Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,066cataloged exploits
34,679CVEs with public exploitation
24,695lab-tested
21,662 exploits
Referência
CVE-2018-16302
MediaComm Zip-n-Go before 4.95 has a Buffer Overflow via a crafted file.
23RISK
open
Referência
CVE-2016-5348
The GPS component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 be
23RISK
open
Referência
CVE-2012-6644
Multiple cross-site scripting (XSS) vulnerabilities in ClipBucket 2.6 allow remote attackers to inject arbitrary web scr
23RISK
open
ReferênciaVexDay Proof
pandaBB - 'displayCategory' Remote File Inclusion
CVE-2006-5494webappsphp
Multiple PHP remote file inclusion vulnerabilities in modules/My_eGallery/public/displayCategory.php in the pandaBB modu
23RISK
open
ReferênciaVexDay Proof
IrfanView 4.00 - '.iff' Local Buffer Overflow
CVE-2007-2363localwindows
Buffer overflow in IrfanView 4.00 and earlier allows user-assisted remote attackers to execute arbitrary code via a craf
23RISK
open
ReferênciaVexDay Proof
GlobalLink 2.7.0.8 - 'glItemCom.dll SetInfo()' Heap Overflow
CVE-2007-4802remotewindows
Multiple heap-based buffer overflows in GlobalLink 2.7.0.8 allow remote attackers to execute arbitrary code via (1) a lo
23RISK
open
ReferênciaVexDay Proof
GlobalLink 2.7.0.8 - 'glitemflat.dll SetClientInfo()' Heap Overflow
CVE-2007-4802remotewindows
Multiple heap-based buffer overflows in GlobalLink 2.7.0.8 allow remote attackers to execute arbitrary code via (1) a lo
23RISK
open
ReferênciaVexDay Proof
Mini File Host 1.x - Arbitrary '.PHP' File Upload
CVE-2008-6785webappsphp
Unrestricted file upload vulnerability in Mini File Host 1.5 allows remote attackers to execute arbitrary code by upload
23RISK
open
ReferênciaVexDay Proof
Exodus 0.10 - URI Handler Arbitrary Parameter Injection (2)
CVE-2008-6936remotewindows
Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, over
23RISK
open
Referência
CVE-2012-6644
Multiple cross-site scripting (XSS) vulnerabilities in ClipBucket 2.6 allow remote attackers to inject arbitrary web scr
23RISK
open
Referência
CVE-2018-0715
Cross-site scripting vulnerability in QNAP Photo Station versions 5.7.0 and earlier could allow remote attackers to inje
23RISK
open
Referência
CVE-2019-3474
Path traversal vulnerability in Filr web application
33RISK
open
ReferênciaVexDay Proof
TorrentTrader Classic 1.09 - Multiple Vulnerabilities
CVE-2009-2157webappsphp
Multiple SQL injection vulnerabilities in TorrentTrader Classic 1.09 allow remote authenticated users to execute arbitra
23RISK
open
Referência
CVE-2016-4004
Directory traversal vulnerability in Dell OpenManage Server Administrator (OMSA) 8.2 allows remote authenticated adminis
23RISK
open
Referência
CVE-2026-5813
PHPGurukul Online Course Registration check_availability.php sql injection
33RISK
open
Referência
CVE-2010-1743
SQL injection vulnerability in projects.php in Scratcher allows remote attackers to execute arbitrary SQL commands via t
23RISK
open
Referência
CVE-2021-41382
Plastic SCM before 10.0.16.5622 mishandles the WebAdmin server management interface.
23RISK
open
Referência
CVE-2023-38357
Session tokens in RWS WorldServer 11.7.3 and earlier have a low entropy and can be enumerated, leading to unauthorized a
23RISK
open
Referência
CVE-2023-4490
WP Job Portal < 2.0.6 - Unauthenticated SQLi
63RISK
open
ReferênciaVexDay Proof
PHP121 Instant Messenger 2.2 - Local File Inclusion
CVE-2007-1908webappsphp
PHP file inclusion vulnerability in php121db.php in PHP121 Instant Messenger 2.2 allows remote attackers to execute arbi
23RISK
open
Referência
CVE-2026-49491
Pixa Bank 2.0 SQL Injection via agence-ajax.php API
41RISK
open
Referência
CVE-2018-18955
In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalat
38RISK
open
Referência
CVE-2026-5812
SourceCodester Pharmacy Product Management System POST Parameter add-sales.php logic error
33RISK
open
ReferênciaVexDay Proof
Attachmax Dolphin 2.1.0 - Multiple Vulnerabilities
CVE-2008-4207webappsphp
Attachmax Dolphin 2.1.0 and earlier does not properly protect info.php in the main folder, which allows remote attackers
23RISK
open
ReferênciaVexDay Proof
webid 0.5.4 - Multiple Vulnerabilities
CVE-2008-7117webappsphp
eledicss.php in WeBid auction script 0.5.4 allows remote attackers to modify arbitrary cascading style sheets (CSS) file
23RISK
open
Referência
CVE-2013-1408
Multiple SQL injection vulnerabilities in the Wysija Newsletters plugin before 2.2.1 for WordPress allow remote authenti
23RISK
open
Referência
CVE-2019-2861
Vulnerability in the Oracle Hyperion Planning component of Oracle Hyperion (subcomponent: Security). The supported versi
23RISK
open
Referência
CVE-2017-2480
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud b
23RISK
open
Referência
CVE-2016-6663
Race condition in Oracle MySQL before 5.5.52, 5.6.x before 5.6.33, 5.7.x before 5.7.15, and 8.x before 8.0.1; MariaDB be
23RISK
open
Referência
CVE-2023-31702
SQL injection in the View User Profile in MicroWorld eScan Management Console 14.0.1400.2281 allows remote attacker to d
41RISK
open
previouspage 266 / 723next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.