Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,107cataloged exploits
34,679CVEs with public exploitation
24,695lab-tested
21,662 exploits
Referência
CVE-2019-13029
Multiple stored Cross-site scripting (XSS) issues in the admin panel and survey system in REDCap 8 before 8.10.20 and 9
23RISK
open
Referência
CVE-2018-12111
Cross-site scripting (XSS) vulnerability in the Canon PrintMe EFI webinterface allows remote attackers to inject arbitra
23RISK
open
Referência
CVE-2014-1915
Multiple cross-site request forgery (CSRF) vulnerabilities in Command School Student Management System 1.06.01 allow rem
23RISK
open
Referência
CVE-2018-15844
An issue was discovered in DamiCMS 6.0.0. There is an CSRF vulnerability that can revise the administrator account's pas
23RISK
open
Referência
CVE-2012-2586
Multiple cross-site scripting (XSS) vulnerabilities in Mailtraq 2.17.3.3150 allow remote attackers to inject arbitrary w
23RISK
open
Referência
CVE-2021-32403
Intelbras Router RF 301K Firmware 1.1.2 is vulnerable to Cross Site Request Forgery (CSRF) due to lack of security mecha
23RISK
open
Referência
CVE-2012-2578
Multiple cross-site scripting (XSS) vulnerabilities in SmarterMail 9.2 allow remote attackers to inject arbitrary web sc
23RISK
open
Referência
CVE-2014-5100
Multiple cross-site request forgery (CSRF) vulnerabilities in Omeka before 2.2.1 allow remote attackers to hijack the au
23RISK
open
Referência
CVE-2014-5100
Multiple cross-site request forgery (CSRF) vulnerabilities in Omeka before 2.2.1 allow remote attackers to hijack the au
23RISK
open
Referência
CVE-2017-14620
SmarterStats Version 11.3.6347 will Render the Referer Field of HTTP Logfiles from URL /Data/Reports/ReferringURLsWithQu
23RISK
open
ReferênciaVexDay Proof
Newswriter SW 1.4.2 - 'main.inc.php' Remote File Inclusion
CVE-2006-5180webappsphp
PHP remote file inclusion vulnerability in include/main.inc.php in Sebastian Baumann and Philipp Wolfer Newswriter SW 1.
23RISK
open
ReferênciaVexDay Proof
PHPAdventure 1.1 - 'ad_main.php' Remote File Inclusion
CVE-2006-5839webappsphp
PHP remote file inclusion vulnerability in ad_main.php in PHPAdventure 1.1-Alpha and earlier allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
PHP Coupon Script 3.0 - 'bus' SQL Injection
CVE-2007-2672webappsphp
SQL injection vulnerability in index.php in PHP Coupon Script 3.0 allows remote attackers to execute arbitrary SQL comma
23RISK
open
ReferênciaVexDay Proof
xml2owl 0.1.1 - 'showcode.php' Remote Command Execution
CVE-2007-6632webappsphp
showCode.php in xml2owl 0.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the path
23RISK
open
ReferênciaVexDay Proof
asiCMS alpha 0.208 - Multiple Remote File Inclusions
CVE-2008-4529webappsphp
Multiple PHP remote file inclusion vulnerabilities in asiCMS alpha 0.208 allow remote attackers to execute arbitrary PHP
23RISK
open
ReferênciaVexDay Proof
Micro CMS 0.3.5 - Remote Add/Delete/Password Change
CVE-2008-6553webappsphp
microcms-admin-home.php in Implied by Design Micro CMS (Micro-CMS) 3.5 (aka 0.3.5) does not require authentication as an
23RISK
open
Referência
CVE-2010-3603
Cross-site request forgery (CSRF) vulnerability in the file manager service (Services/FileService.ashx) in mojoPortal 2.
23RISK
open
Referência
CVE-2010-3603
Cross-site request forgery (CSRF) vulnerability in the file manager service (Services/FileService.ashx) in mojoPortal 2.
23RISK
open
Referência
CVE-2018-14497
Tenda D152 ADSL routers allow XSS via a crafted SSID.
23RISK
open
Referência
CVE-2018-0901
The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Serve
23RISK
open
Referência
CVE-2010-2656
The IBM BladeCenter with Advanced Management Module (AMM) firmware build ID BPET48L, and possibly other versions before
23RISK
open
Referência
CVE-2009-4825
8pixel.net Blog 4 stores sensitive information under the web root with insufficient access control, which allows remote
23RISK
open
Referência
CVE-2009-4820
Angelo-Emlak 1.0 stores sensitive information under the web root with insufficient access control, which allows remote a
23RISK
open
Referência
CVE-2010-2709
Stack-based buffer overflow in webappmon.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote at
50RISK
open
Referência
CVE-2009-4929
admin/manage_users.php in TotalCalendar 2.4 does not require administrative authentication, which allows remote attacker
23RISK
open
Referência
CVE-2009-4056
Directory traversal vulnerability in admin/popup.php in Betsy CMS 3.5 allows remote attackers to include and execute arb
23RISK
open
Referência
CVE-2010-2714
SQL injection vulnerability in photos/index.php in TCW PHP Album 1.0 allows remote attackers to execute arbitrary SQL co
23RISK
open
Referência
CVE-2009-4471
Multiple PHP remote file inclusion vulnerabilities in FreeSchool 1.1.0 and earlier allow remote attackers to execute arb
23RISK
open
ReferênciaVexDay Proof
Bradabra 2.0.5 - '/include/includes.php' Remote File Inclusion
CVE-2007-0500webappsphp
PHP remote file inclusion vulnerability in include/includes.php in Bradabra 2.0.5 and earlier allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
mxBB Module ErrorDocs 1.0 - 'common.php' Remote File Inclusion
CVE-2006-6545webappsphp
PHP remote file inclusion vulnerability in includes/common.php in the ErrorDocs 1.0.0 and earlier module for mxBB (mx_er
23RISK
open
previouspage 273 / 723next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.