Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,496cataloged exploits
34,964CVEs with public exploitation
24,695lab-tested
21,797 exploits
Referência
CVE-2010-2266
nginx 0.8.36 allows remote attackers to cause a denial of service (crash) via certain encoded directory traversal sequen
28RISK
open
ReferênciaVexDay Proof
phpBB Shadow Premod 2.7.1 - Remote File Inclusion
CVE-2006-4664webappsphp
PHP remote file inclusion vulnerability in includes/functions_portal.php in Premod Shadow 2.7.1 and earlier allows remot
23RISK
open
ReferênciaVexDay Proof
VicFTPS < 5.0 - 'CWD' Remote Buffer Overflow (PoC)
CVE-2007-1014doswindows
Stack-based buffer overflow in VicFTPS before 5.0 allows remote attackers to cause a denial of service (application cras
23RISK
open
ReferênciaVexDay Proof
CDNetworks Nefficient Download - 'NeffyLauncher.dll' Code Execution
CVE-2008-1886remotewindows
The NeffyLauncher 1.0.5 ActiveX control (NeffyLauncher.dll) in CDNetworks Nefficient Download uses weak cryptography for
23RISK
open
Referência
CVE-2017-7175
NfSen before 1.3.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the customfmt pa
23RISK
open
Referência
CVE-2015-4592
eClinicalWorks Population Health (CCMR) suffers from an SQL injection vulnerability in portalUserService.jsp which allow
23RISK
open
Referência
CVE-2021-22555
CVE-2021-22555HIGHunder attack
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RISK
open
Referência
CVE-2021-22555
CVE-2021-22555HIGHunder attack
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RISK
open
Referência
CVE-2021-22555
CVE-2021-22555HIGHunder attack
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RISK
open
Referência
CVE-2016-8025
SQL injection vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote authen
23RISK
open
Referência
CVE-2008-7053
LogMeIn Remote Access Utility ActiveX control (RACtrl.dll) allows remote attackers to cause a denial of service (crash)
23RISK
open
Referência
CVE-2009-0886
Directory traversal vulnerability in login.php in OneOrZero Helpdesk 1.6.5.7 and earlier allows remote attackers to read
23RISK
open
Referência
CVE-2014-8770
Unrestricted file upload vulnerability in magmi/web/magmi.php in the MAGMI (aka Magento Mass Importer) plugin 0.7.17a an
23RISK
open
Referência
CVE-2013-5673
SQL injection vulnerability in testimonial.php in the IndiaNIC Testimonial plugin 2.2 for WordPress allows remote attack
23RISK
open
Referência
CVE-2013-5673
SQL injection vulnerability in testimonial.php in the IndiaNIC Testimonial plugin 2.2 for WordPress allows remote attack
23RISK
open
Referência
CVE-2009-4091
comments.php in Simplog 0.9.3.2, and possibly earlier, does not properly restrict access, which allows remote attackers
23RISK
open
ReferênciaVexDay Proof
OneOrZero Helpdesk 1.6.5.7 - Local File Inclusion
CVE-2009-0886webappsphp
Directory traversal vulnerability in login.php in OneOrZero Helpdesk 1.6.5.7 and earlier allows remote attackers to read
23RISK
open
ReferênciaVexDay Proof
FlaP 1.0b - 'pachtofile' Remote File Inclusion
CVE-2007-2940webappsphp
Multiple PHP remote file inclusion vulnerabilities in FlaP 1.0b (1.0 Beta) allow remote attackers to execute arbitrary P
23RISK
open
ReferênciaVexDay Proof
SerWeb 2.0.0 dev1 2007-02-20 - Multiple Local/Remote File Inclusion Vulnerabilities
CVE-2007-6290webappsphp
Multiple directory traversal vulnerabilities in js/get_js.php in SERWeb 2.0.0 dev1 and earlier allow remote attackers to
23RISK
open
ReferênciaVexDay Proof
Maian Guestbook 3.2 - Insecure Cookie Handling
CVE-2008-3320webappsphp
admin/index.php in Maian Guestbook 3.2 and earlier allows remote attackers to bypass authentication and gain administrat
23RISK
open
ReferênciaVexDay Proof
Silentum LoginSys 1.0.0 - Insecure Cookie Handling
CVE-2008-6763webappsphp
login2.php in Silentum LoginSys 1.0.0 allows remote attackers to bypass authentication and obtain access to an arbitrary
23RISK
open
Referência
CVE-2018-4386
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iO
23RISK
open
Referência
CVE-2009-3318
Directory traversal vulnerability in the Roland Breedveld Album (com_album) component 1.14 for Joomla! allows remote att
38RISK
open
ReferênciaVexDay Proof
Opencart 1.1.8 - 'route' Local File Inclusion
CVE-2009-1621webappsphp
Directory traversal vulnerability in index.php in OpenCart 1.1.8 allows remote attackers to read arbitrary files via a .
23RISK
open
Referência
CVE-2019-12137
Typora 0.9.9.24.6 on macOS allows directory traversal, for execution of arbitrary programs, via a file:/// or ../ substr
23RISK
open
Referência
CVE-2016-6503
The CORBA IDL dissectors in Wireshark 2.x before 2.0.5 on 64-bit Windows platforms do not properly interact with Visual
23RISK
open
Referência
CVE-2017-5227
QNAP QTS before 4.2.4 Build 20170313 allows local users to obtain sensitive Domain Administrator password information by
23RISK
open
Referência
CVE-2016-3717
The LABEL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to read arbitrary files vi
28RISK
open
ReferênciaVexDay Proof
Boonex Dolphin 6.1.2 - Multiple Remote File Inclusions
CVE-2008-3167webappsphp
Multiple PHP remote file inclusion vulnerabilities in BoonEx Dolphin 6.1.2, when register_globals is enabled, allow remo
23RISK
open
Referência
CVE-2009-3272
Stack consumption vulnerability in WebKit.dll in WebKit in Apple Safari 3.2.3, and possibly other versions before 4.1.2,
23RISK
open
previouspage 307 / 727next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.