Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

74,469cataloged exploits
34,020CVEs with public exploitation
19,614lab-tested
21,340 exploits
Referência
Ericsson Network Location MPS GMPC21 - Remote Code Execution (RCE) (Metasploit)
In Ericsson Network Location before 2021-07-31, it is possible for an authenticated attacker to inject commands via file
23RISK
open
ReferênciaVexDay Proof
Simple PHP Blog 0.4.7.1 - Remote Command Execution
CVE-2006-1243webappsphp
Directory traversal vulnerability in install05.php in Simple PHP Blog (SPB) 0.4.7.1 and earlier allows remote attackers
23RISK
open
Referência
CVE-2009-4985
SQL injection vulnerability in browse.php in Accessories Me PHP Affiliate Script 1.4 allows remote attackers to execute
23RISK
open
Referência
CVE-2010-4231
Directory traversal vulnerability in the web-based administration interface on the Camtron CMNC-200 Full HD IP Camera an
43RISK
open
Referência
CVE-2020-9467
Piwigo 2.10.1 has stored XSS via the file parameter in a /ws.php request because of the pwg.images.setInfo function.
28RISK
open
Referência
CVE-2017-17876
Biometric Shift Employee Management System 3.0 allows remote attackers to bypass intended file-read restrictions via a u
23RISK
open
Referência
CVE-2020-14461
Zyxel Armor X1 WAP6806 1.00(ABAL.6)C0 devices allow Directory Traversal via the images/eaZy/ URI.
23RISK
open
Referência
CVE-2022-26521
Abantecart through 1.3.2 allows remote authenticated administrators to execute arbitrary code by uploading an executable
23RISK
open
Referência
CVE-2016-10043
An issue was discovered in Radisys MRF Web Panel (SWMS) 9.0.1. The MSM_MACRO_NAME POST parameter in /swms/ms.cgi was dis
23RISK
open
Referência
CVE-2012-1010
Unrestricted file upload vulnerability in actions.php in the AllWebMenus plugin before 1.1.8 for WordPress allows remote
23RISK
open
Referência
CVE-2022-4063
InPost Gallery < 2.1.4.1 - Unauthenticated LFI to RCE
63RISK
open
Referência
CVE-2026-10812
zilliztech GPTCache Cache Key pre.py BufferedReader.peek weak hash
28RISK
open
ReferênciaVexDay Proof
MiniBill 1.22b - config[plugin_dir] Remote File Inclusion
CVE-2006-4489webappsphp
Multiple PHP remote file inclusion vulnerabilities in MiniBill 2006-07-14 (1.2.2) allow remote attackers to execute arbi
23RISK
open
ReferênciaVexDay Proof
Fundanemt 2.2.0 - 'spellcheck.php' Remote Code Execution
CVE-2007-2935webappsphp
core/spellcheck/spellcheck.php in Fundanemt before 2.2.0.1 allows remote attackers to execute arbitrary commands via she
23RISK
open
Referência
CVE-2018-18793
School Event Management System 1.0 allows Arbitrary File Upload via event/controller.php?action=photos.
23RISK
open
Referência
CVE-2018-18793
School Event Management System 1.0 allows Arbitrary File Upload via event/controller.php?action=photos.
23RISK
open
Referência
CVE-2017-7041
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISK
open
Referência
CVE-2018-18924
The image-upload feature in ProjeQtOr 7.2.5 allows remote attackers to execute arbitrary code by uploading a .shtml file
23RISK
open
Referência
CVE-2010-3314
Cross-site scripting (XSS) vulnerability in login.php in EGroupware 1.4.001+.002; 1.6.001+.002 and possibly other versio
23RISK
open
Referência
CVE-2010-1722
Directory traversal vulnerability in the Online Market (com_market) component 2.x for Joomla! allows remote attackers to
38RISK
open
Referência
CVE-2010-1722
Directory traversal vulnerability in the Online Market (com_market) component 2.x for Joomla! allows remote attackers to
38RISK
open
Referência
CVE-2010-1474
Directory traversal vulnerability in the Sweety Keeper (com_sweetykeeper) component 1.5.x for Joomla! allows remote atta
38RISK
open
Referência
CVE-2010-1474
Directory traversal vulnerability in the Sweety Keeper (com_sweetykeeper) component 1.5.x for Joomla! allows remote atta
38RISK
open
Referência
CVE-2016-10277
An elevation of privilege vulnerability in the Motorola bootloader could enable a local malicious application to execute
23RISK
open
ReferênciaVexDay Proof
Shadowed Portal 5.599 - 'root' Remote File Inclusion
CVE-2006-4826webappsphp
PHP remote file inclusion vulnerability in bottom.php in Shadowed Portal 5.599 and earlier allows remote attackers to ex
23RISK
open
ReferênciaVexDay Proof
Mambo Component Security Images 3.0.5 - Remote File Inclusion
CVE-2006-5048webappsphp
Multiple PHP remote file inclusion vulnerabilities in Security Images (com_securityimages) component 3.0.5 and earlier f
23RISK
open
ReferênciaVexDay Proof
HSRS 1.0 - 'addcode.php' Remote File Inclusion
CVE-2006-6154webappsphp
PHP remote file inclusion vulnerability in addcode.php in HIOX Star Rating System Script (HSRS) 1.0 and earlier allows r
23RISK
open
ReferênciaVexDay Proof
Bubla 0.9.2 - 'bu_dir' Multiple Remote File Inclusions
CVE-2006-6867webappsphp
Multiple PHP remote file inclusion vulnerabilities in Vladimir Menshakov buratinable templator (aka bubla) 0.9.1 allow r
23RISK
open
ReferênciaVexDay Proof
Joomla! Component RSfiles 1.0.2 - 'path' File Download
CVE-2007-4504webappsphp
Directory traversal vulnerability in index.php in the RSfiles component (com_rsfiles) 1.0.2 and earlier for Joomla! allo
38RISK
open
ReferênciaVexDay Proof
FretsWeb 1.2 - Multiple Local File Inclusions
CVE-2009-2109webappsphp
Multiple directory traversal vulnerabilities in FretsWeb 1.2 allow remote attackers to read arbitrary files via director
23RISK
open
previouspage 159 / 712next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.