Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,526cataloged exploits
34,478CVEs with public exploitation
24,695lab-tested
21,497 exploits
ReferênciaVexDay Proof
Shadows Rising RPG 0.0.5b - Remote File Inclusion
CVE-2006-4329webappsphp
Multiple PHP remote file inclusion vulnerabilities in Shadows Rising RPG (Pre-Alpha) 0.0.5b and earlier allow remote att
23RISK
open
ReferênciaVexDay Proof
SendStudio 2004.14 - 'ROOTDIR' Remote File Inclusion
CVE-2007-1060webappsphp
Multiple PHP remote file inclusion vulnerabilities in Interspire SendStudio 2004.14 and earlier, when register_globals a
23RISK
open
ReferênciaVexDay Proof
Simple Discussion Board 0.1.0 - Remote File Inclusion
CVE-2006-4918webappsphp
Multiple PHP remote file inclusion vulnerabilities in Simple Discussion Board 0.1.0 allow remote attackers to execute ar
23RISK
open
ReferênciaVexDay Proof
Imageview 5.3 - 'fileview.php?album' Local File Inclusion
CVE-2007-2425webappsphp
Directory traversal vulnerability in fileview.php in Imageview 5.3 allows remote attackers to read arbitrary files via a
23RISK
open
ReferênciaVexDay Proof
CGX 20050314 - 'pathCGX' Remote File Inclusion
CVE-2007-2611webappsphp
Multiple PHP remote file inclusion vulnerabilities in CGX 20050314 allow remote attackers to execute arbitrary PHP code
23RISK
open
ReferênciaVexDay Proof
Downline Goldmine Builder - SQL Injection
CVE-2008-4178webappsphp
SQL injection vulnerability in tr.php in DownlineGoldmine Special Category Addon, Downline Builder Pro, New Addon, and D
23RISK
open
ReferênciaVexDay Proof
Autodesk DWF Viewer Control / LiveUpdate Module - Remote Code Execution
CVE-2008-4472remotewindows
The UpdateEngine class in the LiveUpdate ActiveX control (LiveUpdate16.DLL 17.2.56), as used in Revit Architecture 2009
23RISK
open
Referência
CVE-2019-19142
Intelbras WRN240 devices do not require authentication to replace the firmware via a POST request to the incoming/Firmwa
23RISK
open
Referência
CVE-2010-0287
Directory traversal vulnerability in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25b allows
28RISK
open
Referência
CVE-2022-34140
A stored cross-site scripting (XSS) vulnerability in /index.php?r=site%2Fsignup of Feehi CMS v2.1.1 allows attackers to
23RISK
open
Referência
CVE-2022-34140
A stored cross-site scripting (XSS) vulnerability in /index.php?r=site%2Fsignup of Feehi CMS v2.1.1 allows attackers to
23RISK
open
Referência
ManageEngine OpManager 12.4x - Privilege Escalation / Remote Command Execution (Metasploit)
CVE-2019-15104remotemultiple
An issue was discovered in Zoho ManageEngine OpManager through 12.4x. There is a SQL Injection vulnerability in jsp/NewT
23RISK
open
Referência
CVE-2012-3549
The SCTP implementation in FreeBSD 8.2 allows remote attackers to cause a denial of service (NULL pointer dereference an
23RISK
open
Referência
CVE-2021-27825
A directory traversal vulnerability on Mercury MAC1200R devices allows attackers to read arbitrary files via a web-stati
41RISK
open
Referência
CVE-2013-3956
The NICM.SYS kernel driver 3.1.11.0 in Novell Client 4.91 SP5 on Windows XP and Windows Server 2003; Novell Client 2 SP2
38RISK
open
Referência
CVE-2013-3956
The NICM.SYS kernel driver 3.1.11.0 in Novell Client 4.91 SP5 on Windows XP and Windows Server 2003; Novell Client 2 SP2
38RISK
open
Referência
CVE-2017-6805
Directory traversal vulnerability in the TFTP server in MobaXterm Personal Edition 9.4 allows remote attackers to read a
23RISK
open
Referência
CVE-2017-6805
Directory traversal vulnerability in the TFTP server in MobaXterm Personal Edition 9.4 allows remote attackers to read a
23RISK
open
Referência
CVE-2014-3004
The default configuration for the Xerces SAX Parser in Castor before 1.3.3 allows context-dependent attackers to conduct
23RISK
open
Referência
CVE-2017-17538
MikroTik v6.40.5 devices allow remote attackers to cause a denial of service via a flood of ICMP packets.
23RISK
open
ReferênciaVexDay Proof
nabopoll 1.2 - Remote Unprotected Admin Section
CVE-2007-0873webappsphp
nabopoll 1.1.2 allows remote attackers to bypass authentication and access certain administrative functionality via a di
23RISK
open
ReferênciaVexDay Proof
Zervit Web Server 0.02 - Remote Buffer Overflow (PoC)
CVE-2009-1353doswindows
Buffer overflow in the http_parse_hex function in libz/misc.c in Zervit Webserver 0.02 allows remote attackers to cause
23RISK
open
ReferênciaVexDay Proof
Downline Goldmine Category Addon - SQL Injection
CVE-2008-4178webappsphp
SQL injection vulnerability in tr.php in DownlineGoldmine Special Category Addon, Downline Builder Pro, New Addon, and D
23RISK
open
ReferênciaVexDay Proof
Downline Goldmine newdownlinebuilder - SQL Injection
CVE-2008-4178webappsphp
SQL injection vulnerability in tr.php in DownlineGoldmine Special Category Addon, Downline Builder Pro, New Addon, and D
23RISK
open
ReferênciaVexDay Proof
Downline Goldmine paidversion - SQL Injection
CVE-2008-4178webappsphp
SQL injection vulnerability in tr.php in DownlineGoldmine Special Category Addon, Downline Builder Pro, New Addon, and D
23RISK
open
Referência
CVE-2014-5116
The cairo_image_surface_get_data function in Cairo 1.10.2, as used in GTK+ and Wireshark, allows context-dependent attac
23RISK
open
Referência
CVE-2019-10273
Information leakage vulnerability in the /mc login page in ManageEngine ServiceDesk Plus 9.3 software allows authenticat
23RISK
open
Referência
CVE-2019-10273
Information leakage vulnerability in the /mc login page in ManageEngine ServiceDesk Plus 9.3 software allows authenticat
23RISK
open
Referência
CVE-2017-15012
OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 does not properly validate the i
23RISK
open
Referência
CVE-2005-0575
Buffer overflow in Stormy Studios Knet 1.04c and earlier allows remote attackers to cause a denial of service and possib
23RISK
open
previouspage 176 / 717next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.