Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,542cataloged exploits
34,971CVEs with public exploitation
24,695lab-tested
21,899 exploits
Referência
CVE-2017-20275
Joomla! Component PHP-Bridge 1.2.3 SQL Injection via id Parameter
41RISK
open
Referência
CVE-2017-20274
Joomla LMS King Professional 3.2.4.0 SQL Injection via learningpath
41RISK
open
ReferênciaVexDay Proof
Borland Interbase 2007 - 'ibserver.exe' Buffer Overflow (PoC)
CVE-2008-1910doswindows
Stack-based buffer overflow in the database service (ibserver.exe) in Borland InterBase 2007 SP2 allows remote attackers
23RISK
open
Referência
CVE-2017-20273
Joomla Event Registration Pro Calendar 4.1.3 SQL Injection
41RISK
open
Referência
CVE-2017-20272
Joomla Ultimate Property Listing 1.0.2 SQL Injection via sf_selectuser_id
41RISK
open
ReferênciaVexDay Proof
1024 CMS 1.4.2 - Local File Inclusion / Blind SQL Injection
CVE-2008-1911webappsphp
SQL injection vulnerability in includes/system.php in 1024 CMS 1.4.2 beta and earlier, when magic_quotes_gpc is disabled
23RISK
open
ReferênciaVexDay Proof
DivX Player 6.7 - '.srt' File Subtitle Parsing Buffer Overflow
CVE-2008-1912localwindows
Stack-based buffer overflow in DivX Player 6.7 build 6.7.0.22 and earlier allows user-assisted remote attackers to cause
28RISK
open
Referência
CVE-2026-7604
JeecgBoot OpenApi Service OpenApiController.java OpenApiController.call server-side request forgery
33RISK
open
Referência
CVE-2026-5657
Double Free in Wireshark
33RISK
open
Referência
CVE-2018-25299
Prime95 29.4b8 Local Buffer Overflow via SEH
41RISK
open
Referência
CVE-2018-25298
Merge PACS 7.0 Cross-Site Request Forgery via merge-viewer
33RISK
open
Referência
CVE-2026-7401
SourceCodester CET Automated Grading System with AI Predictive Analytics Registration index.php register cross site scripting
33RISK
open
Referência
CVE-2026-7400
geekgod382 filesystem-mcp-server read_file_tool/write_file_tool server.py is_path_allowed path traversal
33RISK
open
ReferênciaVexDay Proof
Watchfire Appscan 7.0 - ActiveX Multiple Insecure Methods
CVE-2008-2015remotewindows
Multiple absolute path traversal vulnerabilities in certain ActiveX controls in WatchFire AppScan 7.0 allow remote attac
23RISK
open
Referência
CVE-2026-7386
fatbobman mail-mcp-bridge mail_mcp_server.py path traversal
33RISK
open
Referência
CVE-2026-7319
elinsky execution-system-mcp add_action Tool server.py _get_context_file_path path traversal
33RISK
open
Referência
CVE-2026-7318
elie mcp-project research_server.py search_papers path traversal
33RISK
open
Referência
CVE-2026-7317
Grav CMS Cache Value FileCache.php doGet deserialization
28RISK
open
Referência
CVE-2026-7316
eiliyaabedini aider-mcp code_with_ai aider_mcp.py command injection
33RISK
open
Referência
CVE-2026-7314
eiceblue spire-doc-mcp-server base.py get_doc_path path traversal
33RISK
open
ReferênciaVexDay Proof
Megabbs Forum 2.2 - SQL Injection / Cross-Site Scripting
CVE-2008-2023webappsasp
Multiple SQL injection vulnerabilities in PD9 Software MegaBBS 2.2 allow remote attackers to execute arbitrary SQL comma
23RISK
open
ReferênciaVexDay Proof
MiniBB 2.2 - Cross-Site Scripting / SQL Injection / Full Path Disclosure
CVE-2008-2024webappsphp
Cross-site scripting (XSS) vulnerability in index.php in miniBB 2.2, and possibly earlier, when register_globals is enab
23RISK
open
ReferênciaVexDay Proof
MiniBB 2.2 - Cross-Site Scripting / SQL Injection / Full Path Disclosure
CVE-2008-2029webappsphp
Multiple SQL injection vulnerabilities in (1) setup_mysql.php and (2) setup_options.php in miniBB 2.2 and possibly earli
23RISK
open
ReferênciaVexDay Proof
Dream4 Koobi Pro 6.25 Poll - 'poll_id' SQL Injection
CVE-2008-2036webappsphp
SQL injection vulnerability in index.php in dream4 Koobi Pro 6.25 allows remote attackers to execute arbitrary SQL comma
23RISK
open
Referência
CVE-2017-20271
Joomla StreetGuessr Game 1.1.8 SQL Injection via catid
41RISK
open
Referência
CVE-2017-20270
Joomla! Component Twitch Tv 1.1 SQL Injection
41RISK
open
Referência
CVE-2017-20269
Joomla! Component KissGallery 1.0.0 SQL Injection
41RISK
open
Referência
CVE-2017-20268
Joomla! Component Zap Calendar Lite 4.3.4 SQL Injection
41RISK
open
Referência
CVE-2017-20267
Joomla! Component Calendar Planner 1.0.1 SQL Injection
41RISK
open
Referência
CVE-2017-20266
Joomla SP Movie Database 1.3 SQL Injection via searchword
41RISK
open
previouspage 316 / 730next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.