Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

72,018cataloged exploits
32,219CVEs with public exploitation
1,932lab-tested
20,023 exploits
Referência
CVE-2020-14461
Zyxel Armor X1 WAP6806 1.00(ABAL.6)C0 devices allow Directory Traversal via the images/eaZy/ URI.
23RISK
open
Referência
CVE-2022-26521
Abantecart through 1.3.2 allows remote authenticated administrators to execute arbitrary code by uploading an executable
23RISK
open
Referência
MiniBill 1.22b - config[plugin_dir] Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in MiniBill 2006-07-14 (1.2.2) allow remote attackers to execute arbi
23RISK
open
Referência
Simple PHP Blog 0.4.7.1 - Remote Command Execution
Directory traversal vulnerability in install05.php in Simple PHP Blog (SPB) 0.4.7.1 and earlier allows remote attackers
23RISK
open
Referência
CVE-2016-10043
An issue was discovered in Radisys MRF Web Panel (SWMS) 9.0.1. The MSM_MACRO_NAME POST parameter in /swms/ms.cgi was dis
23RISK
open
Referência
Multiple Vendor - PF Null Pointer Dereference
The pf_test_rule function in OpenBSD Packet Filter (PF), as used in OpenBSD 4.2 through 4.5, NetBSD 5.0 before RC3, MirO
23RISK
open
Referência
OpenBSD 4.5 - IP datagrams Remote Denial of Service
The pf_test_rule function in OpenBSD Packet Filter (PF), as used in OpenBSD 4.2 through 4.5, NetBSD 5.0 before RC3, MirO
23RISK
open
Referência
CVE-2012-1010
Unrestricted file upload vulnerability in actions.php in the AllWebMenus plugin before 1.1.8 for WordPress allows remote
23RISK
open
Referência
CVE-2022-4063
InPost Gallery < 2.1.4.1 - Unauthenticated LFI to RCE
63RISK
open
Referência
CVE-2026-10812
zilliztech GPTCache Cache Key pre.py BufferedReader.peek weak hash
28RISK
open
Referência
Shadowed Portal 5.599 - 'root' Remote File Inclusion
PHP remote file inclusion vulnerability in bottom.php in Shadowed Portal 5.599 and earlier allows remote attackers to ex
23RISK
open
Referência
Mambo Component Security Images 3.0.5 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Security Images (com_securityimages) component 3.0.5 and earlier f
23RISK
open
Referência
CVE-2018-18793
School Event Management System 1.0 allows Arbitrary File Upload via event/controller.php?action=photos.
23RISK
open
Referência
CVE-2018-18793
School Event Management System 1.0 allows Arbitrary File Upload via event/controller.php?action=photos.
23RISK
open
Referência
CVE-2017-7041
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISK
open
Referência
Joomla! Component RSfiles 1.0.2 - 'path' File Download
Directory traversal vulnerability in index.php in the RSfiles component (com_rsfiles) 1.0.2 and earlier for Joomla! allo
38RISK
open
Referência
CVE-2018-18924
The image-upload feature in ProjeQtOr 7.2.5 allows remote attackers to execute arbitrary code by uploading a .shtml file
23RISK
open
Referência
Alstrasoft e-Friends 4.85 - Remote Command Execution
Directory traversal vulnerability in chat/getStartOptions.php in AlstraSoft E-friends 4.85 allows remote attackers to in
23RISK
open
Referência
HSRS 1.0 - 'addcode.php' Remote File Inclusion
PHP remote file inclusion vulnerability in addcode.php in HIOX Star Rating System Script (HSRS) 1.0 and earlier allows r
23RISK
open
Referência
Bubla 0.9.2 - 'bu_dir' Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Vladimir Menshakov buratinable templator (aka bubla) 0.9.1 allow r
23RISK
open
Referência
CVE-2010-3314
Cross-site scripting (XSS) vulnerability in login.php in EGroupware 1.4.001+.002; 1.6.001+.002 and possibly other versio
23RISK
open
Referência
FretsWeb 1.2 - Multiple Local File Inclusions
Multiple directory traversal vulnerabilities in FretsWeb 1.2 allow remote attackers to read arbitrary files via director
23RISK
open
Referência
POWERGAP 2003 - 's0x.php' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in POWERGAP allow remote attackers to execute arbitrary PHP code via
28RISK
open
Referência
CVE-2010-1475
Directory traversal vulnerability in the Preventive & Reservation (com_preventive) component 1.0.5 for Joomla! allows re
38RISK
open
Referência
CVE-2010-1475
Directory traversal vulnerability in the Preventive & Reservation (com_preventive) component 1.0.5 for Joomla! allows re
38RISK
open
Referência
CVE-2010-1722
Directory traversal vulnerability in the Online Market (com_market) component 2.x for Joomla! allows remote attackers to
38RISK
open
Referência
CVE-2010-1722
Directory traversal vulnerability in the Online Market (com_market) component 2.x for Joomla! allows remote attackers to
38RISK
open
Referência
CVE-2010-1474
Directory traversal vulnerability in the Sweety Keeper (com_sweetykeeper) component 1.5.x for Joomla! allows remote atta
38RISK
open
Referência
CVE-2010-1474
Directory traversal vulnerability in the Sweety Keeper (com_sweetykeeper) component 1.5.x for Joomla! allows remote atta
38RISK
open
Referência
CVE-2016-10277
An elevation of privilege vulnerability in the Motorola bootloader could enable a local malicious application to execute
23RISK
open
previouspage 139 / 668next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.