Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,107cataloged exploits
34,679CVEs with public exploitation
24,695lab-tested
21,662 exploits
ReferênciaVexDay Proof
gapicms 9.0.2 - 'dirDepth' Remote File Inclusion
CVE-2008-3183webappsphp
PHP remote file inclusion vulnerability in ktmlpro/includes/ktedit/toolbar.php in gapicms 9.0.2 allows remote attackers
23RISK
open
ReferênciaVexDay Proof
HIOX Random Ad 1.3 - Remote File Inclusion
CVE-2008-3401webappsphp
PHP remote file inclusion vulnerability in hioxRandomAd.php in HIOX Random Ad (HRA) 1.3 allows remote attackers to execu
23RISK
open
Referência
CVE-2012-2905
Artiphp CMS 5.5.0 Neo (r422) stores database backups with predictable names under the web root with insufficient access
23RISK
open
Referência
CVE-2017-8912
CMS Made Simple (CMSMS) 2.1.6 allows remote authenticated administrators to execute arbitrary PHP code via the code para
41RISK
open
Referência
CVE-2018-6364
SQL Injection exists in Multilanguage Real Estate MLM Script through 3.0 via the /product-list.php srch parameter.
23RISK
open
Referência
CVE-2018-6364
SQL Injection exists in Multilanguage Real Estate MLM Script through 3.0 via the /product-list.php srch parameter.
23RISK
open
Referência
CVE-2009-4562
Cross-site scripting (XSS) vulnerability in zp-core/admin.php in Zenphoto 1.2.5 allows remote attackers to inject arbitr
23RISK
open
Referência
CVE-2010-4901
Multiple cross-site scripting (XSS) vulnerabilities in char_map.php in MySource Matrix 3.28.3 allow remote attackers to
23RISK
open
ReferênciaVexDay Proof
ExBB Italiano 0.2 - exbb[home_path] Remote File Inclusion
CVE-2006-4488webappsphp
PHP remote file inclusion vulnerability in modules/userstop/userstop.php in ExBB Italia 0.2 and earlier, when register_g
23RISK
open
Referência
CVE-2015-6101
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Wi
23RISK
open
Referência
CVE-2019-20354
The web application component of piSignage before 2.6.4 allows a remote attacker (authenticated as a low-privilege user)
23RISK
open
ReferênciaVexDay Proof
WFTPD Explorer Pro 1.0 - Remote Heap Overflow (PoC)
CVE-2007-6473doswindows
Heap-based buffer overflow in Texas Imperial Software WFTPD Pro Explorer 1.0 allows remote FTP servers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
Stash 1.0.3 - Multiple SQL Injections
CVE-2008-4080webappsphp
SQL injection vulnerability in Stash 1.0.3, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
Scriptsez Easy Image Downloader - Local File Download
CVE-2008-6089webappsphp
Directory traversal vulnerability in main.php in ScriptsEz Easy Image Downloader allows remote attackers to read arbitra
23RISK
open
Referência
CVE-2006-5192
PHP remote file inclusion vulnerability in includes/footer.php in phpGreetz 0.99 and earlier allows remote attackers to
23RISK
open
Referência
CVE-2017-12930
SQL Injection in the admin interface in TecnoVISION DLX Spot Player4 version >1.5.10 allows remote unauthenticated users
23RISK
open
Referência
CVE-2020-25015
A specific router allows changing the Wi-Fi password remotely. Genexis Platinum 4410 V2-1.28, a compact router generally
23RISK
open
Referência
CVE-2021-31762
Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to create a privileged user through Webmin's add users fea
23RISK
open
ReferênciaVexDay Proof
KDPics 1.11 - 'exif.php?lib_path' Remote File Inclusion
CVE-2006-6516webappsphp
Multiple PHP remote file inclusion vulnerabilities in KDPics 1.16 and earlier allow remote attackers to execute arbitrar
23RISK
open
Referência
CVE-2013-5954
Multiple cross-site request forgery (CSRF) vulnerabilities in OpenX 2.8.11 and earlier allow remote attackers to hijack
23RISK
open
Referência
CVE-2018-18755
K-iwi Framework 1775 has SQL Injection via the admin/user/group/update user_group_id parameter or the admin/user/user/up
23RISK
open
Referência
CVE-2018-18755
K-iwi Framework 1775 has SQL Injection via the admin/user/group/update user_group_id parameter or the admin/user/user/up
23RISK
open
ReferênciaVexDay Proof
FlashFXP 3.4.0 build 1145 - Remote Buffer Overflow (Denial of Service) (PoC)
CVE-2007-0825doswindows
FlashFXP 3.4.0 build 1145 allows remote servers to cause a denial of service (CPU consumption) via a response to a PWD c
23RISK
open
ReferênciaVexDay Proof
LiveCMS 3.4 - 'categoria.php?cid' SQL Injection
CVE-2007-3290webappsphp
categoria.php in LiveCMS 3.4 and earlier allows remote attackers to obtain sensitive information via a ' (quote) charact
23RISK
open
ReferênciaVexDay Proof
TorrentTrader Classic 1.07 - Multiple Vulnerabilities
CVE-2007-5311webappsphp
Directory traversal vulnerability in backend/admin-functions.php in TorrentTrader Classic Edition 1.07 allows remote att
23RISK
open
ReferênciaVexDay Proof
phpFastNews 1.0.0 - Insecure Cookie Handling
CVE-2008-4622webappsphp
The isLoggedIn function in fastnews-code.php in phpFastNews 1.0.0 allows remote attackers to bypass authentication and g
23RISK
open
Referência
CVE-2018-9926
An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add an admin account via index.php?m=
23RISK
open
Referência
CVE-2017-14096
A stored cross site scripting (XSS) vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and b
23RISK
open
Referência
CVE-2021-29460
Cross-site scripting (XSS) from unsanitized uploaded SVG files
41RISK
open
ReferênciaVexDay Proof
phpBB lat2cyr Mod 1.0.1 - 'lat2cyr.php' Remote File Inclusion
CVE-2006-5305webappsphp
PHP remote file inclusion vulnerability in lat2cyr.php in the lat2cyr 1.0.1 and earlier phpbb module allows remote attac
23RISK
open
previouspage 268 / 723next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.