Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,589cataloged exploits
34,508CVEs with public exploitation
24,695lab-tested
21,554 exploits
Referência
CVE-2019-25713
MyT-PM 1.5.1 SQL Injection via Charge[group_total] Parameter
41RISK
open
ReferênciaVexDay Proof
Gateway Weblaunch - ActiveX Control Insecure Method
CVE-2008-0221remotewindows
Directory traversal vulnerability in the WebLaunch.WeblaunchCtl.1 (aka CWebLaunchCtl) ActiveX control in weblaunch.ocx 1
23RISK
open
ReferênciaVexDay Proof
Flexphplink Pro - Arbitrary File Upload
CVE-2008-6731webappsphp
Unrestricted file upload vulnerability in submitlink.php in FlexPHPLink Pro 0.0.7 allows remote attackers to execute arb
23RISK
open
ReferênciaVexDay Proof
Chilkat Socket ActiveX 2.3.1.1 - Arbitrary File Creation
CVE-2008-6959remotewindows
Insecure method vulnerability in the Chilkat Socket ActiveX control (ChilkatSocket.ChilkatSocket.1) in ChilkatSocket.dll
23RISK
open
ReferênciaVexDay Proof
Campsite 3.3.0 RC1 - Multiple Remote File Inclusions
CVE-2009-2183webappsphp
Directory traversal vulnerability in admin-files/ad.php in Campsite 3.3.0 RC1 allows remote attackers to read and possib
23RISK
open
Referência
CVE-2018-12292
A use-after-free vulnerability exists in DOMProxyHandler::EnsureExpandoObject in Pale Moon before 27.9.3.
23RISK
open
Referência
CVE-2017-2371
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. The issue involves the "WebKit" compon
23RISK
open
Referência
CVE-2021-24750
WP Visitor Statistics (Real Time Traffic) < 4.8 - Subscriber+ SQL Injection
50RISK
open
Referência
CVE-2023-33131
Microsoft Outlook Remote Code Execution Vulnerability
41RISK
open
Referência
CVE-2020-12352
Improper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adja
23RISK
open
Referência
CVE-2020-12352
Improper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adja
23RISK
open
Referência
CVE-2020-8899
Memory corruption in Quram library when decoding qmg can lead to RCE
48RISK
open
Referência
CVE-2014-0871
RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allows remote att
23RISK
open
Referência
CVE-2011-0502
Music Animation Machine MIDI Player 2006aug19 Release 035 and possibly other versions allows user-assisted remote attack
23RISK
open
Referência
CVE-2023-53941
EasyPHP Webserver 14.1 Remote Code Execution
48RISK
open
ReferênciaVexDay Proof
Mambo Component Peoplebook 1.0 - Remote File Inclusion
CVE-2006-4195webappsphp
PHP remote file inclusion vulnerability in param.peoplebook.php in the Peoplebook Component for Mambo (com_peoplebook) 1
23RISK
open
Referência
CVE-2025-14708
Shiguangwu sgwbox N3 WIREDCFGGET http_eshell_server buffer overflow
48RISK
open
Referência
CVE-2018-4193
An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Windows Ser
23RISK
open
Referência
CVE-2017-8869
Buffer overflow in MediaCoder 0.8.48.5888 allows remote attackers to execute arbitrary code via a crafted .m3u file.
43RISK
open
ReferênciaVexDay Proof
e107 Plugin My_Gallery 2.3 - Arbitrary File Download
CVE-2008-1702webappsphp
Absolute path traversal vulnerability in dload.php in the my_gallery 2.3 plugin for e107 allows remote attackers to obta
23RISK
open
ReferênciaVexDay Proof
Acoustica Beatcraft 1.02 Build 19 - '.bcproj' Local Buffer Overflow
CVE-2008-4087localwindows
Stack-based buffer overflow in Acoustica Beatcraft 1.02 Build 19 allows user-assisted attackers to cause a denial of ser
23RISK
open
ReferênciaVexDay Proof
PHPFK 7.03 - 'page_bottom.php' Local File Inclusion
CVE-2009-2112webappsphp
Directory traversal vulnerability in include/page_bottom.php in phpFK 7.03 allows remote attackers to include and execut
23RISK
open
Referência
CVE-2010-2920
Directory traversal vulnerability in the Foobla Suggestions (com_foobla_suggestions) component 1.5.1.2 for Joomla! allow
38RISK
open
Referência
CVE-2016-4997
The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux
38RISK
open
Referência
CVE-2016-4997
The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux
38RISK
open
ReferênciaVexDay Proof
DoSePa 1.0.4 - 'textview.php' Information Disclosure
CVE-2006-6028webappsphp
Directory traversal vulnerability in textview.php in Anton Vlasov DoSePa 1.0.4 allows remote attackers to read arbitrary
23RISK
open
Referência
CVE-2019-9213
In the Linux kernel before 4.20.14, expand_downwards in mm/mmap.c lacks a check for the mmap minimum address, which make
38RISK
open
Referência
CVE-2019-8924
XAMPP through 5.6.8 allows XSS via the cds-fpdf.php interpret or titel parameter. NOTE: This product is discontinued.
23RISK
open
Referência
CVE-2019-8924
XAMPP through 5.6.8 allows XSS via the cds-fpdf.php interpret or titel parameter. NOTE: This product is discontinued.
23RISK
open
Referência
CVE-2010-4230
Stack-based buffer overflow in a certain ActiveX control for the Camtron CMNC-200 Full HD IP Camera and TecVoz CMNC-200
23RISK
open
previouspage 214 / 719next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.