Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,526cataloged exploits
34,478CVEs with public exploitation
24,695lab-tested
21,534 exploits
Referência
CVE-2009-4451
Unrestricted file upload vulnerability in upper.php in kandalf upper 0.1 allows remote attackers to execute arbitrary co
23RISK
open
Referência
CVE-2009-4819
Multiple unrestricted file upload vulnerabilities in upload.php in PHPhotoalbum allow remote attackers to execute arbitr
23RISK
open
Referência
CVE-2023-4173
mooSocial mooStore index cross site scripting
43RISK
open
Referência
CVE-2010-5028
SQL injection vulnerability in the JExtensions JE Job (com_jejob) component 1.0 for Joomla! allows remote attackers to e
38RISK
open
Referência
CVE-2015-1480
ZOHO ManageEngine ServiceDesk Plus (SDP) before 9.0 build 9031 allows remote authenticated users to obtain sensitive tic
23RISK
open
Referência
CVE-2015-1480
ZOHO ManageEngine ServiceDesk Plus (SDP) before 9.0 build 9031 allows remote authenticated users to obtain sensitive tic
23RISK
open
Referência
CVE-2015-2824
Multiple SQL injection vulnerabilities in the Simple Ads Manager plugin before 2.7.97 for WordPress allow remote attacke
23RISK
open
Referência
CVE-2015-2824
Multiple SQL injection vulnerabilities in the Simple Ads Manager plugin before 2.7.97 for WordPress allow remote attacke
23RISK
open
Referência
CVE-2010-1353
Directory traversal vulnerability in the LoginBox Pro (com_loginbox) component for Joomla! allows remote attackers to re
43RISK
open
Referência
CVE-2009-2334
wp-admin/admin.php in WordPress and WordPress MU before 2.8.1 does not require administrative authentication to access t
23RISK
open
Referência
CVE-2017-13798
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RISK
open
Referência
CVE-2014-4034
SQL injection vulnerability in zero_view_article.php in ZeroCMS 1.0 allows remote attackers to execute arbitrary SQL com
23RISK
open
Referência
CVE-2014-4034
SQL injection vulnerability in zero_view_article.php in ZeroCMS 1.0 allows remote attackers to execute arbitrary SQL com
23RISK
open
Referência
CVE-2014-4034
SQL injection vulnerability in zero_view_article.php in ZeroCMS 1.0 allows remote attackers to execute arbitrary SQL com
23RISK
open
Referência
CVE-2015-1578
Multiple open redirect vulnerabilities in u5CMS before 3.9.4 allow remote attackers to redirect users to arbitrary web s
23RISK
open
Referência
CVE-2015-7986
The index server (hdbindexserver) in SAP HANA 1.00.095 allows remote attackers to execute arbitrary code or cause a deni
23RISK
open
ReferênciaVexDay Proof
Flip 3.0 - Remote Password Hash Disclosure
CVE-2007-5063webappsphp
Adam Scheinberg Flip 3.0 and earlier stores sensitive information under the web root with insufficient access control, w
23RISK
open
ReferênciaVexDay Proof
Rayzz Script 2.0 - Local/Remote File Inclusion
CVE-2007-6230webappsphp
Directory traversal vulnerability in common/classes/class_HeaderHandler.lib.php in Rayzz Script 2.0 allows remote attack
23RISK
open
ReferênciaVexDay Proof
Flat PHP Board 1.2 - Multiple Vulnerabilities
CVE-2007-6395webappsphp
Flat PHP Board 1.2 and earlier stores sensitive information under the web root with insufficient access control, which a
23RISK
open
ReferênciaVexDay Proof
Power Editor 2.0 - Remote File Disclosure / Edit
CVE-2008-2115webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in editor.php in ScriptsEZ.net Power Editor 2.0 allow remote attacke
23RISK
open
ReferênciaVexDay Proof
TmaxSoft JEUS - Alternate Data Streams File Disclosure
CVE-2008-6528remotewindows
NTFS TmaxSoft JEUS 5 before Fix 26 allows remote attackers to read the source code for scripts by appending ::$DATA to t
23RISK
open
Referência
CVE-2014-2579
Multiple cross-site request forgery (CSRF) vulnerabilities in XCloner Standalone 3.5 and earlier allow remote attackers
23RISK
open
Referência
CVE-2015-1723
Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista S
23RISK
open
Referência
CVE-2026-6143
farion1231 cc-switch ProxyServer server.rs cross-domain policy
33RISK
open
Referência
CVE-2012-1025
Absolute path traversal vulnerability in file in Enigma2 Webinterface 1.6.0 through 1.6.8, 1.6rc3, and 1.7.0 allows remo
23RISK
open
Referência
CVE-2009-2382
admin.php in phpMyBlockchecker 1.0.0055 allows remote attackers to bypass authentication and gain administrative access
23RISK
open
Referência
CVE-2023-38501
copyparty vulnerable to reflected cross-site scripting via k304 parameter
48RISK
open
Referência
CVE-2025-11418
Tenda CH22 HTTP Request AdvSetWrlsafeset formWrlsafeset stack-based overflow
48RISK
open
Referência
CVE-2018-18762
SaltOS 3.1 r8126 contains a database download vulnerability.
23RISK
open
Referência
CVE-2018-18762
SaltOS 3.1 r8126 contains a database download vulnerability.
23RISK
open
previouspage 189 / 718next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.