Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,432cataloged exploits
34,424CVEs with public exploitation
24,695lab-tested
21,493 exploits
Referência
CVE-2010-2857
Directory traversal vulnerability in the Music Manager component for Joomla! allows remote attackers to read arbitrary f
38RISK
open
Referência
CVE-2010-2857
Directory traversal vulnerability in the Music Manager component for Joomla! allows remote attackers to read arbitrary f
38RISK
open
Referência
CVE-2010-2680
Directory traversal vulnerability in the JExtensions JE Section/Property Finder (jesectionfinder) component for Joomla!
38RISK
open
Referência
CVE-2018-0826
Windows Storage Services in Windows 10 versions 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, versi
23RISK
open
Referência
CVE-2021-35956
Stored cross-site scripting (XSS) in the embedded webserver of AKCP sensorProbe before SP480-20210624 enables remote aut
23RISK
open
Referência
CVE-2009-3859
Buffer overflow in eEye Retina WiFi Scanner 1.0.8.68, as used in Retina Network Security Scanner 5.10.14, allows user-as
28RISK
open
Referência
CVE-2010-2680
Directory traversal vulnerability in the JExtensions JE Section/Property Finder (jesectionfinder) component for Joomla!
38RISK
open
ReferênciaVexDay Proof
Softerra Time-Assistant 6.2 - 'inc_dir' Remote File Inclusion
CVE-2007-1787webappsphp
Multiple PHP remote file inclusion vulnerabilities in lib/timesheet.class.php in Softerra Time-Assistant 6.2 and earlier
23RISK
open
ReferênciaVexDay Proof
Move Networks Quantum Streaming Player Control - Remote Buffer Overflow
CVE-2008-1044remotewindows
Stack-based buffer overflow in the Quantum Streaming Player (Quantum Streaming IE Player) ActiveX control (aka QSP2IE.QS
23RISK
open
Referência
CVE-2006-2315
PHP remote file inclusion vulnerability in session.inc.php in ISPConfig 2.2.2 and earlier allows remote attackers to exe
23RISK
open
Referência
CVE-2024-6460
Grow by Tradedoubler <= 2.0.21 - Unauthenticated LFI
63RISK
open
Referência
CVE-2015-7235
Multiple SQL injection vulnerabilities in dex_reservations.php in the CP Reservation Calendar plugin before 1.1.7 for Wo
23RISK
open
Referência
CVE-2018-20326
ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have XSS via the cgi-bin/webproc?getpage
23RISK
open
Referência
CVE-2018-20326
ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have XSS via the cgi-bin/webproc?getpage
23RISK
open
Referência
CVE-2009-2736
Static code injection vulnerability in admin.php in sun-jester OpenNews 1.0 allows remote authenticated administrators t
23RISK
open
Referência
CVE-2009-4372
AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows
23RISK
open
Referência
CVE-2015-6008
install.php in Web Reference Database (aka refbase) through 0.9.6 allows remote attackers to execute arbitrary commands
23RISK
open
Referência
CVE-2015-3315
Automatic Bug Reporting Tool (ABRT) allows local users to read, change the ownership of, or have other unspecified impac
38RISK
open
Referência
CVE-2015-6100
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Wi
23RISK
open
Referência
CVE-2017-15374
Shopware v5.2.5 - v5.3 is vulnerable to cross site scripting in the customer and order section of the content management
23RISK
open
Referência
CVE-2009-2961
Stack-based buffer overflow in Thaddy de Konng KOL Player 1.0 allows remote attackers to cause a denial of service (cras
23RISK
open
Referência
CVE-2009-3947
Buffer overflow in the FTP service on the Tandberg MXP F7.0 allows remote attackers to cause a denial of service (proces
23RISK
open
Referência
CVE-2009-4759
Buffer overflow in BrotherSoft BMXPlay 0.4.4b allows remote attackers to cause a denial of service (application crash) o
23RISK
open
ReferênciaVexDay Proof
Winamp 5.21 - '.Midi' File Header Handling Buffer Overflow (PoC)
CVE-2006-3228doswindows
Buffer overflow in in_midi.dll for WinAmp 2.90 up to 5.23, including 5.21, allows remote attackers to execute arbitrary
28RISK
open
ReferênciaVexDay Proof
PHP 5.x COM - Safe Mode / disable_functions Bypass
CVE-2007-5653localwindows
The Component Object Model (COM) functions in PHP 5.x on Windows do not follow safe_mode and disable_functions restricti
23RISK
open
ReferênciaVexDay Proof
dBpowerAMP Audio Player 2 - '.m3u' Buffer Overflow (PoC)
CVE-2008-0661doswindows
Buffer overflow in dBpowerAMP Audio Player Release 2 allows remote attackers to execute arbitrary code via a .M3U file w
23RISK
open
ReferênciaVexDay Proof
Alstrasoft SendIt Pro - Arbitrary File Upload
CVE-2008-6932webappsphp
Unrestricted file upload vulnerability in submit_file.php in AlstraSoft SendIt Pro allows remote attackers to execute ar
23RISK
open
ReferênciaVexDay Proof
Simple PHP News 1.0 - Remote Command Execution
CVE-2009-0643webappsphp
Static code injection vulnerability in post.php in Simple PHP News 1.0 final allows remote attackers to inject arbitrary
23RISK
open
ReferênciaVexDay Proof
eZip Wizard 3.0 - Local Stack Buffer Overflow (PoC) (SEH)
CVE-2009-1059doswindows
Stack-based buffer overflow in Trident PowerZip 7.2 might allow remote attackers to execute arbitrary code via a crafted
23RISK
open
Referência
CVE-2010-1299
Multiple PHP remote file inclusion vulnerabilities in DynPG CMS 4.1.0, and possibly earlier, when magic_quotes_gpc is di
28RISK
open
previouspage 160 / 717next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.