Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,445cataloged exploits
34,432CVEs with public exploitation
24,695lab-tested
21,497 exploits
Referência
CVE-2009-4992
SQL injection vulnerability in paidbanner.php in LM Starmail Paidmail 2.0 allows remote attackers to execute arbitrary S
23RISK
open
Referência
CVE-2018-7737
In Z-BlogPHP 1.5.1.1740, there is Web Site physical path leakage, as demonstrated by admin_footer.php or admin_footer.ph
23RISK
open
ReferênciaVexDay Proof
Joomla! Component JContentSubscription 1.5.8 - Multiple Remote File Inclusions
CVE-2007-5407webappsphp
Multiple PHP remote file inclusion vulnerabilities in the JContentSubscription (com_jcs) 1.5.8 component for Joomla! all
35RISK
open
ReferênciaVexDay Proof
Mms Gallery PHP 1.0 - 'id' Remote File Disclosure
CVE-2007-6323webappsphp
Multiple directory traversal vulnerabilities in MMS Gallery PHP 1.0 allow remote attackers to read arbitrary files via a
23RISK
open
ReferênciaVexDay Proof
Active Test 2.1 - 'QuizID' Blind SQL Injection
CVE-2008-5958webappsasp
Multiple SQL injection vulnerabilities in Active Test 2.1 allow remote attackers to execute arbitrary SQL commands via t
23RISK
open
Referência
CVE-2012-3579
Symantec Messaging Gateway (SMG) before 10.0 has a default password for an unspecified account, which makes it easier fo
50RISK
open
ReferênciaVexDay Proof
GeoVision LiveAudio - ActiveX Remote Freed-Memory Access
CVE-2009-1092remotewindows
Use-after-free vulnerability in the LIVEAUDIO.LiveAudioCtrl.1 ActiveX control in LIVEAU~1.OCX 7.0 for GeoVision DVR syst
23RISK
open
Referência
CVE-2014-3225
Absolute path traversal vulnerability in the web interface in Cobbler 2.4.x through 2.6.x allows remote authenticated us
23RISK
open
Referência
CVE-2014-3225
Absolute path traversal vulnerability in the web interface in Cobbler 2.4.x through 2.6.x allows remote authenticated us
23RISK
open
Referência
CVE-2017-17111
Posty Readymade Classifieds Script 1.0 allows an attacker to inject SQL commands via a listings.php?catid= or ads-detail
23RISK
open
Referência
CVE-2017-17111
Posty Readymade Classifieds Script 1.0 allows an attacker to inject SQL commands via a listings.php?catid= or ads-detail
23RISK
open
Referência
CVE-2010-0718
Buffer overflow in Microsoft Windows Media Player 9 and 11.0.5721.5145 allows remote attackers to cause a denial of serv
23RISK
open
Referência
CVE-2004-1444
Directory traversal vulnerability in Roundup 0.6.4 and earlier allows remote attackers to view arbitrary files via .. (d
23RISK
open
Referência
CVE-2017-10309
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affecte
23RISK
open
Referência
CVE-2013-1606
Buffer overflow in the ubnt-streamer RTSP service on the Ubiquiti UBNT AirCam with airVision firmware before 1.1.6 allow
28RISK
open
Referência
CVE-2015-8357
Directory traversal vulnerability in the bitrix.xscan module before 1.0.4 for Bitrix allows remote authenticated users t
23RISK
open
Referência
CVE-2010-4051
The regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows c
35RISK
open
Referência
CVE-2015-8357
Directory traversal vulnerability in the bitrix.xscan module before 1.0.4 for Bitrix allows remote authenticated users t
23RISK
open
Referência
CVE-2012-5329
Buffer overflow in TYPSoft FTP Server 1.1 allows remote authenticated users to cause a denial of service (application cr
23RISK
open
Referência
CVE-2017-8311
Potential heap based buffer overflow in ParseJSS in VideoLAN VLC before 2.2.5 due to skipping NULL terminator in an inpu
23RISK
open
ReferênciaVexDay Proof
WebYep 1.1.9 - 'webyep_sIncludePath' File Inclusion
CVE-2006-5220webappsphp
Multiple PHP remote file inclusion vulnerabilities in WebYep 1.1.9, when register_globals is enabled, allow remote attac
23RISK
open
ReferênciaVexDay Proof
MangoBery CMS 0.5.5 - 'quotes.php' Remote File Inclusion
CVE-2007-1837webappsphp
Multiple PHP remote file inclusion vulnerabilities in MangoBery CMS 0.5.5 allow remote attackers to execute arbitrary PH
23RISK
open
ReferênciaVexDay Proof
ActSoft DVD-Tools - 'dvdtools.ocx' Remote Buffer Overflow (PoC)
CVE-2007-0976doswindows
Buffer overflow in the ActSoft DVD-Tools ActiveX control (dvdtools.ocx) allows remote attackers to execute arbitrary cod
23RISK
open
ReferênciaVexDay Proof
LeadTools Raster - Dialog File_D Object Remote Buffer Overflow (PoC)
CVE-2007-2946doswindows
Buffer overflow in a certain ActiveX control in LeadTools Raster Dialog File_D Object (LTRDFD14e.DLL) 14.5.0.44 allows r
23RISK
open
ReferênciaVexDay Proof
HP Digital Imaging 'hpqxml.dll 2.0.0.133' - Arbitrary Data Write
CVE-2007-3487remotewindows
Absolute path traversal in a certain ActiveX control in hpqxml.dll 2.0.0.133 in Hewlett-Packard (HP) Photo Digital Imagi
23RISK
open
ReferênciaVexDay Proof
Alcatel OmniPCX Office 210/061.1 - Remote Command Execution
CVE-2008-1331webappscgi
cgi-data/FastJSData.cgi in OmniPCX Office with Internet Access services OXO210 before 210/091.001, OXO600 before 610/014
23RISK
open
ReferênciaVexDay Proof
PHPStore Car Dealers - Arbitrary File Upload
CVE-2008-6929webappsphp
Unrestricted file upload vulnerability in PHPStore Auto Classifieds allows remote authenticated users to execute arbitra
23RISK
open
ReferênciaVexDay Proof
WOW Web On Windows ActiveX Control 2 - Remote Code Execution
CVE-2009-0389remotewindows
Multiple insecure method vulnerabilities in the Web On Windows (WOW) ActiveX control in WOW ActiveX 2 allow remote attac
23RISK
open
ReferênciaVexDay Proof
Mozilla Firefox 3.0.10 - 'KEYGEN' Remote Denial of Service
CVE-2009-1828dosmultiple
Mozilla Firefox 3.0.10 allows remote attackers to cause a denial of service (infinite loop, application hang, and memory
23RISK
open
Referência
CVE-2014-0372
Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0
23RISK
open
previouspage 162 / 717next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.