Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,580cataloged exploits
34,506CVEs with public exploitation
24,695lab-tested
21,534 exploits
Referência
CVE-2009-3364
Stack-based buffer overflow in FTPShell Client 4.1 RC2 allows remote FTP servers to execute arbitrary code via a long re
23RISK
open
Referência
CVE-2016-0007
The sandbox implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8,
23RISK
open
Referência
CVE-2016-0007
The sandbox implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8,
23RISK
open
ReferênciaVexDay Proof
iPhotoAlbum 1.1 - 'header.php' Remote File Inclusion
CVE-2005-2246webappsphp
Multiple PHP remote file inclusion vulnerabilities in iPhotoAlbum 1.1 allow remote attackers to execute arbitrary code v
23RISK
open
Referência
CVE-2011-2641
Opera 11.11 allows remote attackers to cause a denial of service (application crash) by setting the FACE attribute of a
23RISK
open
Referência
CVE-2022-39290
CSRF key bypass using HTTP methods in zoneminder
41RISK
open
Referência
CVE-2014-8357
backupsettings.html in the web administrative portal in Zhone zNID GPON 2426A before S3.0.501 places a session key in a
23RISK
open
Referência
CVE-2014-8357
backupsettings.html in the web administrative portal in Zhone zNID GPON 2426A before S3.0.501 places a session key in a
23RISK
open
ReferênciaVexDay Proof
Hex Workshop 5.1.4 - Color Mapping File Local Buffer Overflow (PoC)
CVE-2008-5756doswindows
Buffer overflow in BreakPoint Software Hex Workshop 5.1.4 allows user-assisted attackers to cause a denial of service an
23RISK
open
Referência
CVE-2010-1069
SQL injection vulnerability in games/game.php in ProArcadeScript allows remote attackers to execute arbitrary SQL comman
23RISK
open
Referência
CVE-2015-1561
The escape_command function in include/Administration/corePerformance/getStats.php in Centreon (formerly Merethis Centre
23RISK
open
Referência
CVE-2006-1652
Multiple buffer overflows in (a) UltraVNC (aka Ultr@VNC) 1.0.1 and earlier and (b) tabbed_viewer 1.29 (1) allow user-ass
50RISK
open
Referência
CVE-2015-2678
Multiple cross-site scripting (XSS) vulnerabilities in MetalGenix GeniXCMS before 0.0.2 allow remote attackers to inject
23RISK
open
Referência
CVE-2015-2678
Multiple cross-site scripting (XSS) vulnerabilities in MetalGenix GeniXCMS before 0.0.2 allow remote attackers to inject
23RISK
open
Referência
CVE-2019-14339
The ContentProvider in the Canon PRINT jp.co.canon.bsd.ad.pixmaprint 2.5.5 application for Android does not properly res
23RISK
open
Referência
CVE-2006-1652
Multiple buffer overflows in (a) UltraVNC (aka Ultr@VNC) 1.0.1 and earlier and (b) tabbed_viewer 1.29 (1) allow user-ass
50RISK
open
Referência
CVE-2015-8368
ntopng (aka ntop) before 2.2 allows remote authenticated users to change the login context and gain privileges via the u
23RISK
open
Referência
CVE-2015-8368
ntopng (aka ntop) before 2.2 allows remote authenticated users to change the login context and gain privileges via the u
23RISK
open
Referência
CVE-2014-4033
Cross-site scripting (XSS) vulnerability in libraries/includes/personal/profile.php in Epignosis eFront 3.6.14.4 allows
23RISK
open
Referência
CVE-2014-4033
Cross-site scripting (XSS) vulnerability in libraries/includes/personal/profile.php in Epignosis eFront 3.6.14.4 allows
23RISK
open
ReferênciaVexDay Proof
CoreHTTP 0.5.3alpha - HTTPd Remote Buffer Overflow
CVE-2007-4060remotelinux
Multiple buffer overflows in the HttpSprockMake function in http.c in Frank Yaul corehttp 0.5.3alpha allow remote attack
23RISK
open
ReferênciaVexDay Proof
ZeusCMS 0.3 - Blind SQL Injection
CVE-2007-6623webappsphp
Absolute path traversal vulnerability in ZeusCMS 0.3 and earlier might allow remote attackers to list arbitrary director
23RISK
open
ReferênciaVexDay Proof
bilboblog 2.1 - Multiple Vulnerabilities
CVE-2008-3303webappsphp
admin/login.php in BilboBlog 0.2.1, when register_globals is enabled, allows remote attackers to bypass authentication a
23RISK
open
ReferênciaVexDay Proof
Simple Machines Forum (SMF) 1.1.6 - Local File Inclusion / Code Execution
CVE-2008-6659webappsphp
Directory traversal vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 all
23RISK
open
ReferênciaVexDay Proof
Exodus 0.10 - URI Handler Arbitrary Parameter Injection (1)
CVE-2008-6935remotewindows
Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, over
23RISK
open
Referência
CVE-2017-15662
In Flexense VX Search Enterprise v10.1.12, the Control Protocol suffers from a denial of service vulnerability. The atta
23RISK
open
Referência
CVE-2015-6970
The web interface in Bosch Security Systems NBN-498 Dinion2X Day/Night IP Cameras with H.264 Firmware 4.54.0026 allows r
23RISK
open
Referência
CVE-2006-1595
Cross-site scripting (XSS) vulnerability in document/rqmkhtml.php in Claroline 1.7.4 and earlier allows remote attackers
23RISK
open
Referência
CVE-2023-30350
FS S3900-24T4S devices allow authenticated attackers with guest access to escalate their privileges and reset the admin
41RISK
open
Referência
CVE-2014-3110
Multiple cross-site scripting (XSS) vulnerabilities on Honeywell FALCON XLWeb Linux controller devices 2.04.01 and earli
23RISK
open
previouspage 197 / 718next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.