Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,647cataloged exploits
34,986CVEs with public exploitation
24,695lab-tested
21,899 exploits
Referência
CVE-2009-3757
Multiple cross-site scripting (XSS) vulnerabilities in sample code in the XenServer Resource Kit in Citrix XenCenterWeb
23RISK
open
Referência
CVE-2017-15662
In Flexense VX Search Enterprise v10.1.12, the Control Protocol suffers from a denial of service vulnerability. The atta
23RISK
open
Referência
CVE-2010-1089
SQL injection vulnerability in vedi_faq.php in PHP Trouble Ticket 2.2 allows remote attackers to execute arbitrary SQL c
23RISK
open
Referência
CVE-2025-25038
MiniDVBLinux Root Command Injection
48RISK
open
Referência
CVE-2025-25038
MiniDVBLinux Root Command Injection
48RISK
open
Referência
CVE-2025-25038
MiniDVBLinux Root Command Injection
48RISK
open
Referência
CVE-2025-25038
MiniDVBLinux Root Command Injection
48RISK
open
Referência
CVE-2016-2417
media/libmedia/IOMX.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x befo
23RISK
open
Referência
CVE-2013-7030
The TFTP service in Cisco Unified Communications Manager (aka CUCM or Unified CM) allows remote attackers to obtain sens
41RISK
open
Referência
CVE-2022-22832
An issue was discovered in Servisnet Tessa 0.0.2. Authorization data is available via an unauthenticated /data-service/u
28RISK
open
Referência
CVE-2019-6804
An XSS issue was discovered on the Job Edit page in Rundeck Community Edition before 3.0.13, related to assets/javascrip
23RISK
open
Referência
CVE-2021-27946
SQL Injection vulnerability in MyBB before 1.8.26 via poll vote count. (issue 1 of 3).
23RISK
open
Referência
CVE-2012-6290
SQL injection vulnerability in ImageCMS before 4.2 allows remote authenticated administrators to execute arbitrary SQL c
23RISK
open
Referência
CVE-2013-2637
A Cross-Site Scripting (XSS) Vulnerability exists in OTRS ITSM prior to 3.2.4, 3.1.8, and 3.0.7 and FAQ prior to 2.1.4 a
23RISK
open
ReferênciaVexDay Proof
JV2 Folder Gallery 3.0 - Remote File Inclusion
CVE-2007-0682webappsphp
PHP remote file inclusion vulnerability in theme/include_mode/template.php in JV2 Folder Gallery 3.0.2 and earlier allow
23RISK
open
Referência
CVE-2017-7221
OpenText Documentum Content Server has an inadequate protection mechanism against SQL injection, which allows remote aut
23RISK
open
ReferênciaVexDay Proof
wavewoo 0.1.1 - 'loading.php?path_include' Remote File Inclusion
CVE-2007-2273webappsphp
PHP remote file inclusion vulnerability in include/loading.php in Alessandro Lulli wavewoo 0.1.1 allows remote attackers
23RISK
open
ReferênciaVexDay Proof
TR News 2.1 - 'nb' SQL Injection
CVE-2008-1958webappsphp
Unrestricted file upload vulnerability in the ajout_cat mode in admin/main.php in Tr Script News 2.1 allows remote authe
23RISK
open
ReferênciaVexDay Proof
Phoenix View CMS Pre Alpha2 - SQL Injection / Local File Inclusion / Cross-Site Scripting
CVE-2008-2535webappsphp
Multiple SQL injection vulnerabilities in Phoenix View CMS Pre Alpha2 and earlier allow remote attackers to execute arbi
23RISK
open
ReferênciaVexDay Proof
Advanced Image Hosting (AIH) 2.1 - SQL Injection
CVE-2008-2536webappsphp
SQL injection vulnerability in out.php in YABSoft Advanced Image Hosting (AIH) Script 2.1 and earlier allows remote atta
23RISK
open
ReferênciaVexDay Proof
groone's Guestbook 2.0 - Remote File Inclusion
CVE-2009-0464webappsphp
PHP remote file inclusion vulnerability in includes/header.php in Groone GBook 2.0 allows remote attackers to execute ar
23RISK
open
Referência
CVE-2015-1721
The kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and
23RISK
open
Referência
CVE-2021-26855
CVE-2021-26855CRITICALunder attackransomware
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
Referência
CVE-2012-1663
Double free vulnerability in libgnutls in GnuTLS before 3.0.14 allows remote attackers to cause a denial of service (app
23RISK
open
Referência
CVE-2021-26855
CVE-2021-26855CRITICALunder attackransomware
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
Referência
CVE-2013-1852
SQL injection vulnerability in leaguemanager.php in the LeagueManager plugin before 3.8.1 for WordPress allows remote at
23RISK
open
Referência
CVE-2013-1852
SQL injection vulnerability in leaguemanager.php in the LeagueManager plugin before 3.8.1 for WordPress allows remote at
23RISK
open
Referência
CVE-2015-4682
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows remote authenticated users to obtain the installation
23RISK
open
Referência
CVE-2015-4682
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows remote authenticated users to obtain the installation
23RISK
open
Referência
CVE-2008-1866
admin/modif_config.php in Blog Pixel Motion (aka PixelMotion) does not require admin authentication, which allows remote
23RISK
open
previouspage 336 / 730next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.