Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,902cataloged exploits
34,597CVEs with public exploitation
24,695lab-tested
21,581 exploits
Referência
CVE-2019-8937
HotelDruid 2.3.0 has XSS affecting the nsextt, cambia1, mese_fine, origine, and anno parameters in creaprezzi.php, tabel
43RISK
open
Referência
CVE-2014-2586
Cross-site scripting (XSS) vulnerability in the login audit form in McAfee Cloud Single Sign On (SSO) allows remote atta
23RISK
open
Referência
CVE-2014-2586
Cross-site scripting (XSS) vulnerability in the login audit form in McAfee Cloud Single Sign On (SSO) allows remote atta
23RISK
open
Referência
CVE-2006-6566
PHP remote file inclusion vulnerability in includes/profilcp_constants.php in the Profile Control Panel (CPanel) module
23RISK
open
Referência
CVE-2014-9580
Cross-site scripting (XSS) vulnerability in ProjectSend (formerly cFTP) r561 allows remote attackers to inject arbitrary
23RISK
open
Referência
CVE-2014-9580
Cross-site scripting (XSS) vulnerability in ProjectSend (formerly cFTP) r561 allows remote attackers to inject arbitrary
23RISK
open
Referência
CVE-2014-4710
Cross-site scripting (XSS) vulnerability in zero_user_account.php in ZeroCMS 1.0 allows remote attackers to inject arbit
23RISK
open
Referência
CVE-2014-4710
Cross-site scripting (XSS) vulnerability in zero_user_account.php in ZeroCMS 1.0 allows remote attackers to inject arbit
23RISK
open
Referência
CVE-2013-7368
Multiple cross-site scripting (XSS) vulnerabilities in Gnew 2013.1 allow remote attackers to inject arbitrary web script
23RISK
open
Referência
CVE-2013-5312
Multiple cross-site scripting (XSS) vulnerabilities in Vastal I-Tech phpVID 1.2.3 allow remote attackers to inject arbit
23RISK
open
Referência
CVE-2013-5312
Multiple cross-site scripting (XSS) vulnerabilities in Vastal I-Tech phpVID 1.2.3 allow remote attackers to inject arbit
23RISK
open
Referência
CVE-2013-4898
Unrestricted file upload vulnerability in the user profile page feature in the Timeline Plugin 4.2.5p9 for SocialEngine
23RISK
open
ReferênciaVexDay Proof
RevilloC MailServer 1.x - 'RCPT TO' Remote Denial of Service
CVE-2006-5552doswindows
Multiple heap-based buffer overflows in RevilloC MailServer 1.21 and earlier allow remote attackers to cause a denial of
23RISK
open
ReferênciaVexDay Proof
OpenH323 Opal SIP Protocol - Remote Denial of Service
CVE-2007-4924doswindows
The Open Phone Abstraction Library (opal), as used by (1) Ekiga before 2.0.10 and (2) OpenH323 before 2.2.4, allows remo
28RISK
open
Referência
CVE-2018-17382
SQL Injection exists in the Jobs Factory 2.0.4 component for Joomla! via the filter_letter parameter.
23RISK
open
Referência
CVE-2018-17382
SQL Injection exists in the Jobs Factory 2.0.4 component for Joomla! via the filter_letter parameter.
23RISK
open
Referência
CVE-2018-18763
SaltOS 3.1 r8126 allows action=ajax&query=numbers&page=usuarios&action2=[SQL] SQL Injection.
23RISK
open
ReferênciaVexDay Proof
Fuju News 1.0 - Authentication Bypass / SQL Injection
CVE-2006-1837webappsphp
SQL injection vulnerability in archiv2.php in Fuju News 1.0 allows remote attackers to execute arbitrary SQL commands vi
23RISK
open
Referência
CVE-2021-26929
An XSS issue was discovered in Horde Groupware Webmail Edition through 5.2.22 (where the Horde_Text_Filter library befor
23RISK
open
Referência
CVE-2021-26929
An XSS issue was discovered in Horde Groupware Webmail Edition through 5.2.22 (where the Horde_Text_Filter library befor
23RISK
open
ReferênciaVexDay Proof
D-Bus Daemon < 1.2.4 - 'libdbus' Denial of Service
CVE-2008-3834dosmultiple
The dbus_signature_validate function in the D-bus library (libdbus) before 1.2.4 allows remote attackers to cause a deni
23RISK
open
Referência
CVE-2023-39026
Directory Traversal vulnerability in FileMage Gateway Windows Deployments v.1.10.8 and before allows a remote attacker t
43RISK
open
Referência
CVE-2020-6756
languageOptions.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows unauthenticated attackers to re
53RISK
open
Referência
CVE-2021-27370
The Contact page in Monica 2.19.1 allows stored XSS via the Last Name field.
23RISK
open
Referência
CVE-2015-6568
Wolf CMS before 0.8.3.1 allows unrestricted file rename and PHP Code Execution because admin/plugin/file_manager/browse/
28RISK
open
Referência
CVE-2015-6568
Wolf CMS before 0.8.3.1 allows unrestricted file rename and PHP Code Execution because admin/plugin/file_manager/browse/
28RISK
open
ReferênciaVexDay Proof
Joomla! Component ionFiles 4.4.2 - File Disclosure
CVE-2008-6080webappsphp
Directory traversal vulnerability in download.php in the ionFiles (com_ionfiles) 4.4.2 component for Joomla! allows remo
43RISK
open
Referência
CVE-2010-1345
Directory traversal vulnerability in the Cookex Agency CKForms (com_ckforms) component 1.3.3 for Joomla! allows remote a
43RISK
open
Referência
CVE-2010-1346
SQL injection vulnerability in admin/login.php in Mini CMS RibaFS 1.0, when magic_quotes_gpc is disabled, allows remote
23RISK
open
Referência
CVE-2014-5201
SQL injection vulnerability in the Gallery Objects plugin 0.4 for WordPress allows remote attackers to execute arbitrary
23RISK
open
previouspage 227 / 720next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.