Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,902cataloged exploits
34,597CVEs with public exploitation
24,695lab-tested
21,581 exploits
Referência
CVE-2016-1803
CoreCapture in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers
23RISK
open
Referência
CVE-2016-1803
CoreCapture in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers
23RISK
open
Referência
CVE-2019-15092
The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in
23RISK
open
Referência
CVE-2019-25699
Newsbull Haber Script 1.0.0 Authenticated SQL Injection via search parameter
41RISK
open
Referência
CVE-2026-21876 PoC: WAF charset bypass (Flask, ASP.NET and Spring Boot stands)
OWASP CRS has multipart bypass using multiple content-type parts
53RISK
open
ReferênciaVexDay Proof
Linksys WRT54G Firmware 1.00.9 - Security Bypass (1)
CVE-2008-1247remotehardware
The web interface on the Linksys WRT54g router with firmware 1.00.9 does not require credentials when invoking scripts,
23RISK
open
ReferênciaVexDay Proof
ASP PORTAL - Remote Database Disclosure
CVE-2008-5562webappsasp
ASPPortal stores sensitive information under the web root with insufficient access control, which allows remote attacker
23RISK
open
ReferênciaVexDay Proof
Total Video Player 1.31 - 'DefaultSkin.ini' Local Stack Overflow
CVE-2009-0261localwindows
Stack-based buffer overflow in EffectMatrix Total Video Player 1.31 allows user-assisted attackers to execute arbitrary
43RISK
open
ReferênciaVexDay Proof
FipsCMS Light 2.1 - 'db.mdb' Remote Database Disclosure
CVE-2009-2022webappsasp
fipsCMS Light 2.1 stores sensitive information under the web root with insufficient access control, which allows remote
23RISK
open
Referência
CVE-2015-7241
XML External Entity (XXE) vulnerability in SAP Netweaver before 7.01.
28RISK
open
Referência
CVE-2015-3796
The TRE library in Libc in Apple iOS before 8.4.1 and OS X before 10.10.5 allows context-dependent attackers to execute
28RISK
open
Referência
CVE-2016-0079
The kernel in Microsoft Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application
23RISK
open
ReferênciaVexDay Proof
NUNE News Script 2.0pre2 - Multiple Remote File Inclusions
CVE-2007-0143webappsphp
Multiple PHP remote file inclusion vulnerabilities in NUNE News Script 2.0pre2 allow remote attackers to execute arbitra
23RISK
open
ReferênciaVexDay Proof
eFiction 3.1.1 - 'path_to_smf' Remote File Inclusion
CVE-2007-1118webappsphp
Multiple PHP remote file inclusion vulnerabilities in eFiction 3.1.1 and earlier allow remote attackers to execute arbit
23RISK
open
Referência
CVE-2010-1226
The HTTP client functionality in Apple iPhone OS 3.1 on the iPhone 2G and 3.1.3 on the iPhone 3GS allows remote attacker
23RISK
open
Referência
CVE-2010-2129
Directory traversal vulnerability in the JE Ajax Event Calendar (com_jeajaxeventcalendar) component 1.0.1 and 1.0.3 for
23RISK
open
Referência
CVE-2010-2129
Directory traversal vulnerability in the JE Ajax Event Calendar (com_jeajaxeventcalendar) component 1.0.1 and 1.0.3 for
23RISK
open
Referência
CVE-2018-9163
A stored Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Recovery Manager Plus before 5.3 (Build 5350) all
23RISK
open
Referência
CVE-2023-1020
Steveas WP Live Chat Shoutbox <= 1.4.2 - Unauthenticated SQLi
63RISK
open
Referência
CVE-2012-3809
Samsung Kies before 2.5.0.12094_27_11 has arbitrary directory modification.
23RISK
open
Referência
CVE-2014-2044
Incomplete blacklist vulnerability in ajax/upload.php in ownCloud before 5.0, when running on Windows, allows remote aut
28RISK
open
Referência
CVE-2014-2044
Incomplete blacklist vulnerability in ajax/upload.php in ownCloud before 5.0, when running on Windows, allows remote aut
28RISK
open
Referência
CVE-2012-3808
Samsung Kies before 2.5.0.12094_27_11 has arbitrary file modification.
23RISK
open
ReferênciaVexDay Proof
Yappa-ng 2.3.3-beta0 - 'album' Local File Inclusion
CVE-2008-4626webappsphp
Directory traversal vulnerability in index.php in Fritz Berger yet another php photo album - next generation (yappa-ng)
23RISK
open
ReferênciaVexDay Proof
minb 0.1.0 - Remote Code Execution
CVE-2008-7005webappsphp
include/modules/top/1-random_quote.php in Minb Is Not a Blog (minb) 0.1.0 allows remote attackers to execute arbitrary P
23RISK
open
Referência
CVE-2023-54335
eXtplorer<= 2.1.14 - Authentication Bypass & Remote Code Execution (RCE)
48RISK
open
Referência
CVE-2021-28242
SQL Injection in the "evoadm.php" component of b2evolution v7.2.2-stable allows remote attackers to obtain sensitive dat
23RISK
open
Referência
CVE-2017-0300
The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2,
23RISK
open
Referência
CVE-2019-13623
In NSA Ghidra before 9.1, path traversal can occur in RestoreTask.java (from the package ghidra.app.plugin.core.archive)
23RISK
open
Referência
CVE-2013-4868
Karotz API 12.07.19.00: Session Token Information Disclosure
23RISK
open
previouspage 221 / 720next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.