Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,020cataloged exploits
35,276CVEs with public exploitation
24,695lab-tested
22,166 exploits
Referência
CVE-2022-47875
A Directory Traversal vulnerability in /be/erpc.php in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to ex
46RISK
open
Referência
CVE-2022-47876
The integrator in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to create Jobs to execute arbitrary code v
48RISK
open
Referência
CVE-2022-47986
CVE-2022-47986CRITICALunder attackransomware
IBM Aspera Faspex code execution
100RISK
open
Referência
CVE-2022-48110
CKSource CKEditor 5 35.4.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Full Featured CK
33RISK
open
Referência
CVE-2022-48177
X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a reflected cross-site scripting (XSS) vulnerability v
33RISK
open
Referência
CVE-2022-48178
X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via
33RISK
open
Referência
CVE-2017-5817
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.
60RISK
open
Referência
CVE-2022-48197
Reflected cross-site scripting (XSS) exists in Sandbox examples in the YUI2 repository. The download distributions, Tree
38RISK
open
Referência
CVE-2023-0315
Command Injection in froxlor/froxlor
78RISK
open
Referência
CVE-2023-0315
Command Injection in froxlor/froxlor
78RISK
open
Referência
CVE-2023-0493
Improper Neutralization of Equivalent Special Elements in btcpayserver/btcpayserver
33RISK
open
Referência
CVE-2023-0527
PHPGurukul Online Security Guards Hiring System search-request.php cross site scripting
43RISK
open
Referência
CVE-2023-0669
CVE-2023-0669HIGHunder attackransomware
Fortra GoAnywhere MFT License Response Servlet Command Injection
100RISK
open
Referência
CVE-2023-0669
CVE-2023-0669HIGHunder attackransomware
Fortra GoAnywhere MFT License Response Servlet Command Injection
100RISK
open
Referência
CVE-2023-0777
Authentication Bypass by Primary Weakness in modoboa/modoboa
61RISK
open
Referência
EasyNas 1.1.0 - OS Command Injection
CVE-2023-0830MEDIUMremotehardware
EasyNAS backup.pl system os command injection
38RISK
open
Referência
CVE-2023-0902
SourceCodester Simple Food Ordering System process_order.php cross site scripting
28RISK
open
Referência
CVE-2023-0904
SourceCodester Employee Task Management System task-details.php sql injection
33RISK
open
Referência
CVE-2023-0912
SourceCodester Auto Dealer Management System sql injection
33RISK
open
Referência
CVE-2017-6998
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
23RISK
open
Referência
CVE-2017-7237
The Spiceworks TFTP Server, as distributed with Spiceworks Inventory 7.5, allows remote attackers to access the Spicewor
23RISK
open
Referência
CVE-2023-0915
SourceCodester Auto Dealer Management System sql injection
33RISK
open
Referência
CVE-2023-0938
SourceCodester Music Gallery Site GET Request music_list.php sql injection
33RISK
open
Referência
CVE-2023-0961
SourceCodester Music Gallery Site GET Request view_music_details.php sql injection
33RISK
open
Referência
CVE-2023-0962
SourceCodester Music Gallery Site GET Request Master.php sql injection
33RISK
open
Referência
CVE-2023-1258
Flow-X disclosure of sensitive information to unauthenticated users
33RISK
open
Referência
Kardex Mlog MCC 5.7.12 - RCE (Remote Code Execution)
CVE-2023-22855CRITICALremotewindows
Kardex Mlog MCC 5.7.12+0-a203c2a213-master allows remote code execution. It spawns a web interface listening on port 808
53RISK
open
Referência
CVE-2023-23162
Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter
23RISK
open
Referência
CVE-2023-23333
There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassin
85RISK
open
Referência
CVE-2017-7643
Proxifier for Mac before 2.19 allows local users to gain privileges via the first parameter to the KLoader setuid progra
23RISK
open
previouspage 351 / 739next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.