Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,526cataloged exploits
34,478CVEs with public exploitation
24,695lab-tested
21,534 exploits
Referência
CVE-2014-5521
plugins/useradmin/fingeruser.php in XRMS CRM, possibly 1.99.2, allows remote authenticated users to execute arbitrary co
23RISK
open
ReferênciaVexDay Proof
ViArt CMS/Shop/Helpdesk 3.3.2 - Remote File Inclusion
CVE-2007-6347webappsphp
PHP remote file inclusion vulnerability in blocks/block_site_map.php in ViArt (1) CMS 3.3.2, (2) HelpDesk 3.3.2, (3) Sho
23RISK
open
Referência
CVE-2016-2203
The management console on Symantec Messaging Gateway (SMG) Appliance devices before 10.6.1 allows local users to discove
38RISK
open
Referência
CVE-2016-2203
The management console on Symantec Messaging Gateway (SMG) Appliance devices before 10.6.1 allows local users to discove
38RISK
open
ReferênciaVexDay Proof
5 star review - Cross-Site Scripting / SQL Injection
CVE-2008-3779webappsphp
Cross-site scripting (XSS) vulnerability in search/index.php in Five Star Review Script allows remote attackers to injec
23RISK
open
ReferênciaVexDay Proof
MW6 PDF417 - ActiveX 'MW6PDF417.dll' Remote Insecure Method
CVE-2008-4926remotewindows
Multiple insecure method vulnerabilities in MW6 Technologies PDF417 ActiveX control (MW6PDF417Lib.PDF417, MW6PDF417.dll)
23RISK
open
Referência
CVE-2014-5381
Grand MA 300 allows a brute-force attack on the PIN.
23RISK
open
Referência
CVE-2010-0672
SQL injection vulnerability in index.php in WSN Guest 1.02 allows remote attackers to execute arbitrary SQL commands via
23RISK
open
Referência
CVE-2017-0175
The Windows kernel in Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows authenticated attackers to obtain sen
23RISK
open
Referência
CVE-2010-3136
Untrusted search path vulnerability in Skype 4.2.0.169 and earlier allows local users, and possibly remote attackers, to
23RISK
open
ReferênciaVexDay Proof
Kaqoo Auction - 'install_root' Multiple Remote File Inclusions
CVE-2007-1790webappsphp
Multiple PHP remote file inclusion vulnerabilities in Kaqoo Auction Software Free Edition allow remote attackers to exec
23RISK
open
Referência
CVE-2015-2527
The process-initialization implementation in win32k.sys in the kernel-mode drivers in Microsoft Windows 8, Windows 8.1,
23RISK
open
Referência
CVE-2018-5715
phprint.php in SugarCRM 3.5.1 has XSS via a parameter name in the query string (aka a $key variable).
38RISK
open
Referência
CVE-2014-100029
Multiple directory traversal vulnerabilities in class/session.php in Ganesha Digital Library (GDL) 4.2 allow remote atta
23RISK
open
Referência
CVE-2017-2365
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS
23RISK
open
Referência
CVE-2010-3468
Directory traversal vulnerability in fileManager.cfc in Mura CMS 5.1 before 5.1.498 and 5.2 before 5.2.2809, and Sava CM
23RISK
open
Referência
CVE-2017-7018
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISK
open
Referência
CVE-2019-16679
Gila CMS before 1.11.1 allows admin/fm/?f=../ directory traversal, leading to Local File Inclusion.
23RISK
open
ReferênciaVexDay Proof
RGameScript Pro - 'page.php?id' Remote File Inclusion
CVE-2007-3980webappsphp
PHP remote file inclusion vulnerability in page.php in RCMS Pro RGameScript Pro allows remote attackers to execute arbit
23RISK
open
ReferênciaVexDay Proof
EasyMail MessagePrinter Object - 'emprint.dll 6.0.1.0' Remote Buffer Overflow
CVE-2007-5070remotewindows
Heap-based buffer overflow in the EasyMailMessagePrinter ActiveX control in emprint.DLL 6.0.1.0 in the Quiksoft EasyMail
23RISK
open
ReferênciaVexDay Proof
BS.Player 2.27 Build 959 - '.srt' File Buffer Overflow (PoC)
CVE-2008-6583doswindows
Buffer overflow in BS.player 2.27 build 959 allows remote attackers to cause a denial of service (crash) and possibly ex
23RISK
open
ReferênciaVexDay Proof
EZContents CMS 2.0.3 - Multiple Local File Inclusions
CVE-2008-7054webappsphp
Multiple directory traversal vulnerabilities in ezContents 2.0.3 allow remote attackers to include and execute arbitrary
23RISK
open
ReferênciaVexDay Proof
OpenX 2.6.3 - 'MAX_type' Local File Inclusion
CVE-2009-0291webappsphp
Directory traversal vulnerability in fc.php in OpenX 2.6.3 allows remote attackers to include and execute arbitrary file
23RISK
open
Referência
CVE-2010-0672
SQL injection vulnerability in index.php in WSN Guest 1.02 allows remote attackers to execute arbitrary SQL commands via
23RISK
open
Referência
CVE-2014-4688
pfSense before 2.1.4 allows remote authenticated users to execute arbitrary commands via (1) the hostname value to diag_
23RISK
open
Referência
CVE-2011-4810
Multiple directory traversal vulnerabilities in WHMCompleteSolution (WHMCS) 3.x and 4.x allow remote attackers to read a
23RISK
open
ReferênciaVexDay Proof
UeberProject 1.0 - '/login/secure.php' Remote File Inclusion
CVE-2006-5539webappsphp
PHP remote file inclusion vulnerability in login/secure.php in UeberProject Management System 1.0 and earlier allows rem
23RISK
open
ReferênciaVexDay Proof
Frequency Clock 0.1b - 'securelib' Remote File Inclusion
CVE-2007-2936webappsphp
Multiple PHP remote file inclusion vulnerabilities in Frequency Clock 0.1b (Beta 0.1) allow remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
AuraCMS 2.1 - Remote File Attachment / Local File Inclusion
CVE-2007-4905webappsphp
Unrestricted file upload vulnerability in mod/contak.php in AuraCMS 2.1 allows remote attackers to upload and execute ar
23RISK
open
Referência
CVE-2013-6366
The Groovy script console in VMware Hyperic HQ 4.6.6 allows remote authenticated administrators to execute arbitrary cod
23RISK
open
previouspage 183 / 718next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.