Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,313cataloged exploits
34,834CVEs with public exploitation
24,695lab-tested
21,797 exploits
Referência
CVE-2010-1057
Multiple directory traversal vulnerabilities in Phpkobo AdFreely (aka Ad Board Script) 1.01, when magic_quotes_gpc is di
23RISK
open
Referência
CVE-2018-18417
In the 3.1 version of Ekushey Project Manager CRM, Stored XSS has been discovered in the input and upload sections, as d
23RISK
open
Referência
CVE-2018-18417
In the 3.1 version of Ekushey Project Manager CRM, Stored XSS has been discovered in the input and upload sections, as d
23RISK
open
Referência
CVE-2012-4254
MySQLDumper 1.24.4 allows remote attackers to obtain sensitive information (Notices) via a direct request to (1) learn/c
23RISK
open
Referência
CVE-2025-65008
OS Command Injection in WODESYS WD-R608U router
48RISK
open
ReferênciaVexDay Proof
DreamAccount 3.1 - 'da_path' Remote File Inclusion
CVE-2006-2881webappsphp
Multiple PHP remote file inclusion vulnerabilities in DreamAccount 3.1 and earlier, when register_globals is enabled, al
28RISK
open
ReferênciaVexDay Proof
PHPMyphorum 1.5a - '/mep/frame.php' Remote File Inclusion
CVE-2007-0361webappsphp
PHP remote file inclusion vulnerability in mep/frame.php in PHPMyphorum 1.5a allows remote attackers to execute arbitrar
23RISK
open
ReferênciaVexDay Proof
Drunken:Golem Portal 0.5.1 Alpha 2 - Remote File Inclusion
CVE-2007-0572webappsphp
PHP remote file inclusion vulnerability in include/irc/phpIRC.php in Drunken:Golem Gaming Portal 0.5.1 Alpha 2 and earli
23RISK
open
Referência
CVE-2010-1739
SQL injection vulnerability in the Newsfeeds (com_newsfeeds) component for Joomla! allows remote attackers to execute ar
23RISK
open
ReferênciaVexDay Proof
Net-Side.net CMS - 'index.php?cms' Remote File Inclusion
CVE-2007-1707webappsphp
PHP remote file inclusion vulnerability in index.php in Net Side Content Management System (Net-Side.net CMS) allows rem
23RISK
open
ReferênciaVexDay Proof
Free Image Hosting 2.0 - 'AD_BODY_TEMP' Remote File Inclusion
CVE-2007-1715webappsphp
PHP remote file inclusion vulnerability in frontpage.php in Free Image Hosting 2.0 and earlier allows remote attackers t
23RISK
open
Referência
CVE-2019-9625
JBMC DirectAdmin 1.55 allows CSRF via the /CMD_ACCOUNT_ADMIN URI to create a new admin account.
23RISK
open
ReferênciaVexDay Proof
EHCP 0.22.8 - Multiple Remote File Inclusions
CVE-2007-6178webappsphp
Multiple PHP remote file inclusion vulnerabilities in Easy Hosting Control Panel for Ubuntu (EHCP) 0.22.8 and earlier al
23RISK
open
ReferênciaVexDay Proof
Affiliate Market 0.1 Beta - 'Language' Local File Inclusion
CVE-2008-0794webappsphp
Directory traversal vulnerability in user/header.php in Affiliate Market 0.1 BETA allows remote attackers to include and
23RISK
open
ReferênciaVexDay Proof
Clever Copy 3.0 - 'results.php' SQL Injection
CVE-2008-2909webappsphp
SQL injection vulnerability in results.php in Clever Copy 3.0 allows remote attackers to execute arbitrary SQL commands
23RISK
open
ReferênciaVexDay Proof
Contenido 4.8.4 - Remote File Inclusion / Cross-Site Scripting
CVE-2008-2911webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Contenido 4.8.4 allow remote attackers to inject arb
23RISK
open
ReferênciaVexDay Proof
Pre Job Board - 'JobSearch.php' SQL Injection
CVE-2008-2915webappsphp
Multiple SQL injection vulnerabilities in jobseekers/JobSearch.php (aka the search module) in Pre Job Board allow remote
23RISK
open
ReferênciaVexDay Proof
Pre ADS Portal 2.0 - SQL Injection
CVE-2008-2916webappsphp
Multiple SQL injection vulnerabilities in Pre ADS Portal 2.0 and earlier, when magic_quotes_gpc is disabled, allow remot
23RISK
open
ReferênciaVexDay Proof
E-Smart Cart - 'productsofcat.asp' SQL Injection
CVE-2008-2917webappsasp
SQL injection vulnerability in productsofcat.asp in E-SMART CART allows remote attackers to execute arbitrary SQL comman
23RISK
open
ReferênciaVexDay Proof
LokiCMS 0.3.4 - 'admin.php' Create Local File Inclusion
CVE-2008-4662webappsphp
Directory traversal vulnerability in admin.php in LokiCMS 0.3.4, when magic_quotes_gpc is disabled, allows remote attack
23RISK
open
ReferênciaVexDay Proof
CodeAvalanche RateMySite - Database Disclosure
CVE-2008-5896webappsasp
CodeAvalanche RateMySite stores sensitive information under the web root with insufficient access control, which allows
23RISK
open
Referência
CVE-2013-10042
freeFTPd <= 1.0.10 PASS Command Stack-Based Buffer Overflow
63RISK
open
Referência
CVE-2013-10042
freeFTPd <= 1.0.10 PASS Command Stack-Based Buffer Overflow
63RISK
open
Referência
CVE-2009-3508
Multiple directory traversal vulnerabilities in MUJE CMS 1.0.4.34 allow remote attackers to include and execute arbitrar
23RISK
open
Referência
CVE-2008-2701
SQL injection vulnerability in the GameQ (com_gameq) component 4.0 and earlier for Joomla! allows remote attackers to ex
23RISK
open
Referência
CVE-2018-11445
A CSRF issue was discovered on the User Add/System Settings Page (system-settings-user-new2.php) in EasyService Billing
23RISK
open
Referência
CVE-2018-0832
The Windows kernel in Windows 8.1 and RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Window
23RISK
open
Referência
CVE-2018-0894
The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Serve
23RISK
open
Referência
CVE-2018-11442
A CSRF issue was discovered in EasyService Billing 1.0, which was triggered via a quotation-new3-new2.php?add=true&id= U
23RISK
open
ReferênciaVexDay Proof
FunkBoard CF0.71 - 'profile.php' Remote User Pass Change
CVE-2006-2896webappsphp
profile.php in FunkBoard CF0.71 allows remote attackers to change arbitrary passwords via a modified uid hidden form fie
23RISK
open
previouspage 298 / 727next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.