Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,445cataloged exploits
34,432CVEs with public exploitation
24,695lab-tested
21,497 exploits
ReferênciaVexDay Proof
Apple Safari - RSS 'feed://' Buffer Overflow via libxml2 (PoC)
CVE-2008-3529doswindows
Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-de
28RISK
open
ReferênciaVexDay Proof
Star Articles 6.0 - Arbitrary File Upload
CVE-2008-7076webappsphp
Unrestricted file upload vulnerability in user.modify.profile.php in Kalptaru Infotech Ltd. Star Articles 6.0 allows rem
23RISK
open
Referência
CVE-2015-3313
SQL injection vulnerability in WordPress Community Events plugin before 1.4.
23RISK
open
Referência
CVE-2015-3313
SQL injection vulnerability in WordPress Community Events plugin before 1.4.
23RISK
open
Referência
CVE-2014-8393
DLL Hijacking vulnerability in CorelDRAW X7, Corel Photo-Paint X7, Corel PaintShop Pro X7, Corel Painter 2015, and Corel
23RISK
open
Referência
CVE-2006-2152
PHP remote file inclusion vulnerability in admin/addentry.php in phpBB Advanced Guestbook 2.4.0 and earlier, when regist
23RISK
open
Referência
CVE-2017-13262
In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing length decrement operation. Th
23RISK
open
Referência
CVE-2017-13262
In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing length decrement operation. Th
23RISK
open
ReferênciaVexDay Proof
SysInfo 1.21 - 'sysinfo.cgi' Remote Command Execution
CVE-2006-1831webappscgi
Direct static code injection vulnerability in sysinfo.cgi in sysinfo 1.21 and possibly other versions before 2.25 allows
23RISK
open
ReferênciaVexDay Proof
Advanced Guestbook 2.4.0 - 'phpBB' File Inclusion
CVE-2006-2152webappsphp
PHP remote file inclusion vulnerability in admin/addentry.php in phpBB Advanced Guestbook 2.4.0 and earlier, when regist
23RISK
open
ReferênciaVexDay Proof
Simple Web Content Management System - SQL Injection
CVE-2007-0093webappsphp
SQL injection vulnerability in page.php in Simple Web Content Management System allows remote attackers to execute arbit
23RISK
open
Referência
CVE-2018-8532
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious
28RISK
open
Referência
CVE-2017-14087
A Host Header Injection vulnerability in Trend Micro OfficeScan XG (12.0) may allow an attacker to spoof a particular Ho
23RISK
open
Referência
CVE-2017-14087
A Host Header Injection vulnerability in Trend Micro OfficeScan XG (12.0) may allow an attacker to spoof a particular Ho
23RISK
open
Referência
CVE-2012-0276
Multiple heap-based buffer overflows in XnView before 1.99 allow remote attackers to cause a denial of service (applicat
23RISK
open
Referência
CVE-2012-0276
Multiple heap-based buffer overflows in XnView before 1.99 allow remote attackers to cause a denial of service (applicat
23RISK
open
Referência
CVE-2010-1930
Off-by-one error in Novell iManager 2.7, 2.7.3, and 2.7.3 FTF2 allows remote attackers to cause a denial of service (dae
23RISK
open
ReferênciaVexDay Proof
OllyDBG 1.10 and ImpREC 1.7f - Export Name Buffer Overflow
CVE-2008-3148localwindows
Stack-based buffer overflow in (1) OllyDBG 1.10 and (2) ImpREC 1.7f allows user-assisted attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
Nokia N95-8 browser - 'setAttributeNode' Method Crash
CVE-2009-0649doshardware
The web browser in Symbian OS on the Nokia N95 cell phone allows remote attackers to cause a denial of service (crash) v
23RISK
open
Referência
CVE-2008-1436
Microsoft Windows XP Professional SP2, Vista, and Server 2003 and 2008 does not properly assign activities to the (1) Ne
35RISK
open
Referência
CVE-2020-27930
CVE-2020-27930HIGHunder attack
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, wat
76RISK
open
Referência
CVE-2014-8835
The xpc_data_get_bytes function in libxpc in Apple OS X before 10.10.2 does not verify that a dictionary's Attributes ke
23RISK
open
Referência
CVE-2014-8835
The xpc_data_get_bytes function in libxpc in Apple OS X before 10.10.2 does not verify that a dictionary's Attributes ke
23RISK
open
Referência
CVE-2016-10504
Heap-based buffer overflow vulnerability in the opj_mqc_byteout function in mqc.c in OpenJPEG before 2.2.0 allows remote
23RISK
open
Referência
WordPress Plugin WooCommerce CardGate Payment Gateway 3.1.15 - Payment Process Bypass
CVE-2020-8819webappsphp
An issue was discovered in the CardGate Payments plugin through 3.1.15 for WooCommerce. Lack of origin authentication in
23RISK
open
Referência
CVE-2022-24263
Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-m
23RISK
open
Referência
CVE-2018-8533
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing malicious X
28RISK
open
Referência
CVE-2010-3135
Untrusted search path vulnerability in Cisco Packet Tracer 5.2 allows local users, and possibly remote attackers, to exe
23RISK
open
Referência
CVE-2017-10682
SQL injection vulnerability in the administrative backend in Piwigo through 2.9.1 allows remote users to execute arbitra
23RISK
open
Referência
CVE-2016-9332
An issue was discovered in Moxa SoftCMS versions prior to Version 1.6. Moxa SoftCMS Webserver does not properly validate
23RISK
open
previouspage 163 / 717next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.