Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,316cataloged exploits
34,835CVEs with public exploitation
24,695lab-tested
21,797 exploits
Referência
CVE-2015-7893
SecEmailUI in Samsung Galaxy S6 does not sanitize HTML email content, allows remote attackers to execute arbitrary JavaS
23RISK
open
Referência
CVE-2015-7893
SecEmailUI in Samsung Galaxy S6 does not sanitize HTML email content, allows remote attackers to execute arbitrary JavaS
23RISK
open
ReferênciaVexDay Proof
Fuzzylime CMS 3.0 - Local File Inclusion
CVE-2007-4805webappsphp
Directory traversal vulnerability in getgalldata.php in fuzzylime (cms) 3.0 and earlier allows remote attackers to inclu
23RISK
open
Referência
CVE-2009-3327
Multiple SQL injection vulnerabilities in WX-Guestbook 1.1.208 allow remote attackers to execute arbitrary SQL commands
23RISK
open
Referência
CVE-2013-6040
MW6 Aztec, DataMatrix, and MaxiCode ActiveX controls versions before 4.0 are vulnerable to arbitrary code via crafted HTML document.
41RISK
open
Referência
CVE-2013-6040
MW6 Aztec, DataMatrix, and MaxiCode ActiveX controls versions before 4.0 are vulnerable to arbitrary code via crafted HTML document.
41RISK
open
ReferênciaVexDay Proof
TeamCalPro 3.1.000 - Multiple Local/Remote File Inclusions
CVE-2007-6554webappsphp
Multiple directory traversal vulnerabilities in TeamCal Pro 3.1.000 and earlier allow remote attackers to include and ex
23RISK
open
ReferênciaVexDay Proof
Apache 2.2.14 mod_isapi - Dangling Pointer Remote SYSTEM
CVE-2010-0425remotewindows
modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2
60RISK
open
Referência
CVE-2020-5295
Local File read vulnerability in OctoberCMS
33RISK
open
ReferênciaVexDay Proof
Professional Download Assistant 0.1 - Database Disclosure
CVE-2008-5572webappsasp
Professional Download Assistant 0.1 stores sensitive information under the web root with insufficient access control, wh
23RISK
open
ReferênciaVexDay Proof
CoolPlayer 2.19 - '.Skin' Local Buffer Overflow
CVE-2008-5735localwindows
Stack-based buffer overflow in skin.c in CoolPlayer 2.17 through 2.19 allows remote attackers to execute arbitrary code
23RISK
open
Referência
CVE-2009-4841
Heap-based buffer overflow in the SonicMediaPlayer ActiveX control in SonicMediaPlayer.dll in Roxio CinePlayer 3.2 allow
23RISK
open
Referência
CVE-2012-1466
The Traffic Grapher Server for NetMechanica NetDecision before 4.6.1 allows remote attackers to obtain the source code o
23RISK
open
Referência
CVE-2012-1464
Dashboard Server for NetMechanica NetDecision before 4.6.1 allows remote attackers to obtain the installation path via a
23RISK
open
ReferênciaVexDay Proof
DS-IPN.NET Digital Sales IPN - Database Disclosure
CVE-2009-0328webappsasp
ROBS-PROJECTS Digital Sales IPN (aka DS-IPN.NET or DS-IPN Paypal Shop) stores sensitive information under the web root w
23RISK
open
Referência
CVE-2018-1120
A flaw was found affecting the Linux kernel before version 4.17. By mmap()ing a FUSE-backed file onto a process's memory
28RISK
open
Referência
CVE-2025-34515
Ilevia EVE X1 Server 4.7.18.0.eden Root Privilege Escalation
48RISK
open
Referência
CVE-2021-3355
A stored-self XSS exists in LightCMS v1.3.4, allowing an attacker to execute HTML or JavaScript code in a vulnerable Tit
23RISK
open
Referência
CVE-2009-3335
SQL injection vulnerability in the TurtuShout component 0.11 for Joomla! allows remote attackers to execute arbitrary SQ
23RISK
open
ReferênciaVexDay Proof
HP-UX 11i - 'swask' Format String Privilege Escalation
CVE-2006-5558localhp-ux
Format string vulnerability in the swask command in HP-UX B.11.11 and possibly other versions allows local users to exec
23RISK
open
Referência
CVE-2009-3336
SQL injection vulnerability in auction_details.php in PHP Pro Bid allows remote attackers to execute arbitrary SQL comma
23RISK
open
ReferênciaVexDay Proof
Ourgame GLWorld 2.x - 'hgs_startNotify()' ActiveX Buffer Overflow
CVE-2008-0647remotewindows
Multiple stack-based buffer overflows in the HanGamePluginCn18.HanGamePluginCn18.1 ActiveX control in HanGamePluginCn18.
23RISK
open
ReferênciaVexDay Proof
LoveCMS 1.6.2 Final (Simple Forum 3.1d) - Change Admin Password
CVE-2008-5308webappsphp
The Simple Forum 3.1d module for LoveCMS 1.6.2 Final does not properly restrict access to administrator functions, which
23RISK
open
Referência
CVE-2019-10677
Multiple Cross-Site Scripting (XSS) issues in the web interface on DASAN Zhone ZNID GPON 2426A EU version S3.1.285 devic
23RISK
open
Referência
Microsoft Windows 11 Pro 23H2 - Ancillary Function Driver for WinSock Privilege Escalation
CVE-2024-38193HIGHunder attacklocalwindows
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
76RISK
open
Referência
CVE-2017-7048
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISK
open
Referência
CVE-2016-1252
The apt package in Debian jessie before 1.0.9.8.4, in Debian unstable before 1.4~beta2, in Ubuntu 14.04 LTS before 1.0.1
23RISK
open
Referência
CVE-2016-1252
The apt package in Debian jessie before 1.0.9.8.4, in Debian unstable before 1.4~beta2, in Ubuntu 14.04 LTS before 1.0.1
23RISK
open
Referência
CVE-2015-1726
Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista S
23RISK
open
Referência
CVE-2009-1561
Cross-site request forgery (CSRF) vulnerability in administration.cgi on the Cisco Linksys WRT54GC router with firmware
23RISK
open
previouspage 305 / 727next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.