Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,980cataloged exploits
36,899CVEs with public exploitation
24,695lab-tested
24,476 exploits
Exploit-DB
Mailing List Manager Pro 3.0 - SQL Injection
CVE-2017-15967webappsphp30 Oct 2017
Mailing List Manager Pro 3.0 allows SQL Injection via the edit parameter to admin/users in a sort=login action, or the e
23RISK
open
Exploit-DB
AROX School ERP PHP Script - 'id' SQL Injection
CVE-2017-15978webappsphp30 Oct 2017
AROX School ERP PHP Script 1.0 allows SQL Injection via the office_admin/ id parameter.
23RISK
open
Exploit-DB
CPA Lead Reward Script - SQL Injection
CVE-2017-15986webappsphp30 Oct 2017
CPA Lead Reward Script allows SQL Injection via the username parameter.
23RISK
open
Exploit-DB
Protected Links - SQL Injection
CVE-2017-15977webappsphp30 Oct 2017
Protected Links - Expiring Download Links 1.0 allows SQL Injection via the username parameter.
23RISK
open
Exploit-DB
Shareet - 'photo' SQL Injection
CVE-2017-15979webappsphp30 Oct 2017
Shareet - Photo Sharing Social Network 1.0 allows SQL Injection via the photo parameter.
23RISK
open
Exploit-DB
Fake Magazine Cover Script - SQL Injection
CVE-2017-15987webappsphp30 Oct 2017
Fake Magazine Cover Script allows SQL Injection via the rate.php value parameter or the content.php id parameter.
23RISK
open
Exploit-DB
CmsLite 1.4 - 'S' SQL Injection
CVE-2017-15984webappsphp30 Oct 2017
Creative Management System (CMS) Lite 1.4 allows SQL Injection via the S parameter to index.php.
23RISK
open
Exploit-DB
Same Sex Dating Software Pro 1.0 - SQL Injection
CVE-2017-15971webappsphp30 Oct 2017
Same Sex Dating Software Pro 1.0 allows SQL Injection via the viewprofile.php profid parameter, the viewmessage.php send
23RISK
open
Exploit-DB
ZeeBuddy 2x - 'groupid' SQL Injection
CVE-2017-15976webappsphp30 Oct 2017
ZeeBuddy 2x allows SQL Injection via the admin/editadgroup.php groupid parameter, a different vulnerability than CVE-200
23RISK
open
Exploit-DB
Website Broker Script - 'status_id' SQL Injection
CVE-2017-15992webappsphp30 Oct 2017
Website Broker Script allows SQL Injection via the 'status_id' Parameter to status_list.php.
23RISK
open
Exploit-DB
Vastal I-Tech Agent Zone - 'searchCommercial.php' / 'searchResidential.php' SQL Injection
CVE-2017-15991webappsphp30 Oct 2017
Vastal I-Tech Agent Zone (aka The Real Estate Script) allows SQL Injection in searchCommercial.php via the property_type
23RISK
open
Exploit-DB
iProject Management System 1.0 - 'ID' SQL Injection
CVE-2017-15961webappsphp30 Oct 2017
iProject Management System 1.0 allows SQL Injection via the ID parameter to index.php.
23RISK
open
Exploit-DB
tPanel 2009 - Authentication Bypass
CVE-2017-15974webappsphp30 Oct 2017
tPanel 2009 allows SQL injection for Authentication Bypass via 'or 1=1 or ''=' to login.php.
23RISK
open
Exploit-DB
Joomla! Component Zh YandexMap 6.1.1.0 - 'placemarklistid' SQL Injection
CVE-2017-15966webappsphp30 Oct 2017
The Zh YandexMap (aka com_zhyandexmap) component 6.1.1.0 for Joomla! allows SQL Injection via the placemarklistid parame
23RISK
open
Exploit-DB
Article Directory Script 3.0 - 'id' SQL Injection
CVE-2017-15960webappsphp30 Oct 2017
Article Directory Script 3.0 allows SQL Injection via the id parameter to author.php or category.php.
23RISK
open
Exploit-DB
Job Board Script - 'nice_theme' SQL Injection
CVE-2017-15964webappsphp30 Oct 2017
Job Board Script Software allows SQL Injection via the PATH_INFO to a /job-details URI.
23RISK
open
Exploit-DB
Sokial Social Network Script 1.0 - SQL Injection
CVE-2017-15973webappsphp30 Oct 2017
Sokial Social Network Script 1.0 allows SQL Injection via the id parameter to admin/members_view.php.
23RISK
open
Exploit-DBVexDay Proof
Oracle Java SE - Web Start jnlp XML External Entity Processing Information Disclosure
CVE-2017-10309webappsxml30 Oct 2017
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affecte
23RISK
open
Exploit-DB
Ingenious 2.3.0 - Arbitrary File Upload
CVE-2017-15957webappsphp30 Oct 2017
my_profile.php in Ingenious School Management System 2.3.0 allows a student or teacher to upload an arbitrary file.
23RISK
open
Exploit-DB
MyMagazine 1.0 - 'id' SQL Injection
CVE-2017-15983webappsphp30 Oct 2017
MyMagazine Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing
23RISK
open
Exploit-DB
Nice PHP FAQ Script - 'nice_theme' SQL Injection
CVE-2017-15988webappsphp30 Oct 2017
Nice PHP FAQ Script allows SQL Injection via the index.php nice_theme parameter, a different vulnerability than CVE-2008
23RISK
open
Exploit-DB
Zomato Clone Script - 'resid' SQL Injection
CVE-2017-15993webappsphp30 Oct 2017
Zomato Clone Script allows SQL Injection via the restaurant-menu.php resid parameter.
23RISK
open
Exploit-DB
PHPMyFAQ 2.9.8 - Cross-Site Scripting (3)
CVE-2017-15727webappsphp28 Oct 2017
In phpMyFAQ before 2.9.9, there is Stored Cross-site Scripting (XSS) via an HTML attachment.
23RISK
open
Exploit-DB
PHP Melody 2.6.1 - SQL Injection
CVE-2017-15081webappsphp28 Oct 2017
In PHPSUGAR PHP Melody CMS 2.6.1, SQL Injection exists via the playlist parameter to playlists.php.
23RISK
open
Exploit-DB
phpMyFAQ 2.9.8 - Cross-Site Request Forgery
CVE-2017-15730webappsphp27 Oct 2017
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.ratings.php.
23RISK
open
Exploit-DB
Watchdog Development Anti-Malware / Online Security Pro - NULL Pointer Dereference
CVE-2017-15920doswindows26 Oct 2017
In Watchdog Anti-Malware 2.74.186.150 and Online Security Pro 2.74.186.150, the zam32.sys driver contains a NULL pointer
23RISK
open
Exploit-DB
HitmanPro 3.7.15 Build 281 - Kernel Pool Overflow
CVE-2017-6008localwindows26 Oct 2017
A kernel pool overflow in the driver hitmanpro37.sys in Sophos SurfRight HitmanPro before 3.7.20 Build 286 (included in
23RISK
open
Exploit-DB
Watchdog Development Anti-Malware / Online Security Pro - NULL Pointer Dereference
CVE-2017-15921doswindows26 Oct 2017
In Watchdog Anti-Malware 2.74.186.150 and Online Security Pro 2.74.186.150, the zam32.sys driver contains a NULL pointer
23RISK
open
Exploit-DB
KeystoneJS 4.0.0-beta.5 - CSV Excel Macro Injection
CVE-2017-15879webappsnodejs25 Oct 2017
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in admin/server/api/download.js and lib/list/getCS
23RISK
open
Exploit-DB
KeystoneJS 4.0.0-beta.5 - Cross-Site Scripting
CVE-2017-15878webappsnodejs25 Oct 2017
A cross-site scripting (XSS) vulnerability exists in fields/types/markdown/MarkdownType.js in KeystoneJS before 4.0.0-be
23RISK
open
previouspage 125 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.