Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,608cataloged exploits
34,986CVEs with public exploitation
24,695lab-tested
21,899 exploits
Referência
CVE-2025-15500
Sangfor Operation and Maintenance Management System HTTP POST Request getHis os command injection
48RISK
open
ReferênciaVexDay Proof
MW6 Barcode - ActiveX 'Barcode.dll' Remote Heap Overflow (PoC)
CVE-2009-0298doswindows
Heap-based buffer overflow in MW6 Technologies Barcode ActiveX control (Barcode.MW6Barcode.1, Barcode.dll) 3.0.0.1 allow
23RISK
open
Referência
CVE-2017-13056
The launchURL function in PDF-XChange Viewer 2.5 (Build 314.0) might allow remote attackers to execute arbitrary code vi
23RISK
open
ReferênciaVexDay Proof
Firefly Media Server 0.2.4 - Remote Denial of Service
CVE-2007-5824doslinux
webserver.c in mt-dappd in Firefly Media Server 0.2.4 and earlier allows remote attackers to cause a denial of service (
23RISK
open
Referência
CVE-2009-4836
Eval injection vulnerability in system/services/init.php in Movie PHP Script 2.0 allows remote attackers to execute arbi
23RISK
open
ReferênciaVexDay Proof
DesignWorks Professional 4.3.1 - '.CCT' File Local Stack Buffer Overflow (PoC)
CVE-2008-6363doswindows
Stack-based buffer overflow in DesignWorks Professional 4.3.1 and 5.0.7 allows remote attackers to execute arbitrary cod
23RISK
open
Referência
CVE-2017-0167
An information disclosure vulnerability exists in Windows 8.1, Windows RT 8.1, Windows Server 2012 R2, Windows 10, and W
23RISK
open
Referência
CVE-2009-4668
Stack-based buffer overflow in JetCast.exe 2.0.4.1109 in jetAudio 7.5.2 and 7.5.3.15 allows remote attackers to execute
23RISK
open
Referência
CVE-2009-2896
Buffer overflow in KMplayer 2.9.4.1433 and earlier allows remote attackers to cause a denial of service (application cra
23RISK
open
Referência
CVE-2010-2440
Stack-based buffer overflow in st-wizard.exe in Subtitle Translation Wizard 3.0 allows user-assisted remote attackers to
23RISK
open
Referência
CVE-2010-2331
Stack-based buffer overflow in iSharer File Sharing Wizard 1.5.0 allows remote attackers to execute arbitrary code via a
23RISK
open
Referência
CVE-2006-7127
Multiple PHP remote file inclusion vulnerabilities in JAF CMS 4.0 and 4.0 RC2 allow remote attackers to execute arbitrar
23RISK
open
Referência
CVE-2010-1049
Multiple SQL injection vulnerabilities in Uiga Business Portal allow remote attackers to execute arbitrary SQL commands
23RISK
open
Referência
CVE-2015-5529
Multiple cross-site scripting (XSS) vulnerabilities in Free Reprintables ArticleFR 3.0.6 allow remote attackers to injec
23RISK
open
Referência
CVE-2010-1050
SQL injection vulnerability in index.php in AudiStat 1.3 allows remote attackers to execute arbitrary SQL commands via t
23RISK
open
Referência
Tatsu 3.3.11 - Unauthenticated RCE
CVE-2021-25094webappsphp
Tatsu < 3.3.12 - Unauthenticated RCE
60RISK
open
Referência
CVE-2012-3845
Buffer overflow in LAN Messenger 1.2.28 and earlier allows remote attackers to cause a denial of service (crash) via a l
23RISK
open
Referência
CVE-2010-1054
Multiple SQL injection vulnerabilities in ParsCMS allow remote attackers to execute arbitrary SQL commands via the RP pa
23RISK
open
Referência
CVE-2009-4758
Stack-based buffer overflow in dicas Mpegable Player 2.12 allows remote attackers to cause a denial of service (applicat
23RISK
open
Referência
CVE-2008-3430
Buffer overflow in the CoVideoWindow.ocx ActiveX control 5.0.907.1 in Eyeball MessengerSDK, as used in products such as
23RISK
open
Referência
CVE-2021-43116
An Access Control vulnerability exists in Nacos 2.0.3 in the access prompt page; enter username and password, click on l
23RISK
open
Referência
CVE-2014-5094
Status2k allows remote attackers to obtain configuration information via a phpinfo action in a request to status/index.p
23RISK
open
Referência
CVE-2015-2841
Citrix NetScaler AppFirewall, as used in NetScaler 10.5, allows remote attackers to bypass intended firewall restriction
23RISK
open
Referência
CVE-2016-6186
Cross-site scripting (XSS) vulnerability in the dismissChangeRelatedObjectPopup function in contrib/admin/static/admin/j
23RISK
open
Referência
CVE-2016-6186
Cross-site scripting (XSS) vulnerability in the dismissChangeRelatedObjectPopup function in contrib/admin/static/admin/j
23RISK
open
Referência
CVE-2017-13861
An issue was discovered in certain Apple products. iOS before 11.2 is affected. tvOS before 11.2 is affected. watchOS be
43RISK
open
Referência
D-Link DIR-615 - Privilege Escalation
CVE-2019-19743webappshardware
On D-Link DIR-615 devices, a normal user is able to create a root(admin) user from the D-Link portal.
23RISK
open
Referência
CVE-2015-7249
ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allow remote authenticated users to bypass intended access r
23RISK
open
ReferênciaVexDay Proof
e107 - 'include()' Remote File Upload
CVE-2004-2262webappsphp
ImageManager in e107 before 0.617 does not properly check the types of uploaded files, which allows remote attackers to
28RISK
open
ReferênciaVexDay Proof
GeoVision LiveX 8200 - ActiveX 'LIVEX_~1.OCX' File Corruption
CVE-2009-0865remotewindows
Directory traversal vulnerability in the SnapShotToFile method in the GeoVision LiveX (aka LiveX_v8200) ActiveX control
23RISK
open
previouspage 325 / 730next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.