Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,902cataloged exploits
34,597CVEs with public exploitation
24,695lab-tested
21,581 exploits
Referência
CVE-2026-13536
GotoHTTP reg.12x cross site scripting
33RISK
open
ReferênciaVexDay Proof
Mambo Component SimpleBoard 1.1.0 - Remote File Inclusion
CVE-2006-3528webappsphp
Multiple PHP remote file inclusion vulnerabilities in Simpleboard Mambo module 1.1.0 and earlier allow remote attackers
23RISK
open
ReferênciaVexDay Proof
AuraCMS 2.2 - 'albums' Pramater SQL Injection
CVE-2008-0735webappsphp
SQL injection vulnerability in mod/gallery/ajax/gallery_data.php in AuraCMS 2.2 allows remote attackers to execute arbit
23RISK
open
ReferênciaVexDay Proof
Yblog 0.2.2.2 - Cross-Site Scripting / SQL Injection
CVE-2008-2668webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in yBlog 0.2.2.2 allow remote attackers to inject arbitrary web scri
23RISK
open
ReferênciaVexDay Proof
OneCMS 2.4 - SQL Injection / Upload
CVE-2008-7208webappsphp
Multiple SQL injection vulnerabilities in OneCMS 2.4, and possibly earlier, allow remote attackers to execute arbitrary
23RISK
open
Referência
CVE-2010-3603
Cross-site request forgery (CSRF) vulnerability in the file manager service (Services/FileService.ashx) in mojoPortal 2.
23RISK
open
Referência
CVE-2010-3608
Multiple SQL injection vulnerabilities in wpQuiz 2.7 allow remote attackers to execute arbitrary SQL commands via the (1
23RISK
open
Referência
CVE-2010-3608
Multiple SQL injection vulnerabilities in wpQuiz 2.7 allow remote attackers to execute arbitrary SQL commands via the (1
23RISK
open
Referência
CVE-2009-4888
Cross-site scripting (XSS) vulnerability in poster.php in PHortail 1.2.1 allows remote attackers to inject arbitrary web
23RISK
open
Referência
CVE-2017-8839
XSS via orig_url exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_38
23RISK
open
Referência
CVE-2022-37061
All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command Injection. This
60RISK
open
Referência
CVE-2009-3803
Multiple cross-site scripting (XSS) vulnerabilities in Amiro.CMS 5.4.0.0 and earlier allow remote attackers to inject ar
23RISK
open
Referência
CVE-2009-4381
Cross-site scripting (XSS) vulnerability in index.php in texmedia Million Pixel Script 3 allows remote attackers to inje
23RISK
open
Referência
CVE-2009-4381
Cross-site scripting (XSS) vulnerability in index.php in texmedia Million Pixel Script 3 allows remote attackers to inje
23RISK
open
Referência
CVE-2007-0132
SQL injection vulnerability in compare_product.php in iGeneric iG Shop 1.4 allows remote attackers to execute arbitrary
23RISK
open
Referência
CVE-2007-3889
Multiple SQL injection vulnerabilities in Insanely Simple Blog 0.5 and earlier allow remote attackers to execute arbitra
23RISK
open
ReferênciaVexDay Proof
ig shop 1.0 - Code Execution / SQL Injection
CVE-2007-0132webappsphp
SQL injection vulnerability in compare_product.php in iGeneric iG Shop 1.4 allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
CHILKAT ASP String - 'CkString.dll 1.1 SaveToFile()' Insecure Method
CVE-2007-4252remotewindows
Absolute path traversal vulnerability in a certain ActiveX control in CkString.dll 1.1 and earlier in CHILKAT ASP String
23RISK
open
Referência
Bolt CMS 3.6.4 - Cross-Site Scripting
CVE-2019-9553webappsphp
Bolt 3.6.4 has XSS via the slug, teaser, or title parameter to editcontent/pages, a related issue to CVE-2017-11128 and
23RISK
open
Referência
CVE-2022-37061
All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command Injection. This
60RISK
open
Referência
CVE-2022-37061
All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command Injection. This
60RISK
open
Referência
CVE-2011-1062
Multiple cross-site scripting (XSS) vulnerabilities in include/html/header.php in TaskFreak! 0.6.4 allow remote attacker
23RISK
open
Referência
CVE-2019-9553
Bolt 3.6.4 has XSS via the slug, teaser, or title parameter to editcontent/pages, a related issue to CVE-2017-11128 and
23RISK
open
Referência
CVE-2018-12094
Cross-site scripting (XSS) vulnerability in news.php in Dimofinf CMS Version 3.0.0 allows remote attackers to inject arb
23RISK
open
Referência
CVE-2018-8732
Cross-site scripting (XSS) vulnerability in WampServer 3.1.1 allows remote attackers to inject arbitrary web script or H
23RISK
open
ReferênciaVexDay Proof
PAPOO 3_RC3 - SQL Injection / Admin Credentials Disclosure
CVE-2006-3572webappsphp
SQL injection vulnerability in forumthread.php in Papoo 3 RC3 and earlier allows remote attackers to execute arbitrary S
23RISK
open
ReferênciaVexDay Proof
aspwebalbum 3.2 - Multiple Vulnerabilities
CVE-2008-6977webappsasp
Cross-site scripting (XSS) vulnerability in album.asp in Full Revolution aspWebAlbum 3.2 allows remote attackers to inje
23RISK
open
ReferênciaVexDay Proof
aspwebalbum 3.2 - Arbitrary File Upload / SQL Injection / Cross-Site Scripting
CVE-2008-6977webappsphp
Cross-site scripting (XSS) vulnerability in album.asp in Full Revolution aspWebAlbum 3.2 allows remote attackers to inje
23RISK
open
Referência
CVE-2010-4893
Cross-site scripting (XSS) vulnerability in foodvendors.php in FestOS 2.3b allows remote attackers to inject arbitrary w
23RISK
open
Referência
CVE-2016-8805
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 3
23RISK
open
previouspage 229 / 720next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.