open
Referência
CVE-2014-6271
CVE-2014-6271CRITICALunder attack
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
Referência
CVE-2014-6271
CVE-2014-6271CRITICALunder attack
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
Referência
CVE-2014-6271
CVE-2014-6271CRITICALunder attack
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
Referência
CVE-2014-6271
CVE-2014-6271CRITICALunder attack
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
Referência
CVE-2014-6271
CVE-2014-6271CRITICALunder attack
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
Referência
CVE-2026-70636
Flowise 3.1.4 Authentication Bypass via OAuth2 Credential Refresh Endpoint
41RISK
open
Referência
CVE-2026-67622
Flowise 3.1.4 IDOR in OpenAI Assistants Integration
41RISK
open
Referência
CVE-2026-67621
Flowise 3.1.4 Missing Authorization on Document Store Mutation Endpoints
41RISK
open
Referência
CVE-2026-19110
DataGear Chart Name HtmlTplDashboardWidgetHtmlRenderer.java HtmlTplDashboardWidgetHtmlRenderer cross site scripting
33RISK
open
Referência
CVE-2026-19071
itsourcecode Hospital Management System viewappointment.php sql injection
33RISK
open
Referência
CVE-2026-19070
itsourcecode Hospital Management System viewadmin.php sql injection
33RISK
open
Referência
CVE-2015-7257
ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated non-administrato
23RISK
open
Referência
CVE-2015-7257
ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated non-administrato
23RISK
open
Referência
CVE-2015-7258
ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated users to obtain
28RISK
open
Referência
CVE-2015-7297
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via un
60RISK
open
Referência
CVE-2026-17515
MLS Import < 7.0.4 - Subscriber+ Sensitive Information Disclosure via mlsimport_logger_per_item
33RISK
open
Referência
CVE-2026-16055
Contest Gallery < 30.0.7 - Unauthenticated Login-Protection and 2FA Bypass via post_cg_login
41RISK
open
Referência
CVE-2026-16942
WP Custom HTML Pages <= 0.6.2 - Author+ Stored XSS
33RISK
open
Referência
CVE-2026-16940
Custom Fields for WooCommerce < 1.5.1 - Unauthenticated Arbitrary File Deletion via Path Traversal
48RISK
open
previouspage 566 / 750next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.