Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,794cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
24,458 exploits
Exploit-DB
RosarioSIS 6.7.2 - Cross Site Scripting (XSS)
CVE-2020-15716webappsphp03 Dec 2025
RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the Preferences.php scrip
23RISK
open
Exploit-DB
phpMyFAQ 2.9.8 - Cross-Site Request Forgery(CSRF)
CVE-2017-15734webappsphp03 Dec 2025
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.main.php.
23RISK
open
Exploit-DB
PluckCMS 4.7.10 - Unrestricted File Upload
CVE-2020-20969HIGHwebappsphp03 Dec 2025
File Upload vulnerability in PluckCMS v.4.7.10 allows a remote attacker to execute arbitrary code via the trashcan_resto
41RISK
open
Exploit-DB
phpMyFaq 2.9.8 - Cross Site Request Forgery (CSRF)
CVE-2017-15808webappsphp03 Dec 2025
In phpMyFaq before 2.9.9, there is CSRF in admin/ajax.config.php.
23RISK
open
Exploit-DB
MaNGOSWebV4 4.0.6 - Reflected XSS
CVE-2017-6478webappsmultiple03 Dec 2025
paintballrefjosh/MaNGOSWebV4 before 4.0.8 is vulnerable to a reflected XSS in install/index.php (step parameter).
38RISK
open
Exploit-DB
phpMyAdmin 5.0.0 - SQL Injection
CVE-2020-5504webappsphp03 Dec 2025
In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could
35RISK
open
Exploit-DB
Django 5.1.13 - SQL Injection
CVE-2025-64459CRITICALwebappsmultiple03 Dec 2025
Potential SQL injection via _connector keyword argument in QuerySet and Q objects
53RISK
open
Exploit-DB
Piwigo 13.6.0 - SQL Injection
CVE-2023-33362CRITICALwebappsphp02 Dec 2025
Piwigo 13.6.0 is vulnerable to SQL Injection via in the "profile" function.
48RISK
open
Exploit-DB
phpIPAM 1.6 - Reflected Cross-Site Scripting (XSS)
CVE-2024-41358MEDIUMwebappsphp02 Dec 2025
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\import-export\import-load-data.php.
33RISK
open
Exploit-DB
YOURLS 1.8.2 - Cross-Site Request Forgery (CSRF)
CVE-2022-0088LOWwebappsmultiple02 Dec 2025
Cross-Site Request Forgery (CSRF) in yourls/yourls
28RISK
open
Exploit-DB
phpMyFAQ 3.1.7 - Reflected Cross-Site Scripting (XSS)
CVE-2022-3766HIGHwebappsmultiple02 Dec 2025
Cross-site Scripting (XSS) - Reflected in thorsten/phpmyfaq
56RISK
open
Exploit-DB
phpIPAM 1.6 - Reflected-Cross-Site Scripting (XSS)
CVE-2024-41357HIGHwebappsphp02 Dec 2025
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/powerDNS/record-edit.php.
41RISK
open
Exploit-DB
phpIPAM 1.5.1 - SQL Injection
CVE-2023-1211HIGHwebappsphp02 Dec 2025
SQL Injection in phpipam/phpipam
41RISK
open
Exploit-DB
Flowise 3.0.4 - Remote Code Execution (RCE)
CVE-2025-59528CRITICALwebappsmultiple31 Oct 2025
Flowise has Remote Code Execution vulnerability
85RISK
open
Exploit-DB
Casdoor 2.95.0 - Cross-Site Request Forgery (CSRF)
CVE-2023-34927webappsmultiple29 Oct 2025
Casdoor v1.331.0 and below was discovered to contain a Cross-Site Request Forgery (CSRF) in the endpoint /api/set-passwo
23RISK
open
Exploit-DB
dotCMS 25.07.02-1 - Authenticated Blind SQL Injection
CVE-2025-8311CRITICALwebappsmultiple16 Sep 2025
dotCMS versions 24.03.22 and after, identified a Boolean-based blind SQLi vulnerability in the /api/v1/contenttype endpo
48RISK
open
Exploit-DB
Mbed TLS 3.6.4 - Use-After-Free
CVE-2025-47917HIGHlocalmultiple16 Sep 2025
Mbed TLS before 3.6.4 allows a use-after-free in certain situations of applications that are developed in accordance wit
41RISK
open
Exploit-DB
ClipBucket 5.5.2 Build #90 - Server-Side Request Forgery (SSRF)
CVE-2025-55911MEDIUMremotemultiple16 Sep 2025
An issue Clip Bucket v.5.5.2 Build#90 allows a remote attacker to execute arbitrary codes via the file_downloader.php an
33RISK
open
Exploit-DB
Concrete CMS 9.4.3 - Stored XSS
CVE-2025-8573LOWwebappsmultiple16 Sep 2025
Concrete CMS 9 through 9.4.2 is vulnerable to Stored XSS from Home Folder on Members Dashboard page
28RISK
open
Exploit-DB
Tourism Management System 2.0 - Arbitrary Shell Upload
CVE-2025-57642HIGHwebappsmultiple16 Sep 2025
A Shell Upload vulnerability in Tourism Management System 2.0 allows an attacker to upload and execute arbitrary PHP she
41RISK
open
Exploit-DB
Casdoor 2.55.0 - Cross-Site Request Forgery (CSRF)
CVE-2023-34927webappsmultiple16 Sep 2025
Casdoor v1.331.0 and below was discovered to contain a Cross-Site Request Forgery (CSRF) in the endpoint /api/set-passwo
23RISK
open
Exploit-DB
ClipBucket 5.5.0 - Arbitrary File Upload
CVE-2025-55912HIGHremotemultiple16 Sep 2025
An issue in ClipBucket 5.5.0 and prior versions allows an unauthenticated attacker can exploit the plupload endpoint in
41RISK
open
Exploit-DB
HTTP/2 2.0 - Denial Of Service (DOS)
CVE-2023-44487HIGHunder attackremotemultiple16 Sep 2025
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISK
open
Exploit-DB
HTMLDOC 1.9.13 - Stack Buffer Overflow
CVE-2021-43579remotemultiple16 Sep 2025
A stack-based buffer overflow in image_load_bmp() in HTMLDOC <= 1.9.13 results in remote code execution if the victim co
23RISK
open
Exploit-DB
XWiki Platform 15.10.10 - Metasploit Module for Remote Code Execution (RCE)
CVE-2025-24893CRITICALunder attackwebappsmultiple16 Sep 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
Exploit-DB
ELEX WooCommerce WordPress Plugin 1.4.3 - SQL Injection
CVE-2025-10046MEDIUMwebappsmultiple16 Sep 2025
ELEX WooCommerce Google Shopping (Google Product Feed) <= 1.4.3 - Authenticated (Admin+) SQL Inejction
33RISK
open
Exploit-DB
Ivanti Endpoint Manager Mobile 12.5.0.0 - Authentication Bypass
CVE-2025-4427MEDIUMunder attackremotemultiple26 Aug 2025
Authentication Bypass
100RISK
open
Exploit-DB
Birth Chart Compatibility WordPress Plugin 2.0 - Full Path Disclosure
CVE-2025-6082MEDIUMwebappsmultiple26 Aug 2025
Birth Chart Compatibility <= 2.0 - Unauthenticated Full Path Exposure
33RISK
open
Exploit-DB
StoryChief Wordpress Plugin 1.0.42 - Arbitrary File Upload
CVE-2025-7441CRITICALwebappsmultiple26 Aug 2025
StoryChief <= 1.0.42 - Unauthenticated Arbitrary File Upload
75RISK
open
Exploit-DB
GeoVision ASManager Windows Application 6.1.2.0 - Credentials Disclosure
CVE-2025-26263MEDIUMlocalwindows26 Aug 2025
GeoVision ASManager Windows desktop application with the version 6.1.2.0 or less (fixed in 6.2.0), is vulnerable to cred
33RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.