Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,794cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
22,573 exploits
ReferênciaVexDay Proof
EgyPlus 7ml 1.0.1 - Authentication Bypass
CVE-2009-2167webappsphp
Multiple SQL injection vulnerabilities in cpanel/login.php in EgyPlus 7ammel (aka 7ml) 1.0.1 and earlier, when magic_quo
23RISK
open
Referência
CVE-2019-9194
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
60RISK
open
Referência
CVE-2019-9194
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
60RISK
open
ReferênciaVexDay Proof
Internet PhotoShow (Special Edition) - Insecure Cookie Handling
CVE-2008-2282webappsphp
admin.php in Internet Photoshow and Internet Photoshow Special Edition (SE) allows remote attackers to bypass authentica
23RISK
open
Referência
CVE-2023-33246
CVE-2023-33246CRITICALunder attack
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RISK
open
Referência
CVE-2023-33246
CVE-2023-33246CRITICALunder attack
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RISK
open
Referência104
CVE-2023-33246 RocketMQ RCE Detect By Version and Exploit
CVE-2023-33246CRITICALunder attack
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RISK
open
ReferênciaVexDay Proof
idautomation bar code - ActiveX Multiple Vulnerabilities
CVE-2008-2283remotewindows
IDAutomation allows remote attackers to overwrite arbitrary files via the argument to the (1) SaveBarCode and (2) SaveEn
23RISK
open
Referência
CVE-2026-10815
LakshayD02 Hostel-Management-System-PHP Admin Dashboard index.php authorization
33RISK
open
Referência
CVE-2026-10814
milvus-io milvus Grantee ID Hash kv_catalog.go weak hash
28RISK
open
Referência
CVE-2026-10812
zilliztech GPTCache Cache Key pre.py BufferedReader.peek weak hash
28RISK
open
Referência
CVE-2023-46747
CVE-2023-46747CRITICALunder attackransomware
BIG-IP Configuration utility unauthenticated remote code execution vulnerability
100RISK
open
Referência
CVE-2019-25745
WordPress Plugin Google Review Slider 6.1 SQL Injection via tid
41RISK
open
Referência
CVE-2019-25735
AllPlayer 7.4 Local Buffer Overflow via SEH Unicode
41RISK
open
Referência
CVE-2020-8260
CVE-2020-8260HIGHunder attack
A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform
100RISK
open
Referência
CVE-2020-11651
CVE-2020-11651CRITICALunder attack
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISK
open
Referência
CVE-2020-11651
CVE-2020-11651CRITICALunder attack
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISK
open
Referência
CVE-2008-7269
Open redirect vulnerability in api.php in SiteEngine 5.x allows user-assisted remote attackers to redirect users to arbi
38RISK
open
ReferênciaVexDay Proof
Kostenloses Linkmanagementscript - SQL Injection
CVE-2008-2301webappsphp
SQL injection vulnerability in Kostenloses Linkmanagementscript allows remote attackers to execute arbitrary SQL command
23RISK
open
Referência
CVE-2026-8037
CVE-2026-8037CRITICALunder attack
OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF
100RISK
open
Referência
CVE-2026-10804
Streamlit Palette hashing.py weak hash
28RISK
open
Referência
CVE-2026-10803
MLflow Dataset Digest Computation digest_utils.py mlflow.data.digest_utils weak hash
28RISK
open
Referência
CVE-2026-10802
keystonejs keystone GraphQL API Endpoint output-field.ts resource consumption
33RISK
open
Referência
CVE-2026-10801
modelscope ms-swift PIL Image Cache Key base.py Template._save_pil_image weak hash
28RISK
open
Referência
CVE-2026-10288
code-projects Hotel and Tourism Reservation System Admin Login login.php password_verify improper authentication
33RISK
open
Referência
CVE-2026-10286
CodeAstro Payroll System home_employee.php sql injection
33RISK
open
ReferênciaVexDay Proof
Core Image Fun House 2.0 (OSX) - Arbitrary Code Execution (PoC)
CVE-2008-2304dososx
Buffer overflow in Apple Core Image Fun House 2.0 and earlier in CoreImage Examples in Xcode tools before 3.1 allows use
23RISK
open
Referência
CVE-2026-7229
code-projects Coaching Management System POST reply.php sql injection
33RISK
open
Referência
CVE-2021-25298
CVE-2021-25298HIGHunder attack
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi
100RISK
open
Referência
CVE-2021-25298
CVE-2021-25298HIGHunder attack
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi
100RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.