Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,772cataloged exploits
35,760CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,523GitHub PoC 14,289VulnCheck XDB 8,710Nuclei 4,319Metasploit 3,476✓ verified onlyrecentpopularrisk
22,492 exploits
Referência
CVE-2026-19230
SourceCodester Photo Share Website Comment Input Box ajax.php save_upload cross site scripting
33RISK
open ↗Referência
CVE-2026-19207
PHPGurukul Company Visitor Management System manage-newvisitors.php cross site scripting
33RISK
open ↗Referência
CVE-2026-15148
WP Events Manager < 2.2.5 - Unauthenticated Payment Bypass and Booking Status Update via IDOR
33RISK
open ↗Referência
CVE-2015-6104
The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window
35RISK
open ↗Referência
CVE-2015-6104
The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window
35RISK
open ↗Referência
CVE-2015-6152
Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory co
35RISK
open ↗Referência
CVE-2015-6541
Multiple cross-site request forgery (CSRF) vulnerabilities in the Mail interface in Zimbra Collaboration Server (ZCS) be
23RISK
open ↗Referência
CVE-2026-15245
BNE Testimonials < 2.0.8.2 - Contributor+ Stored XSS via Slider Shortcode
33RISK
open ↗Referência
CVE-2026-15215
Subscriptions for WooCommerce < 2.0.1 - Shop Manager+ Arbitrary Plugin Installation
41RISK
open ↗Referência
CVE-2014-6271
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open ↗Referência
CVE-2014-6271
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open ↗Referência
CVE-2014-6271
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open ↗Referência
CVE-2014-6271
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open ↗Referência
CVE-2014-6271
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open ↗Referência
CVE-2026-70636
Flowise 3.1.4 Authentication Bypass via OAuth2 Credential Refresh Endpoint
41RISK
open ↗Referência
CVE-2026-67621
Flowise 3.1.4 Missing Authorization on Document Store Mutation Endpoints
41RISK
open ↗Referência
CVE-2026-19110
DataGear Chart Name HtmlTplDashboardWidgetHtmlRenderer.java HtmlTplDashboardWidgetHtmlRenderer cross site scripting
33RISK
open ↗Referência
CVE-2026-19071
itsourcecode Hospital Management System viewappointment.php sql injection
33RISK
open ↗Referência
CVE-2026-19070
itsourcecode Hospital Management System viewadmin.php sql injection
33RISK
open ↗Referência
CVE-2015-7257
ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated non-administrato
23RISK
open ↗Referência
CVE-2015-7257
ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated non-administrato
23RISK
open ↗Referência
CVE-2015-7258
ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated users to obtain
28RISK
open ↗Referência
CVE-2015-7297
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via un
60RISK
open ↗Referência
CVE-2026-17515
MLS Import < 7.0.4 - Subscriber+ Sensitive Information Disclosure via mlsimport_logger_per_item
33RISK
open ↗Referência
CVE-2026-16055
Contest Gallery < 30.0.7 - Unauthenticated Login-Protection and 2FA Bypass via post_cg_login
41RISK
open ↗Referência
CVE-2026-16940
Custom Fields for WooCommerce < 1.5.1 - Unauthenticated Arbitrary File Deletion via Path Traversal
48RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.