Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,313cataloged exploits
34,834CVEs with public exploitation
24,695lab-tested
21,797 exploits
Referência
CVE-2009-4806
admin/save_user.asp in Digital Interchange Document Library 1.0.1 does not require administrative authentication, which
23RISK
open
Referência
CVE-2019-0881
An elevation of privilege vulnerability exists when the Windows Kernel improperly handles key enumeration, aka 'Windows
23RISK
open
Referência
CVE-2026-5534
itsourcecode Online Enrollment System Parameter index.php sql injection
33RISK
open
Referência
CVE-2016-6851
An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code can be provided as parameter to the OX G
23RISK
open
Referência
CVE-2016-6851
An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code can be provided as parameter to the OX G
23RISK
open
ReferênciaVexDay Proof
BASE 1.2.4 - melissa Snort Frontend Remote File Inclusion
CVE-2006-2685webappsphp
PHP remote file inclusion vulnerability in Basic Analysis and Security Engine (BASE) 1.2.4 and earlier, with register_gl
50RISK
open
ReferênciaVexDay Proof
CCleague Pro 1.0.1RC1 - 'cookie' Remote Code Execution
CVE-2006-4721webappsphp
Directory traversal vulnerability in admin.php in CCleague Pro Sports CMS 1.0.1 RC1 allows remote attackers to read and
23RISK
open
Referência
CVE-2013-2594
SQL injection vulnerability in reports/calldiary.php in Hornbill Supportworks ITSM 1.0.0 through 3.4.14 allows remote at
23RISK
open
Referência
CVE-2013-2594
SQL injection vulnerability in reports/calldiary.php in Hornbill Supportworks ITSM 1.0.0 through 3.4.14 allows remote at
23RISK
open
Referência
CVE-2026-5533
badlogic pi-mono SVG Artifact SvgArtifact.ts cross site scripting
33RISK
open
ReferênciaVexDay Proof
GL-SH Deaf Forum 6.4.4 - Local File Inclusion
CVE-2007-3535webappsphp
Multiple directory traversal vulnerabilities in GL-SH Deaf Forum 6.4.4 and earlier allow remote attackers to include and
23RISK
open
ReferênciaVexDay Proof
Scribe 0.2 - PHP Remote Code Execution
CVE-2007-5823webappsphp
Directory traversal vulnerability in forum.php in Ben Ng Scribe 0.2 and earlier allows remote attackers to create or ove
23RISK
open
ReferênciaVexDay Proof
Oxygen 2.0 - 'repquote' SQL Injection
CVE-2008-2816webappsphp
SQL injection vulnerability in post.php in Oxygen (aka O2PHP Bulletin Board) 2.0 allows remote attackers to execute arbi
23RISK
open
ReferênciaVexDay Proof
Nitro Web Gallery 1.4.3 - 'section' SQL Injection
CVE-2008-2817webappsphp
SQL injection vulnerability in albums.php in NiTrO Web Gallery 1.4.3 and earlier allows remote attackers to execute arbi
23RISK
open
ReferênciaVexDay Proof
SlimCMS 1.0.0 - 'redirect.php' Privilege Escalation
CVE-2008-5708webappsphp
redirect.php in SlimCMS 1.0.0 does not require authentication, which allows remote attackers to create administrative us
23RISK
open
ReferênciaVexDay Proof
RPortal 1.1 - 'file_op' Remote File Inclusion
CVE-2008-6099webappsphp
PHP remote file inclusion vulnerability in index.php in RPortal 1.1 and earlier allows remote attackers to execute arbit
23RISK
open
Referência
CVE-2018-19041
The Media File Manager plugin 1.4.2 for WordPress allows XSS via the dir parameter of an mrelocator_getdir action to the
23RISK
open
Referência
CVE-2022-47877
A Stored cross-site scripting vulnerability in Jedox 2020.2.5 allows remote, authenticated users to inject arbitrary web
48RISK
open
Referência
CVE-2017-12971
Cross-site scripting (XSS) vulnerability in Apache2Triad 1.5.4 allows remote attackers to inject arbitrary web script or
23RISK
open
Referência
CVE-2017-12971
Cross-site scripting (XSS) vulnerability in Apache2Triad 1.5.4 allows remote attackers to inject arbitrary web script or
23RISK
open
Referência
CVE-2010-4330
Directory traversal vulnerability in includes/controller.php in Pulse CMS Basic before 1.2.9 allows remote attackers to
23RISK
open
Referência
CVE-2026-27476
RustFly 2.0.0 Command Injection via UDP Remote Control
48RISK
open
Referência
CVE-2023-23286
Cross Site Scripting (XSS) vulnerability in Provide server 14.4 allows attackers to execute arbitrary code through the s
33RISK
open
Referência
CVE-2018-18760
RhinOS 3.0 build 1190 allows CSRF.
23RISK
open
Referência
CVE-2018-18760
RhinOS 3.0 build 1190 allows CSRF.
23RISK
open
Referência
CVE-2019-11564
A cross-site scripting (XSS) vulnerability in HumHub 1.3.12 allows remote attackers to inject arbitrary web script or HT
23RISK
open
Referência
CVE-2010-1301
SQL injection vulnerability in main.php in Centreon 2.1.5 allows remote attackers to execute arbitrary SQL commands via
23RISK
open
Referência
CVE-2010-1301
SQL injection vulnerability in main.php in Centreon 2.1.5 allows remote attackers to execute arbitrary SQL commands via
23RISK
open
Referência
CVE-2017-8382
admidio 3.2.8 has CSRF in adm_program/modules/members/members_function.php with an impact of deleting arbitrary user acc
23RISK
open
Referência
CVE-2017-8382
admidio 3.2.8 has CSRF in adm_program/modules/members/members_function.php with an impact of deleting arbitrary user acc
23RISK
open
previouspage 293 / 727next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.