Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,058cataloged exploits
35,300CVEs with public exploitation
24,695lab-tested
22,166 exploits
ReferênciaVexDay Proof
Yahoo! Messenger 8.1.0.421 - CYFT Object Arbitrary File Download
CVE-2007-5017remotewindows
Absolute path traversal vulnerability in a certain ActiveX control in the CYFT object in ft60.dll in Yahoo! Messenger 8.
23RISK
open
Referência
CVE-2016-1000124
Unauthenticated SQL Injection in Huge-IT Portfolio Gallery Plugin v1.0.6
23RISK
open
Referência
CVE-2015-6512
SQL injection vulnerability in the get_messages function in server/plugins/chatroom/chatroom.php in FreiChat 9.6 allows
23RISK
open
Referência
CVE-2015-6512
SQL injection vulnerability in the get_messages function in server/plugins/chatroom/chatroom.php in FreiChat 9.6 allows
23RISK
open
Referência
CVE-2011-4674
SQL injection vulnerability in popup.php in Zabbix 1.8.3 and 1.8.4, and possibly other versions before 1.8.9, allows rem
23RISK
open
Referência
CVE-2019-16531
LayerBB before 1.1.4 has multiple CSRF issues, as demonstrated by changing the System Settings via admin/general.php.
23RISK
open
Referência
CVE-2023-34723
An issue was discovered in TechView LA-5570 Wireless Gateway 1.0.19_T53, allows attackers to gain sensitive information
23RISK
open
Referência
CVE-2010-1653
Directory traversal vulnerability in graphics.php in the Graphics (com_graphics) component 1.0.6 and 1.5.0 for Joomla! a
43RISK
open
ReferênciaVexDay Proof
Online Fantasy Football League (OFFL) 0.2.6 - 'teams.php' SQL Injection
CVE-2008-2890webappsphp
Multiple SQL injection vulnerabilities in Online Fantasy Football League (OFFL) 0.2.6 and earlier allow remote attackers
23RISK
open
Referência
CVE-2016-4313
Directory traversal vulnerability in unzip/extract feature in eXtplorer 2.1.9 allows remote attackers to execute arbitra
23RISK
open
ReferênciaVexDay Proof
Calendar Script 1.1 - Insecure Cookie Handling
CVE-2008-5738webappsphp
Nodstrum MySQL Calendar 1.1 and 1.2 allows remote attackers to bypass authentication and gain administrative access by s
23RISK
open
ReferênciaVexDay Proof
PHPAuctionSystem - Insecure Cookie Handling
CVE-2009-0108webappsphp
PHPAuctions (aka PHPAuctionSystem) allows remote attackers to bypass authentication and gain administrative access via m
23RISK
open
Referência
CVE-2019-0552
An elevation of privilege exists in Windows COM Desktop Broker, aka "Windows COM Elevation of Privilege Vulnerability."
23RISK
open
Referência
CVE-2014-9146
Multiple cross-site scripting (XSS) vulnerabilities in Fiyo CMS 2.0.1.8 allow remote attackers to inject arbitrary web s
23RISK
open
Referência
CVE-2012-5242
Directory traversal vulnerability in functions/suggest.php in Banana Dance B.2.6 and earlier allows remote attackers to
23RISK
open
Referência
CVE-2009-4467
misc.php in DeluxeBB 1.3 allows remote attackers to register accounts without a valid email address via a valemail actio
23RISK
open
Referência
CVE-2009-2327
Cross-site scripting (XSS) vulnerability in add_voting.php in KerviNet Forum 1.1 and earlier allows remote authenticated
23RISK
open
Referência
CVE-2011-1665
PHPBoost 3.0 stores sensitive information under the web root with insufficient access control, which allows remote attac
23RISK
open
Referência
CVE-2010-0978
KMSoft Guestbook (aka GBook) 1.0 stores sensitive information under the web root with insufficient access control, which
23RISK
open
Referência
CVE-2010-0978
KMSoft Guestbook (aka GBook) 1.0 stores sensitive information under the web root with insufficient access control, which
23RISK
open
ReferênciaVexDay Proof
CaLogic Calendars 1.2.2 - 'CLPath' Remote File Inclusion
CVE-2006-2570webappsphp
PHP remote file inclusion vulnerability in CaLogic Calendars 1.2.2 allows remote attackers to execute arbitrary PHP code
23RISK
open
Referência
CVE-2019-11504
Zotonic before version 0.47 has mod_admin XSS.
23RISK
open
Referência
CVE-2019-11504
Zotonic before version 0.47 has mod_admin XSS.
23RISK
open
ReferênciaVexDay Proof
PageSquid CMS 0.3 Beta - 'index.php' SQL Injection
CVE-2008-2897webappsphp
SQL injection vulnerability in index.php in PageSquid CMS 0.3 Beta allows remote attackers to execute arbitrary SQL comm
23RISK
open
Referência
CVE-2016-4669
An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS b
38RISK
open
Referência
CVE-2016-4669
An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS b
38RISK
open
ReferênciaVexDay Proof
Chicomas 2.0.4 - Database Backup / File Disclosure / Cross-Site Scripting
CVE-2008-5853webappsphp
Chilek Content Management System (aka ChiCoMaS) 2.0.4 and earlier stores sensitive information under the web root with i
23RISK
open
ReferênciaVexDay Proof
Absolute FAQ Manager 6.0 - Insecure Cookie Handling
CVE-2008-6854webappsphp
Xigla Software Absolute FAQ Manager.NET 6.0 allows remote attackers to bypass authentication and gain administrative acc
23RISK
open
ReferênciaVexDay Proof
The Gemini Portal 4.7 - Insecure Cookie Handling
CVE-2008-7024webappsphp
admin.php in Arz Development The Gemini Portal 4.7 and earlier allows remote attackers to bypass authentication and gain
23RISK
open
ReferênciaVexDay Proof
fungamez rc1 - Authentication Bypass / Local File Inclusion
CVE-2009-1489webappsphp
includes/user.php in Fungamez RC1 allows remote attackers to bypass authentication and gain administrative access by set
23RISK
open
previouspage 360 / 739next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.