Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,066cataloged exploits
34,679CVEs with public exploitation
24,695lab-tested
21,662 exploits
Referência
CVE-2022-0316
Multiple themes - Unauthenticated Arbitrary File Upload
48RISK
open
Referência
CVE-2013-6364
Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book
23RISK
open
Referência
CVE-2014-125115
Pandora FMS ≤ 5.0 SP2 Default Credential SQL Injection RCE
63RISK
open
Referência
CVE-2014-125115
Pandora FMS ≤ 5.0 SP2 Default Credential SQL Injection RCE
63RISK
open
Referência
CVE-2014-3935
SQL injection vulnerability in glossaire-aff.php in the Glossaire module 1.0 for XOOPS allows remote attackers to execut
23RISK
open
Referência
CVE-2025-5630
D-Link DIR-816 form2lansetup.cgi stack-based overflow
48RISK
open
Referência
CVE-2009-3665
Multiple SQL injection vulnerabilities in index.php in Nullam Blog 0.1.2 allow remote attackers to execute arbitrary SQL
23RISK
open
Referência
CVE-2018-20472
An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. The logs web interface is vulnerable to stored XSS.
23RISK
open
Referência
CVE-2014-2081
Multiple SQL injection vulnerabilities in the login in web_reports/cgi-bin/InfoStation.cgi in Innovative vtls-Virtua bef
23RISK
open
ReferênciaVexDay Proof
MagNet BeeHive CMS (header) - Remote File Inclusion
CVE-2006-3266webappsphp
Multiple PHP remote file inclusion vulnerabilities in Bee-hive Lite 1.2 and earlier, when register_globals is enabled, a
28RISK
open
ReferênciaVexDay Proof
THoRCMS 1.3.1 - 'phpbb_root_path' Remote File Inclusion
CVE-2006-3269webappsphp
PHP remote file inclusion vulnerability in includes/functions_cms.php in THoRCMS 1.3.1 allows remote attackers to execut
23RISK
open
ReferênciaVexDay Proof
Voodoo chat 1.0RC1b - 'users.dat' Password Disclosure
CVE-2006-6890webappsphp
Voodoo chat 1.0RC1b stores sensitive information under the web root with insufficient access control, which allows remot
23RISK
open
ReferênciaVexDay Proof
Prozilla Cheat Script 2.0 - 'id' SQL Injection
CVE-2008-1863webappsphp
SQL injection vulnerability in view_reviews.php in Prozilla Cheat Script (aka Cheats) 2.0 allows remote attackers to exe
23RISK
open
ReferênciaVexDay Proof
Ultrastats 0.2.142 - 'players-detail.php' Blind SQL Injection
CVE-2008-3241webappsphp
SQL injection vulnerability in players-detail.php in UltraStats 0.2.136, 0.2.140, and 0.2.142 allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
ASP Portal - Multiple SQL Injections
CVE-2008-5605webappsasp
Multiple SQL injection vulnerabilities in ASP Portal allow remote attackers to execute arbitrary SQL commands via the (1
23RISK
open
ReferênciaVexDay Proof
Pligg 9.9.5b - Arbitrary File Upload / SQL Injection
CVE-2008-5739webappsphp
SQL injection vulnerability in evb/check_url.php in Pligg CMS 9.9.5 Beta allows remote attackers to execute arbitrary SQ
23RISK
open
ReferênciaVexDay Proof
k-rate - SQL Injection / Cross-Site Scripting
CVE-2008-7097webappsphp
Multiple SQL injection vulnerabilities in Qsoft K-Rate Premium allow remote attackers to execute arbitrary SQL commands
23RISK
open
ReferênciaVexDay Proof
2DayBiz Template Monster Clone - 'edituser.php' Change Pass
CVE-2009-1767webappsphp
admin/edituser.php in 2daybiz Template Monster Clone does not require administrative authentication, which allows remote
23RISK
open
Referência
CVE-2014-4741
SQL injection vulnerability in demo/ads.php in Artifectx xClassified 1.2 allows remote attackers to execute arbitrary SQ
23RISK
open
Referência
CVE-2014-9242
SQL injection vulnerability in admin/pages/modify.php in WebsiteBaker 2.8.3 allows remote attackers to execute arbitrary
23RISK
open
Referência
CVE-2017-17737
The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) has XSS via the REF parameter to /network_diag
23RISK
open
Referência
CVE-2011-4026
SQL injection vulnerability in thanks.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via
23RISK
open
Referência
CVE-2023-31903
GuppY CMS 6.00.10 is vulnerable to Unrestricted File Upload which allows remote attackers to execute arbitrary code by u
48RISK
open
Referência
CVE-2020-17382
The MSI AmbientLink MsIo64 driver 1.0.0.8 has a Buffer Overflow (0x80102040, 0x80102044, 0x80102050,and 0x80102054).
23RISK
open
Referência
CVE-2013-7043
Multiple cross-site request forgery (CSRF) vulnerabilities on Cisco Scientific Atlanta DPR2320R2 routers with software 2
23RISK
open
ReferênciaVexDay Proof
PHPEasyData Pro 2.2.2 - 'index.php' SQL Injection
CVE-2006-5707webappsphp
SQL injection vulnerability in index.php in PHPEasyData Pro 1.4.1 and 2.2.1 allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
AuraCMS 2.1 - Remote File Attachment / Local File Inclusion
CVE-2007-4886webappsphp
Incomplete blacklist vulnerability in index.php in AuraCMS 1.x and probably 2.x allows remote attackers to execute arbit
23RISK
open
ReferênciaVexDay Proof
WebSihirbazi 5.1.1 - 'pageid' SQL Injection
CVE-2007-6556webappsphp
Multiple SQL injection vulnerabilities in websihirbazi 5.1.1 allow remote attackers to execute arbitrary SQL commands vi
23RISK
open
ReferênciaVexDay Proof
Joomla! Component mediaslide - 'albumnum' Blind SQL Injection
CVE-2008-0802webappsphp
SQL injection vulnerability in index.php in the MediaSlide (com_mediaslide) 0.5 component for Joomla! allows remote atta
23RISK
open
ReferênciaVexDay Proof
Joomla! Component Acajoom 1.1.5 - SQL Injection
CVE-2008-1427webappsphp
SQL injection vulnerability in the Joobi Acajoom (com_acajoom) 1.1.5 and 1.2.5 component for Joomla! allows remote attac
23RISK
open
previouspage 267 / 723next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.