Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,813cataloged exploits
35,788CVEs with public exploitation
24,695lab-tested
22,549 exploits
Referência
CVE-2014-4492
libnetcore in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 does not verify that certain
28RISK
open
Referência
CVE-2014-4511
Gitlist before 0.5.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the file name in
60RISK
open
Referência
CVE-2009-4381
Cross-site scripting (XSS) vulnerability in index.php in texmedia Million Pixel Script 3 allows remote attackers to inje
23RISK
open
Referência
CVE-2009-4381
Cross-site scripting (XSS) vulnerability in index.php in texmedia Million Pixel Script 3 allows remote attackers to inje
23RISK
open
Referência
CVE-2009-4386
SQL injection vulnerability in hotel_tiempolibre_ext.php in Venalsur Booking Centre Booking System for Hotels Group, whe
23RISK
open
Referência
CVE-2009-4423
SQL injection vulnerability in index.php in weenCompany 4.0.0 allows remote attackers to execute arbitrary SQL commands
23RISK
open
Referência
CVE-2009-4432
SQL injection vulnerability in index.php in CodeMight VideoCMS 3.1 allows remote attackers to execute arbitrary SQL comm
23RISK
open
Referência
CVE-2026-73482
phpList < 3.7.0-RC5 Cross-Site Request Forgery via admins.php
41RISK
open
Referência
CVE-2019-25765
ASP-CMS SQL Injection via commentList.asp id Parameter
41RISK
open
Referência
CVE-2015-4877
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.5.0, 8.5.1, and 8.
23RISK
open
Referência
CVE-2024-58374
Hongjing e-HR Unauthenticated SQL Injection via getSdutyTree
41RISK
open
Referência
CVE-2026-59109
Zalktis: SQL injection via partner-controlled fields in imported e-invoices
41RISK
open
Referência
CVE-2026-73515
PostGIS < 3.7.0beta2 Out-of-Bounds Read via FlatGeobuf Buffer
41RISK
open
Referência
CVE-2026-14332
Ecwid by Lightspeed Ecommerce Shopping Cart < 7.0.9 - Subscriber+ Store Disconnection via 'ec_disconnect' Action
33RISK
open
Referência
CVE-2026-19088
ShopEngine < 4.9.3 - Customer PII Disclosure via Forced Authentication
33RISK
open
Referência
CVE-2026-18945
WP Helper Premium < 4.7.6 - Unauthenticated Order Data Disclosure and Order Manipulation via Missing Order Key Validation
41RISK
open
Referência
CVE-2026-14213
Amelia < 2.4.6 - Provider+ Cross-Customer Appointment Data Disclosure via IDOR
28RISK
open
Referência
CVE-2026-14182
Customer Email Verification for WooCommerce < 3.2.6 - Unauthenticated Account Takeover via Type-Juggling Authentication Bypass
48RISK
open
Referência
CVE-2026-13610
KiviCare < 4.5.2 - Unauthenticated Privilege Escalation via Registration
41RISK
open
Referência
CVE-2026-13328
TLP Food Menu < 6.0.2 - Unauthenticated Reservation Status Modification
33RISK
open
Referência
CVE-2026-18391
WooCommerce Subscriptions < 9.1.0 - Unauthenticated RCE via PHP Object Injection
48RISK
open
Referência
CVE-2026-18366
Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator
48RISK
open
Referência
CVE-2026-18230
WP Directory Kit < 1.5.6 - Subscriber+ SQL Injection via section Parameter
41RISK
open
Referência
CVE-2026-18057
Events Manager < 7.4.1 - Subscriber+ Booking Consent Record Tampering via SQL Injection
41RISK
open
Referência
CVE-2026-18049
WP Photo Album Plus < 9.2.07.002 - Unauthenticated Option Disclosure via gettogo
41RISK
open
Referência
CVE-2026-69112
Hugging Face Accelerate 1.14.0 Path Traversal and DoS via weight_map
33RISK
open
Referência
CVE-2026-71966
CyberPanel 2.4.3 Authenticated Command Injection via starRemoteTransfer
41RISK
open
Referência
CVE-2026-71965
CyberPanel 2.4.3 Authenticated RCE via Remote Backup Feature
41RISK
open
Referência
CVE-2026-71964
CyberPanel 2.4.3 Arbitrary File Read via File Manager ZIP Upload
41RISK
open
Referência
CVE-2026-71962
Flowise 2.2.4 - 3.1.4 Missing Authorization via openai-assistants-file/download
41RISK
open
previouspage 601 / 752next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.