Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,647cataloged exploits
34,986CVEs with public exploitation
24,695lab-tested
21,899 exploits
Referência
CVE-2021-25298
CVE-2021-25298HIGHunder attack
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi
100RISK
open
ReferênciaVexDay Proof
PHP-Update 2.7 - '/admin/uploads.php' Remote Code Execution
CVE-2006-6879webappsphp
Unrestricted file upload vulnerability in admin/uploads.php in PHP-Update 2.7 and earlier allows remote authenticated us
23RISK
open
Referência
CVE-2026-9377
SourceCodester SUP Online Shopping productedit.php cross site scripting
33RISK
open
ReferênciaVexDay Proof
PHP-Update 2.7 - Multiple Vulnerabilities
CVE-2006-6879webappsphp
Unrestricted file upload vulnerability in admin/uploads.php in PHP-Update 2.7 and earlier allows remote authenticated us
23RISK
open
ReferênciaVexDay Proof
PHP-Update 2.7 - Multiple Vulnerabilities
CVE-2006-6880webappsphp
Multiple SQL injection vulnerabilities in code/guestadd.php in PHP-Update 2.7 and earlier allow remote attackers to exec
23RISK
open
ReferênciaVexDay Proof
Vz (Adp) Forum 2.0.3 - Remote Password Disclosure
CVE-2006-6891webappsphp
Vz (Adp) Forum 2.0.3 stores sensitive information under the web root with insufficient access control, which allows remo
23RISK
open
ReferênciaVexDay Proof
Nitrotech 0.0.3a - Remote Code Execution
CVE-2006-6938webappsphp
Directory traversal vulnerability in includes/common.php in NitroTech 0.0.3a, as distributed before 2006, allows remote
23RISK
open
Referência
CVE-2023-4278
MasterStudy LMS < 3.0.18 - Unauthenticated Instructor Account Creation
41RISK
open
Referência
CVE-2023-4278
MasterStudy LMS < 3.0.18 - Unauthenticated Instructor Account Creation
41RISK
open
ReferênciaVexDay Proof
FreeWebShop.org script 2.2.2 - Multiple Vulnerabilities
CVE-2006-6941webappsphp
index.php in FreeWebshop 2.2.2 and earlier allows remote attackers to obtain sensitive information via an invalid action
23RISK
open
Referência
glibc 2.38 - Buffer Overflow
CVE-2023-4911HIGHunder attacklocallinux
Glibc: buffer overflow in ld.so leading to privilege escalation
100RISK
open
Referência
CVE-2026-23760
CVE-2026-23760CRITICALunder attackransomware
SmarterTools SmarterMail < Build 9511 Authentication Bypass via Password Reset API
100RISK
open
Referência
CVE-2023-6553
Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
85RISK
open
Referência
CVE-2015-1497
radexecd.exe in Persistent Systems Radia Client Automation (RCA) 7.9, 8.1, 9.0, and 9.1 allows remote attackers to execu
60RISK
open
Referência
CVE-2015-1497
radexecd.exe in Persistent Systems Radia Client Automation (RCA) 7.9, 8.1, 9.0, and 9.1 allows remote attackers to execu
60RISK
open
Referência
CVE-2024-11954
Pimcore Search Document cross site scripting
33RISK
open
Referência
CVE-2024-11956
Pimcore customer-data-framework list sql injection
33RISK
open
Referência
CVE-2024-12344
TP-Link VN020 F3v(T) FTP USER Command memory corruption
33RISK
open
Referência
CVE-2024-12483
Dromara UJCMS User ID id authorization
33RISK
open
Referência
VirtualBox 7.0.16 - Privilege Escalation
CVE-2024-21111HIGHlocalwindows
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
41RISK
open
Referência
CVE-2022-24112
CVE-2022-24112CRITICALunder attack
apisix/batch-requests plugin allows overwriting the X-REAL-IP header
100RISK
open
ReferênciaVexDay Proof
Linux Kernel 2.6.x - 'sys_timer_create()' Local Denial of Service
CVE-2006-7051doslinux
The sys_timer_create function in posix-timers.c for Linux kernel 2.6.x allows local users to cause a denial of service (
23RISK
open
Referência
Microsoft Windows 11 - Kernel Privilege Escalation
CVE-2024-21338HIGHunder attackransomwarelocalwindows
Windows Kernel Elevation of Privilege Vulnerability
83RISK
open
Referência
CVE-2024-22318
IBM i Access Client Solutions information disclosure
33RISK
open
ReferênciaVexDay Proof
TinyPHP Forum 3.6 - 'profile.php' Remote Code Execution
CVE-2006-7063webappsphp
Directory traversal vulnerability in profile.php in TinyPHPforum 3.6 and earlier allows remote attackers to include and
23RISK
open
ReferênciaVexDay Proof
PhpNews 1.0 - 'Include' Remote File Inclusion
CVE-2006-7081webappsphp
Multiple PHP remote file inclusion vulnerabilities in PhpNews 1.0 allow remote attackers to execute arbitrary PHP code v
23RISK
open
Referência
CVE-2015-4852
CVE-2015-4852CRITICALunder attack
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers
100RISK
open
Referência
CVE-2015-1497
radexecd.exe in Persistent Systems Radia Client Automation (RCA) 7.9, 8.1, 9.0, and 9.1 allows remote attackers to execu
60RISK
open
Referência
CVE-2014-3871
Multiple SQL injection vulnerabilities in register.php in Geodesic Solutions GeoCore MAX 7.3.3 (formerly GeoClassifieds
23RISK
open
Referência
ManageEngine Application Manager 14.2 - Privilege Escalation / Remote Command Execution (Metasploit)
CVE-2019-15105remotemultiple
An issue was discovered in Zoho ManageEngine Application Manager through 14.2. There is a SQL Injection vulnerability in
23RISK
open
previouspage 332 / 730next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.