Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,902cataloged exploits
34,597CVEs with public exploitation
24,695lab-tested
21,624 exploits
ReferênciaVexDay Proof
Redaction System 1.0 - 'lang_prefix' Remote File Inclusion
CVE-2006-5302webappsphp
Multiple PHP remote file inclusion vulnerabilities in Redaction System 1.0000 allow remote attackers to execute arbitrar
23RISK
open
Referência
CVE-2020-8495
In Kronos Web Time and Attendance (webTA) 3.8.x and later 3.x versions before 4.0, the com.threeis.webta.H491delegate se
41RISK
open
Referência
CVE-2014-3848
The iMember360 plugin before 3.9.001 for WordPress does not properly restrict access, which allows remote attackers to o
23RISK
open
Referência
CVE-2014-3848
The iMember360 plugin before 3.9.001 for WordPress does not properly restrict access, which allows remote attackers to o
23RISK
open
Referência
CVE-2006-5521
PHP remote file inclusion vulnerability in DNS/RR.php in Net_DNS 0.03 and earlier allows remote attackers to execute arb
23RISK
open
ReferênciaVexDay Proof
Net_DNS 0.3 - '/DNS/RR.php' Remote File Inclusion
CVE-2006-5521webappsphp
PHP remote file inclusion vulnerability in DNS/RR.php in Net_DNS 0.03 and earlier allows remote attackers to execute arb
23RISK
open
ReferênciaVexDay Proof
vp-asp shopping cart 6.09 - SQL Injection / Cross-Site Scripting
CVE-2007-0225webappsasp
Cross-site scripting (XSS) vulnerability in shopcustadmin.asp in VP-ASP Shopping Cart 6.09 and earlier allows remote att
23RISK
open
Referência
CVE-2013-4865
Cross-site request forgery (CSRF) vulnerability in upgrade_step2.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows
23RISK
open
ReferênciaVexDay Proof
Anthologia 0.5.2 - 'index.php?ads_file' Remote File Inclusion
CVE-2007-2094webappsphp
PHP remote file inclusion vulnerability in index.php in Anthologia 0.5.2 allows remote attackers to execute arbitrary PH
23RISK
open
ReferênciaVexDay Proof
VisoHotlink 1.01 - 'functions.visohotlink.php' Remote File Inclusion
CVE-2007-0489webappsphp
PHP remote file inclusion vulnerability in includes/functions.visohotlink.php in VisoHotlink 1.01 and possibly earlier a
23RISK
open
ReferênciaVexDay Proof
PHP-Generics 1.0.0 Beta - Multiple Remote File Inclusions
CVE-2007-2346webappsphp
Multiple PHP remote file inclusion vulnerabilities in PHP-Generics 1.0 beta allow remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
Glossword 1.8.1 - 'custom_vars.php' Remote File Inclusion
CVE-2007-2743webappsphp
PHP remote file inclusion vulnerability in custom_vars.php in GlossWord 1.8.1 allows remote attackers to execute arbitra
23RISK
open
ReferênciaVexDay Proof
CounterPath X-Lite 3.x - SIP phone Remote Denial of Service
CVE-2007-4382doswindows
CounterPath X-Lite 3.0 34025, and possibly eyeBeam, allows remote attackers to cause a denial of service (device crash)
23RISK
open
ReferênciaVexDay Proof
PHP Real Estate Classifieds - Remote File Inclusion
CVE-2007-3160webappsphp
PHP remote file inclusion vulnerability in admin/header.php in PHP Real Estate Classifieds Premium Plus allows remote at
23RISK
open
ReferênciaVexDay Proof
Joomla! 1.5.x - 'Token' Remote Admin Change Password
CVE-2008-3681webappsphp
components/com_user/models/reset.php in Joomla! 1.5 through 1.5.5 does not properly validate reset tokens, which allows
23RISK
open
ReferênciaVexDay Proof
wbstreet 1.0 - SQL Injection / File Disclosure
CVE-2008-5956webappsphp
Wbstreet (aka PHPSTREET Webboard) 1.0 stores sensitive information under the web root with insufficient access control,
23RISK
open
Referência
CVE-2015-2564
SQL injection vulnerability in client-edit.php in ProjectSend (formerly cFTP) r561 allows remote authenticated users to
23RISK
open
Referência
CVE-2015-2564
SQL injection vulnerability in client-edit.php in ProjectSend (formerly cFTP) r561 allows remote authenticated users to
23RISK
open
Referência
CVE-2025-34125
D-Link DSP-W110A1 Cookie Command Injection
63RISK
open
Referência
CVE-2025-34125
D-Link DSP-W110A1 Cookie Command Injection
63RISK
open
Referência
CVE-2025-34125
D-Link DSP-W110A1 Cookie Command Injection
63RISK
open
Referência
CVE-2019-9184
SQL injection vulnerability in the J2Store plugin 3.x before 3.3.7 for Joomla! allows remote attackers to execute arbitr
23RISK
open
Referência
CVE-2011-5233
Heap-based buffer overflow in IrfanView before 4.32 allows remote attackers to execute arbitrary code via crafted "Rows
23RISK
open
Referência
CVE-2019-6224
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Mojave 10.
23RISK
open
Referência
CVE-2013-4985
Multiple Vivotek IP Cameras remote authentication bypass that could allow access to the video stream
23RISK
open
Referência
CVE-2026-2017
IP-COM W30AP POST Request wx3auth R7WebsSecurityHandler stack-based overflow
48RISK
open
Referência
CVE-2017-16884
Cross-site scripting (XSS) vulnerability in MistServer before 2.13 allows remote attackers to inject arbitrary web scrip
23RISK
open
Referência
CVE-2017-16884
Cross-site scripting (XSS) vulnerability in MistServer before 2.13 allows remote attackers to inject arbitrary web scrip
23RISK
open
Referência
CVE-2018-16302
MediaComm Zip-n-Go before 4.95 has a Buffer Overflow via a crafted file.
23RISK
open
Referência
CVE-2016-5348
The GPS component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 be
23RISK
open
previouspage 236 / 721next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.