Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,902cataloged exploits
34,597CVEs with public exploitation
24,695lab-tested
21,624 exploits
Referência
CVE-2017-0100
A DCOM object in Helppane.exe in Microsoft Windows 7 SP1; Windows Server 2008 R2; Windows 8.1; Windows Server 2012 Gold
23RISK
open
Referência
CVE-2022-4117
IWS - Geo Form Fields <= 1.0 - Unauthenticated SQLi
63RISK
open
Referência
CVE-2017-4916
VMware Workstation Pro/Player contains a NULL pointer dereference vulnerability that exists in the vstor2 driver. Succes
23RISK
open
Referência
CVE-2014-9261
The sanitize function in Codoforum 2.5.1 does not properly implement filtering for directory traversal sequences, which
23RISK
open
Referência
CVE-2014-9261
The sanitize function in Codoforum 2.5.1 does not properly implement filtering for directory traversal sequences, which
23RISK
open
Referência
CVE-2010-3155
Untrusted search path vulnerability in Adobe ExtendScript Toolkit (ESTK) CS5 3.5.0.52 allows local users, and possibly r
28RISK
open
Referência
CVE-2017-15014
OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design ga
23RISK
open
ReferênciaVexDay Proof
WEBO (Web ORGanizer) 1.0 - 'baseDir' Remote File Inclusion
CVE-2007-1391webappsphp
PHP remote file inclusion vulnerability in modules/abook/foldertree.php in Leo West WEBO (aka weborganizer) 1.0 allows r
23RISK
open
Referência
CVE-2022-37255
TP-Link Tapo C310 1.3.0 devices allow access to the RTSP video feed via credentials of User --- and Password TPL07552646
41RISK
open
ReferênciaVexDay Proof
Pluck CMS 4.5.3 - 'g_pcltar_lib_dir' Local File Inclusion
CVE-2008-6253webappsphp
Directory traversal vulnerability in data/inc/lib/pcltar.lib.php in Pluck 4.5.3, when register_globals is enabled, allow
23RISK
open
ReferênciaVexDay Proof
ICQ 6.5 - URL Search Hook (Windows Explorer) Remote Buffer Overflow (PoC)
CVE-2009-1915doswindows
Stack-based buffer overflow in the URL Search Hook (ICQToolBar.dll) in ICQ 6.5 allows remote attackers to cause a denial
23RISK
open
Referência
CVE-2017-8837
Cleartext password storage exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-
23RISK
open
Referência
CVE-2025-14534
UTT 进取 512W Endpoint formNatStaticMap strcpy buffer overflow
48RISK
open
Referência
CVE-2017-15962
iStock Management System 1.0 allows Arbitrary File Upload via user/profile.
23RISK
open
Referência
CVE-2017-15962
iStock Management System 1.0 allows Arbitrary File Upload via user/profile.
23RISK
open
Referência
CVE-2017-9603
SQL injection vulnerability in the WP Jobs plugin before 1.5 for WordPress allows authenticated users to execute arbitra
23RISK
open
Referência
CVE-2017-14955
Check_MK before 1.2.8p26 mishandles certain errors within the failed-login save feature because of a race condition, whi
28RISK
open
Referência
CVE-2018-19040
The Media File Manager plugin 1.4.2 for WordPress allows directory listing via a ../ directory traversal in the dir para
28RISK
open
Referência
CVE-2015-3301
Directory traversal vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce
23RISK
open
Referência
CVE-2015-3301
Directory traversal vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce
23RISK
open
ReferênciaVexDay Proof
Web Wiz Forums 9.07 - 'sub' Directory Traversal
CVE-2008-0466webappsasp
Web Wiz RTE_file_browser.asp in, as used in Web Wiz Rich Text Editor 4.0, Web Wiz Forums 9.07, and Web Wiz Newspad 1.02,
23RISK
open
ReferênciaVexDay Proof
yourplace 1.0.2 - Multiple Vulnerabilities / Remote Code Execution
CVE-2008-6769webappsphp
Unrestricted file upload vulnerability in upload.php in YourPlace 1.0.2 and earlier allows remote authenticated users to
23RISK
open
Referência
CVE-2015-4684
Multiple directory traversal vulnerabilities in Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allow (1) re
23RISK
open
Referência
CVE-2015-4684
Multiple directory traversal vulnerabilities in Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allow (1) re
23RISK
open
Referência
CVE-2016-1813
The IOAccelSharedUserClient2::page_off_resource method in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1
23RISK
open
Referência
CVE-2016-1813
The IOAccelSharedUserClient2::page_off_resource method in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1
23RISK
open
Referência
CVE-2009-3307
Multiple PHP remote file inclusion vulnerabilities in FSphp 0.2.1 allow remote attackers to execute arbitrary PHP code v
23RISK
open
Referência
CVE-2019-6780
The Wise Chat plugin before 2.7 for WordPress mishandles external links because rendering/filters/post/WiseChatLinksPost
23RISK
open
ReferênciaVexDay Proof
DigitalHive 2.0 RC2 - 'base_include.php' Remote File Inclusion
CVE-2006-5493webappsphp
PHP remote file inclusion vulnerability in template/purpletech/base_include.php in DigitalHive 2.0 RC2 allows remote att
23RISK
open
ReferênciaVexDay Proof
phpProfiles 3.1.2b - Multiple Remote File Inclusions
CVE-2006-6740webappsphp
Multiple PHP remote file inclusion vulnerabilities in phpProfiles 3.1.2b and earlier allow remote attackers to execute a
23RISK
open
previouspage 237 / 721next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.