Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,008cataloged exploits
34,638CVEs with public exploitation
24,695lab-tested
21,624 exploits
Referência
CVE-2009-2399
PHP remote file inclusion vulnerability in dm-albums/template/album.php in DM FileManager 3.9.4, when register_globals i
23RISK
open
Referência
CVE-2009-2769
PHP remote file inclusion vulnerability in include/timesheet.php in Ultrize TimeSheet 1.2.2, when register_globals is en
23RISK
open
Referência
CVE-2012-2275
Multiple cross-site request forgery (CSRF) vulnerabilities in TestLink 1.9.3 and earlier allow remote attackers to hijac
23RISK
open
Referência
CVE-2012-2275
Multiple cross-site request forgery (CSRF) vulnerabilities in TestLink 1.9.3 and earlier allow remote attackers to hijac
23RISK
open
Referência
CVE-2007-1152
Multiple directory traversal vulnerabilities in Pyrophobia 2.1.3.1 allow remote attackers to read arbitrary files via a
23RISK
open
Referência
CVE-2009-3124
Directory traversal vulnerability in get_message.cgi in QuarkMail allows remote attackers to read arbitrary files via a
23RISK
open
ReferênciaVexDay Proof
e107 0.617 - Cross-Site Scripting Remote Cookie Disclosure
CVE-2005-2327webappsphp
Cross-site scripting (XSS) vulnerability in e107 0.617 and earlier allows remote attackers to inject arbitrary web scrip
23RISK
open
ReferênciaVexDay Proof
Admbook 1.2.2 - 'x-forwarded-for' Remote Command Execution
CVE-2006-0852webappsphp
Direct static code injection vulnerability in write.php in Admbook 1.2.2 and earlier allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
TR Newsportal 0.36tr1 - 'poll.php' Remote File Inclusion
CVE-2006-2557webappsphp
PHP remote file inclusion vulnerability in extras/poll/poll.php in Florian Amrhein NewsPortal before 0.37, and TR Newspo
28RISK
open
ReferênciaVexDay Proof
Web Oddity Web Server 0.09b - Directory Traversal
CVE-2007-4726remotelinux
Directory traversal vulnerability in Web Oddity 0.09b allows remote attackers to read arbitrary files via a .. (dot dot)
23RISK
open
ReferênciaVexDay Proof
SiteBuilderElite 1.2 - Multiple Remote File Inclusions
CVE-2008-1123webappsphp
Multiple PHP remote file inclusion vulnerabilities in SiteBuilder Elite 1.2 allow remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
merlix educate servert - Authentication Bypass / File Disclosure
CVE-2008-6870webappsasp
Merlix Educate Server allows remote attackers to bypass intended security restrictions and obtain sensitive information
23RISK
open
Referência
CVE-2009-3151
Directory traversal vulnerability in actions/downloadFile.php in Ultrize TimeSheet 1.2.2 allows remote attackers to read
23RISK
open
Referência
CVE-2018-11443
The parameter q is affected by Cross-site Scripting in jobcard-ongoing.php in EasyService Billing 1.0.
23RISK
open
ReferênciaVexDay Proof
UBBCentral UBB.Threads 6.4.x < 6.5.2 - 'thispath' Remote File Inclusion
CVE-2006-2568webappsphp
PHP remote file inclusion vulnerability in addpost_newpoll.php in UBB.threads 6.4 through 6.5.2 and 6.5.1.1 (trial) allo
23RISK
open
Referência
CVE-2017-6331
Prior to SEP 14 RU1 Symantec Endpoint Protection product can encounter an issue of Tamper-Protection Bypass, which is a
23RISK
open
ReferênciaVexDay Proof
Sisfo Kampus 2006 - 'dwoprn.php?f' Arbitrary File Download
CVE-2007-4895webappsphp
Directory traversal vulnerability in dwoprn.php in Sisfo Kampus 2006 (Semarang 3) allows remote attackers to read arbitr
23RISK
open
Referência
CVE-2009-4748
SQL injection vulnerability in mycategoryorder.php in the My Category Order plugin 2.8 and earlier for WordPress allows
23RISK
open
Referência
CVE-2009-4748
SQL injection vulnerability in mycategoryorder.php in the My Category Order plugin 2.8 and earlier for WordPress allows
23RISK
open
Referência
CVE-2015-1517
SQL injection vulnerability in Piwigo before 2.7.4, when all filters are activated, allows remote authenticated users to
23RISK
open
Referência
CVE-2010-0967
Multiple directory traversal vulnerabilities in Geekhelps ADMP 1.01, when magic_quotes_gpc is disabled, allow remote att
23RISK
open
Referência
CVE-2024-27620
An issue in Ladder v.0.0.1 thru v.0.0.21 allows a remote attacker to obtain sensitive information via a crafted request
41RISK
open
ReferênciaVexDay Proof
JShop 1.x < 2.x - 'xPage' Local File Inclusion
CVE-2008-1624webappsphp
Directory traversal vulnerability in v2demo/page.php in Jshop Server 1.x through 2.x allows remote attackers to include
23RISK
open
ReferênciaVexDay Proof
WordPress Plugin st_newsletter - 'stnl_iframe.php' SQL Injection
CVE-2008-4625webappsphp
SQL injection vulnerability in stnl_iframe.php in the ShiftThis Newsletter (st_newsletter) plugin for WordPress allows r
23RISK
open
ReferênciaVexDay Proof
glFusion 1.1.2 - 'COM_applyFilter()/cookies' Blind SQL Injection
CVE-2009-1282webappsphp
SQL injection vulnerability in private/system/lib-session.php in glFusion 1.1.2 and earlier allows remote attackers to e
23RISK
open
ReferênciaVexDay Proof
VidShare Pro - Arbitrary File Upload
CVE-2009-1750webappsphp
Unrestricted file upload vulnerability in VidSharePro allows remote authenticated users to execute arbitrary code by upl
23RISK
open
ReferênciaVexDay Proof
adaptweb 0.9.2 - Local File Inclusion / SQL Injection
CVE-2009-2151webappsphp
Directory traversal vulnerability in index.php in AdaptWeb 0.9.2 allows remote attackers to read arbitrary files via a .
23RISK
open
Referência
aiohttp 3.9.1 - directory traversal PoC
CVE-2024-23334MEDIUMwebappspython
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RISK
open
Referência
CVE-2014-2022
SQL injection vulnerability in includes/api/4/breadcrumbs_create.php in vBulletin 4.2.2, 4.2.1, 4.2.0 PL2, and earlier a
23RISK
open
Referência
CVE-2010-4313
Unrestricted file upload vulnerability in fileman_file_upload.php in Orbis CMS 1.0.2 allows remote authenticated users t
23RISK
open
previouspage 248 / 721next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.