Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,894cataloged exploits
35,202CVEs with public exploitation
24,695lab-tested
21,899 exploits
ReferênciaVexDay Proof
LetterIt 2 - 'Language' Local File Inclusion
CVE-2008-3446webappsphp
Directory traversal vulnerability in inc/wysiwyg.php in LetterIt 2 allows remote attackers to include and execute arbitr
23RISK
open
Referência
CVE-2014-5189
SQL injection vulnerability in lib/optin/optin_page.php in the Lead Octopus plugin for WordPress allows remote attackers
23RISK
open
ReferênciaVexDay Proof
Cmaps v8.0 - SQL injection
CVE-2023-29809CRITICALwebappsphp
SQL injection vulnerability found in Maximilian Vogt companymaps (cmaps) v.8.0 allows a remote attacker to execute arbit
53RISK
open
ReferênciaVexDay Proof
Ads Pro - 'dhtml.pl' Remote Command Execution
CVE-2008-6826webappscgi
dhtml.pl in MHF Media Pro allows remote attackers to execute arbitrary commands via shell metacharacters in the page par
23RISK
open
ReferênciaVexDay Proof
WFTPD Pro Server 3.23.1.1 - 'APPE' Remote Buffer Overflow (PoC)
CVE-2006-5826doswindows
Buffer overflow in Texas Imperial Software WFTPD Pro Server 3.23.1.1 allows remote authenticated users to execute arbitr
28RISK
open
Referência
CVE-2017-2472
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS b
23RISK
open
Referência
CVE-2010-1363
SQL injection vulnerability in the JProjects (com_j-projects) component for Joomla! allows remote attackers to execute a
23RISK
open
Referência
CVE-2018-7747
Multiple cross-site scripting (XSS) vulnerabilities in the Caldera Forms plugin before 1.6.0-rc.1 for WordPress allow re
23RISK
open
Referência
CVE-2018-7747
Multiple cross-site scripting (XSS) vulnerabilities in the Caldera Forms plugin before 1.6.0-rc.1 for WordPress allow re
23RISK
open
Referência
CVE-2013-7319
Cross-site scripting (XSS) vulnerability in the Download Manager plugin before 2.5.9 for WordPress allows remote attacke
23RISK
open
ReferênciaVexDay Proof
iLife iPhoto Photocast - XML Title Remote Format String (PoC)
CVE-2007-0051dososx
Format string vulnerability in Apple iPhoto 6.0.5 (316), and other versions before 6.0.6, allows remote user-assisted at
23RISK
open
Referência
CVE-2021-24287
Select All Categories and Taxonomies < 1.3.2 - Reflected Cross-Site Scripting (XSS)
43RISK
open
Referência
CVE-2010-0641
Cross-site scripting (XSS) vulnerability in webline/html/admin/wcs/LoginPage.jhtml in Cisco Collaboration Server (CCS) 5
23RISK
open
Referência
CVE-2018-18324
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has XSS via the admin/fileManager2.php fm_current_dir parameter
23RISK
open
Referência
CVE-2014-8681
SQL injection vulnerability in the GetIssues function in models/issue.go in Gogs (aka Go Git Service) 0.3.1-9 through 0.
23RISK
open
Referência
CVE-2014-8681
SQL injection vulnerability in the GetIssues function in models/issue.go in Gogs (aka Go Git Service) 0.3.1-9 through 0.
23RISK
open
Referência
CVE-2013-3529
Multiple cross-site scripting (XSS) vulnerabilities in user/obits.php in the WP FuneralPress plugin before 1.1.7 for Wor
23RISK
open
Referência
CVE-2013-3529
Multiple cross-site scripting (XSS) vulnerabilities in user/obits.php in the WP FuneralPress plugin before 1.1.7 for Wor
23RISK
open
Referência
CVE-2016-1337
Cisco EPC3928 devices allow remote attackers to obtain sensitive configuration and credential information by making requ
23RISK
open
Referência
CVE-2019-19363
An issue was discovered in Ricoh (including Savin and Lanier) Windows printer drivers prior to 2020 that allows attacker
38RISK
open
ReferênciaVexDay Proof
KB-Bestellsystem - 'kb_whois.cgi' Command Execution
CVE-2007-6176webappscgi
kb_whois.cgi in K+B-Bestellsystem (aka KB-Bestellsystem) allows remote attackers to execute arbitrary commands via shell
23RISK
open
ReferênciaVexDay Proof
Axigen 5.0.2 - AXIMilter Remote Format String
CVE-2008-0434remotelinux
Format string vulnerability in the AXIMilter module in AXIGEN Mail Server 5.0.2 allows remote attackers to execute arbit
28RISK
open
Referência
OutSystems Service Studio 11.53.30 - DLL Hijacking
CVE-2022-47636localwindows
A DLL hijacking vulnerability has been discovered in OutSystems Service Studio 11 11.53.30 build 61739. When a user open
23RISK
open
ReferênciaVexDay Proof
PHPX 3.5.16 - Cookie Poisoning / Authentication Bypass
CVE-2008-3489webappsphp
SQL injection vulnerability in checkCookie function in includes/functions.inc.php in PHPX 3.5.16 allows remote attackers
23RISK
open
ReferênciaVexDay Proof
Icewarp Merak Mail Server 9.4.1 - 'Base64FileEncode()' Buffer Overflow (PoC)
CVE-2009-1516doswindows
Stack-based buffer overflow in the IceWarpServer.APIObject ActiveX control in api.dll in IceWarp Merak Mail Server 9.4.1
23RISK
open
Referência
CVE-2026-12697
wpForo Forum < 3.1.2 - Subscriber+ Cross-User AI Chat Message Deletion via IDOR
33RISK
open
ReferênciaVexDay Proof
Apple Safari - RSS 'feed://' Buffer Overflow via libxml2 (PoC)
CVE-2008-3529doswindows
Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-de
28RISK
open
Referência
CVE-2025-28137
The TOTOLINK A810R V4.1.2cu.5182_B20201026 were found to contain a pre-auth remote command execution vulnerability in th
53RISK
open
ReferênciaVexDay Proof
Discuz! 6.0.1 - 'searchid' SQL Injection
CVE-2008-3554webappsphp
SQL injection vulnerability in index.php in Discuz! 6.0.1 allows remote attackers to execute arbitrary SQL commands via
23RISK
open
Referência
CVE-2010-1315
Directory traversal vulnerability in weberpcustomer.php in the webERPcustomer (com_weberpcustomer) component 1.2.1 and 1
38RISK
open
previouspage 339 / 730next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.