Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,813cataloged exploits
35,788CVEs with public exploitation
24,695lab-tested
22,549 exploits
Referência
CVE-2026-18934
RSS Aggregator by Feedzy < 5.2.6 - Author+ Cross-User Import Job Manipulation and Post Deletion
33RISK
open
Referência
CVE-2026-16985
Squeeze < 1.7.12 - Author+ Arbitrary File Upload
41RISK
open
Referência
CVE-2026-16949
Term Pages < 2.0.0 - Unauthenticated SQL Injection via tp_lookup
33RISK
open
Referência
CVE-2026-14941
Customer Reviews for WooCommerce < 5.116.0 - Subscriber+ Missing Authorization via Multiple Settings AJAX Actions
33RISK
open
Referência
CVE-2026-14860
Podcast Player < 8.3.1 - Unauthenticated Server-Side Request Forgery
33RISK
open
Referência
CVE-2026-14206
HT Contact Form < 2.9.3 - Unauthenticated Saved Form Draft Data Disclosure
41RISK
open
Referência
CVE-2026-13701
Advanced Excerpt < 4.5 - Admin+ Stored XSS via Ellipsis Setting
33RISK
open
Referência
CVE-2026-13600
AutoNetTV Relay < 3.0.14 - Unauthenticated Privilege Escalation via Scheduled Sync Cron
41RISK
open
Referência
CVE-2026-13170
Eventin < 4.1.20 - Editor+ Local File Inclusion via speaker_template Setting
41RISK
open
Referência
CVE-2026-12971
LearnPress < 4.4.4 - Instructor+ Server-Side Request Forgery via openai_apply_image_feature
28RISK
open
Referência
CVE-2026-17018
CubeWP Framework <= 1.1.30 - Contributor+ Arbitrary Post and User Meta Disclosure via IDOR
33RISK
open
Referência
Sphider Search Engine - Multiple Vulnerabilities
CVE-2014-5081webappsphp
sphider prior to 1.3.6, sphider-pro prior to 3.2, and sphider-plus prior to 3.2 allow authentication bypass
28RISK
open
Referência
CVE-2026-17010
Saitama Addon Pack <= 1.0.8 - Contributor+ Stored XSS via Post Meta
33RISK
open
Referência
CVE-2026-17016
Restore PayPal Standard for WooCommerce <= 3.1.0 - Payment Bypass via PDT Underpayment
28RISK
open
Referência
CVE-2014-5112
maint/modules/home/index.php in Fonality trixbox allows remote attackers to execute arbitrary commands via shell metacha
23RISK
open
Referência
CVE-2014-5115
Absolute path traversal vulnerability in DirPHP 1.0 allows remote attackers to read arbitrary files via a full pathname
23RISK
open
Referência
CVE-2026-17012
Restore PayPal Standard for WooCommerce <= 3.1.0 - Payment Bypass via Unvalidated receiver_email
33RISK
open
Referência
CVE-2015-6827
Cross-site request forgery (CSRF) vulnerability in Auto-Exchanger 5.1.0 allows remote attackers to hijack the authentica
23RISK
open
Referência
CVE-2015-6923
The ndvbs module in VBox Communications Satellite Express Protocol 2.3.17.3 allows local users to write to arbitrary phy
23RISK
open
Referência
CVE-2015-6923
The ndvbs module in VBox Communications Satellite Express Protocol 2.3.17.3 allows local users to write to arbitrary phy
23RISK
open
Referência
CVE-2026-3430
Creative Mail 1.6.5 - 1.6.9 - Unauthenticated SQLi
41RISK
open
Referência
CVE-2026-70637
LightFTP 2.4 Data Race Condition via ABOR Command in ftpserv.c
41RISK
open
Referência
CVE-2010-0373
SQL injection vulnerability in the libros (com_libros) component for Joomla! allows remote attackers to execute arbitrar
23RISK
open
Referência
CVE-2026-19019
poco-ai poco-agent Claude File workspace.py WorkspaceManager._setup_session_persistence cleanup
33RISK
open
Referência
CVE-2026-19019
poco-ai poco-agent Claude File workspace.py WorkspaceManager._setup_session_persistence cleanup
33RISK
open
Referência
CVE-2026-19011
TinyAGI agents.ts buildSystemPrompt file inclusion
33RISK
open
Referência
CVE-2026-19010
TinyAGI Message API Endpoint index.ts processMessage authorization
33RISK
open
Referência
CVE-2026-19009
TinyAGI Message API Endpoint response.ts collectFiles file inclusion
33RISK
open
Referência
CVE-2026-19008
mf-yang openclaw-cn apply_patch Tool sandbox-paths.ts assertNoSymlinkEscape link following
33RISK
open
Referência
CVE-2026-19007
mf-yang openclaw-cn reply-elevated.ts isApprovedElevatedSender privileges management
33RISK
open
previouspage 603 / 752next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.