Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,647cataloged exploits
34,986CVEs with public exploitation
24,695lab-tested
21,899 exploits
ReferênciaVexDay Proof
Advanced Webhost Billing System (AWBS) 2.4.0 - 'cart2.php' Remote File Inclusion
CVE-2007-2272webappsphp
PHP remote file inclusion vulnerability in docs/front-end-demo/cart2.php in Advanced Webhost Billing System (AWBS) 2.4.0
23RISK
open
Referência
CVE-2009-3019
Microsoft Internet Explorer 6 on Windows XP SP2 and SP3, and Internet Explorer 7 on Vista, allows remote attackers to ca
28RISK
open
Referência
CVE-2017-7183
The TFTP server in ExtraPuTTY 0.30 and earlier allows remote attackers to cause a denial of service (crash) via a large
23RISK
open
Referência
CVE-2018-16606
In ProConf before 6.1, an Insecure Direct Object Reference (IDOR) allows any author to view and grab all submitted paper
23RISK
open
Referência
CVE-2009-3531
SQL injection vulnerability in vnews.php in Universe CMS 1.0.6 allows remote attackers to execute arbitrary SQL commands
23RISK
open
ReferênciaVexDay Proof
Microsoft FoxServer - 'vfp6r.dll 6.0.8862.0' ActiveX Command Execution
CVE-2008-0236remotewindows
An ActiveX control for Microsoft Visual FoxPro (vfp6r.dll 6.0.8862.0) allows remote attackers to execute arbitrary comma
28RISK
open
Referência
CVE-2009-3534
Directory traversal vulnerability in index.php in LionWiki 3.0.3, when magic_quotes_gpc is disabled, allows remote attac
23RISK
open
ReferênciaVexDay Proof
PhpAddEdit 1.3 - 'cookie' Authentication Bypass
CVE-2008-6581webappsphp
login.php in PhpAddEdit 1.3 allows remote attackers to bypass authentication and gain administrative access by setting t
23RISK
open
Referência
CVE-2014-1618
Multiple SQL injection vulnerabilities in UAEPD Shopping Cart Script allow remote attackers to execute arbitrary SQL com
23RISK
open
Referência
CVE-2010-0944
Directory traversal vulnerability in the JCollection (com_jcollection) component for Joomla! allows remote attackers to
43RISK
open
Referência
CVE-2009-3536
Multiple stack-based buffer overflows in EpicDJSoftware EpicVJ 1.2.8.0 and 1.3.1.2 allow remote attackers to cause a den
23RISK
open
Referência
CVE-2009-2384
Buffer overflow in amp.exe in Brothersoft PEamp 1.02b allows user-assisted remote attackers to execute arbitrary code vi
23RISK
open
Referência
CVE-2019-16758
In Lexmark Services Monitor 2.27.4.0.39 (running on TCP port 2070), a remote attacker can use a directory traversal tech
28RISK
open
Referência
CVE-2018-15691
Insecure deserialization of a specially crafted serialized object, in CA Release Automation 6.5 and earlier, allows atta
28RISK
open
Referência
CVE-2026-29000
pac4j-jwt JwtAuthenticator Authentication Bypass
48RISK
open
Referência
CVE-2016-5680
Stack-based buffer overflow in cgi-bin/cgi_main in NUUO NVRmini 2 1.7.6 through 3.0.0 and NETGEAR ReadyNAS Surveillance
28RISK
open
ReferênciaVexDay Proof
FTPShell Server 4.3 - Licence Key Remote Buffer Overflow (PoC)
CVE-2009-0349doswindows
Stack-based buffer overflow in FTPShell Server 4.3 allows user-assisted remote attackers to cause a denial of service (p
23RISK
open
Referência
CVE-2017-5607
Splunk Enterprise 5.0.x before 5.0.18, 6.0.x before 6.0.14, 6.1.x before 6.1.13, 6.2.x before 6.2.13.1, 6.3.x before 6.3
23RISK
open
Referência
CVE-2009-1329
Stack-based buffer overflow in Mini-stream Shadow Stream Recorder 3.0.1.7 allows remote attackers to execute arbitrary c
23RISK
open
Referência
CVE-2009-1329
Stack-based buffer overflow in Mini-stream Shadow Stream Recorder 3.0.1.7 allows remote attackers to execute arbitrary c
23RISK
open
ReferênciaVexDay Proof
Elecard MPEG Player 5.5 - '.m3u' Stack Buffer Overflow (PoC)
CVE-2009-0491doswindows
Stack-based buffer overflow in Elecard MPEG Player 5.5 build 15884.081218 allows remote attackers to execute arbitrary c
23RISK
open
ReferênciaVexDay Proof
Simple Website Software 0.99 - 'common.php' File Inclusion
CVE-2006-5636webappsphp
PHP remote file inclusion vulnerability in common.php in Simple Website Software (SWS) 0.99 and earlier allows remote at
23RISK
open
Referência
phpList 3.5.0 - Authentication Bypass
CVE-2020-8547webappsphp
phpList 3.5.0 allows type juggling for admin login bypass because == is used instead of === for password hashes, which m
23RISK
open
Referência
CVE-2022-26982
SimpleMachinesForum 2.1.1 and earlier allows remote authenticated administrators to execute arbitrary code by inserting
23RISK
open
Referência
CVE-2021-3394
Millennium Millewin (also known as "Cartella clinica") 13.39.028, 13.39.28.3342, and 13.39.146.1 has insecure folder per
23RISK
open
Referência
CVE-2021-24499
Workreap theme < 2.2.2 - Unauthenticated Upload Leading to Remote Code Execution
50RISK
open
Referência
CVE-2012-4751
Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) Help Desk 2.4.x before 2.4.15, 3.0.x befor
23RISK
open
Referência
CVE-2013-5692
Directory traversal vulnerability in X2Engine X2CRM before 3.5 allows remote authenticated administrators to include and
23RISK
open
Referência
CVE-2009-4964
Stack-based buffer overflow in KSP 2006 FINAL allows remote attackers to execute arbitrary code via a long string in a .
23RISK
open
Referência
CVE-2009-3338
Stack-based buffer overflow in EffectMatrix (E.M.) Magic Morph 1.95b allows remote attackers to execute arbitrary code v
23RISK
open
previouspage 328 / 730next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.