Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,526cataloged exploits
34,478CVEs with public exploitation
24,695lab-tested
21,497 exploits
Referência
CVE-2005-0575
Buffer overflow in Stormy Studios Knet 1.04c and earlier allows remote attackers to cause a denial of service and possib
23RISK
open
ReferênciaVexDay Proof
C-News 1.0.1 - 'path' Remote File Inclusion
CVE-2006-4629webappsphp
PHP remote file inclusion vulnerability in affichage/commentaires.php in C-News.fr C-News 1.0.1 and earlier allows remot
23RISK
open
ReferênciaVexDay Proof
Limbo CMS Module event 1.0 - Remote File Inclusion
CVE-2006-6800webappsphp
PHP remote file inclusion in eventcal/mod_eventcal.php in the event module 1.0 for Limbo CMS allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
Transmit.app 3.5.5 - 'ftps://' URL Handler Heap Buffer Overflow (PoC)
CVE-2007-0020dososx
Heap-based buffer overflow in the SFTP protocol handler for Panic Transmit (Transmit.app) up to 3.5.5 allows remote atta
23RISK
open
ReferênciaVexDay Proof
Mambo Component nfnaddressbook 0.4 - Remote File Inclusion
CVE-2007-1596webappsphp
Multiple PHP remote file inclusion vulnerabilities in the NFN Address Book (com_nfn_addressbook) 0.4 component for Mambo
23RISK
open
Referência
CVE-2016-5840
hotfix_upload.cgi in Trend Micro Deep Discovery Inspector (DDI) 3.7, 3.8 SP1 (3.81), and 3.8 SP2 (3.82) allows remote ad
23RISK
open
ReferênciaVexDay Proof
phpMyPortal 3.0.0 RC3 - GLOBALS[CHEMINMODULES] Remote File Inclusion
CVE-2007-2594webappsphp
PHP remote file inclusion vulnerability in inc/articles.inc.php in phpMyPortal 3.0.0 RC3 allows remote attackers to exec
23RISK
open
ReferênciaVexDay Proof
PHP 'Perl' Extension - 'Safe_mode' Bypass
CVE-2007-4596localwindows
The perl extension in PHP does not follow safe_mode restrictions, which allows context-dependent attackers to execute ar
23RISK
open
ReferênciaVexDay Proof
Charrays CMS 0.9.3 - Multiple Remote File Inclusions
CVE-2007-6179webappsphp
Multiple PHP remote file inclusion vulnerabilities in Charray's CMS 0.9.3 allow remote attackers to execute arbitrary PH
23RISK
open
ReferênciaVexDay Proof
Maian Links 3.1 - Insecure Cookie Handling
CVE-2008-3319webappsphp
admin/index.php in Maian Links 3.1 and earlier allows remote attackers to bypass authentication and gain administrative
23RISK
open
ReferênciaVexDay Proof
Dokuwiki 2009-02-14 - Local File Inclusion
CVE-2009-1960webappsphp
inc/init.php in DokuWiki 2009-02-14, rc2009-02-06, and rc2009-01-30, when register_globals is enabled, allows remote att
28RISK
open
ReferênciaVexDay Proof
Maian Uploader 4.0 - Insecure Cookie Handling
CVE-2008-3321webappsphp
admin/index.php in Maian Uploader 4.0 and earlier allows remote attackers to bypass authentication and gain administrati
23RISK
open
Referência
CVE-2015-3107
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows
35RISK
open
Referência
CVE-2016-5764
Micro Focus Rumba FTP 4.X client buffer overflow makes it possible to corrupt the stack and allow arbitrary code executi
23RISK
open
Referência
CVE-2012-1670
admin/index.php in PHP Grade Book before 1.9.5 BETA allows remote attackers to read the database via a SaveSQL action.
23RISK
open
Referência
CVE-2009-4541
Multiple PHP remote file inclusion vulnerabilities in IsolSoft Support Center 2.5 allow remote attackers to execute arbi
23RISK
open
Referência
CVE-2018-9035
CSV Injection vulnerability in ExportToCsvUtf8.php of the Contact Form 7 to Database Extension plugin 2.10.32 for WordPr
23RISK
open
ReferênciaVexDay Proof
Oracle 10g - MDSYS.SDO_TOPO_DROP_FTBL SQL Injection (Metasploit)
CVE-2008-3979localmultiple
Unspecified vulnerability in the Oracle Spatial component in Oracle Database 10.1.0.5 and 10.2.0.2 allows remote authent
50RISK
open
Referência
CVE-2014-4138
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory co
35RISK
open
Referência
CVE-2014-4138
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory co
35RISK
open
Referência
CVE-2018-1133
An issue was discovered in Moodle 3.x. A Teacher creating a Calculated question can intentionally cause remote code exec
35RISK
open
Referência
CVE-2015-2169
Cross-site scripting (XSS) vulnerability in Zoho ManageEngine AssetExplorer 6.1 service pack 6112 allows remote attacker
23RISK
open
Referência
CVE-2015-2169
Cross-site scripting (XSS) vulnerability in Zoho ManageEngine AssetExplorer 6.1 service pack 6112 allows remote attacker
23RISK
open
ReferênciaVexDay Proof
WEBInsta MM 1.3e - 'cabsolute_path' Remote File Inclusion
CVE-2006-4209webappsphp
PHP remote file inclusion vulnerability in install3.php in WEBInsta Mailing List Manager 1.3e allows remote attackers to
23RISK
open
Referência
CVE-2016-4230
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows
35RISK
open
ReferênciaVexDay Proof
Konqueror 3.5.9 - 'font color' Remote Crash
CVE-2008-4514doslinux
The HTML parser in KDE Konqueror 3.5.9 allows remote attackers to cause a denial of service (application crash) via a fo
23RISK
open
Referência
CVE-2014-5084
A Command Execution vulnerability exists in Sphider Pro 3.2 due to insufficient sanitization of fwrite, which could let
23RISK
open
Referência
CVE-2012-4889
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine Firewall Analyzer 7.2 allow remote attackers to inje
38RISK
open
Referência
CVE-2009-5134
Buffer overflow in the "create torrent dialog" functionality in uTorrent 1.8.3 build 15772, and possibly other versions
23RISK
open
Referência
CVE-2017-0245
The kernel-mode drivers in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1 and Windows Server 2012 Gold allow a local
23RISK
open
previouspage 177 / 717next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.