Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,058cataloged exploits
35,300CVEs with public exploitation
24,695lab-tested
22,166 exploits
Referência
CVE-2026-10162
TRENDnet TEW-432BRP formSetPassword stack-based overflow
41RISK
open
ReferênciaVexDay Proof
Moodle < 1.6.9/1.7.7/1.8.9/1.9.5 - File Disclosure
CVE-2009-1171webappsphp
The TeX filter in Moodle 1.6 before 1.6.9+, 1.7 before 1.7.7+, 1.8 before 1.8.9, and 1.9 before 1.9.5 allows user-assist
23RISK
open
ReferênciaVexDay Proof
Amaya 11.1 - W3C Editor/Browser (defer) Stack Overflow (PoC)
CVE-2009-1209doswindows
Stack-based buffer overflow in W3C Amaya Web Browser 11.1 allows remote attackers to execute arbitrary code via a script
28RISK
open
Referência
CVE-2009-4680
SQL injection vulnerability in search.php in phpDirectorySource 1.x allows remote attackers to execute arbitrary SQL com
23RISK
open
Referência
CVE-2014-8322
Stack-based buffer overflow in the tcp_test function in aireplay-ng.c in Aircrack-ng before 1.2 RC 1 allows remote attac
28RISK
open
Referência
CVE-2014-8356
The web administrative portal in Zhone zNID 2426A before S3.0.501 allows remote authenticated users to bypass intended a
23RISK
open
Referência
CVE-2014-8356
The web administrative portal in Zhone zNID 2426A before S3.0.501 allows remote authenticated users to bypass intended a
23RISK
open
Referência
CVE-2014-8357
backupsettings.html in the web administrative portal in Zhone zNID GPON 2426A before S3.0.501 places a session key in a
23RISK
open
Referência
CVE-2014-8357
backupsettings.html in the web administrative portal in Zhone zNID GPON 2426A before S3.0.501 places a session key in a
23RISK
open
Referência
CVE-2014-8361
CVE-2014-8361CRITICALunder attack
The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClien
100RISK
open
Referência
CVE-2014-8375
SQL injection vulnerability in GBgallery.php in the GB Gallery Slideshow plugin 1.5 for WordPress allows remote administ
23RISK
open
Referência
CVE-2014-8386
Multiple stack-based buffer overflows in Advantech AdamView 4.3 and earlier allow remote attackers to execute arbitrary
23RISK
open
Referência
CVE-2014-8393
DLL Hijacking vulnerability in CorelDRAW X7, Corel Photo-Paint X7, Corel PaintShop Pro X7, Corel Painter 2015, and Corel
23RISK
open
Referência
CVE-2014-8469
Cross-site scripting (XSS) vulnerability in Guests/Boots in AdminCP in Moxi9 PHPFox before 4 Beta allows remote attacker
23RISK
open
Referência
CVE-2014-8469
Cross-site scripting (XSS) vulnerability in Guests/Boots in AdminCP in Moxi9 PHPFox before 4 Beta allows remote attacker
23RISK
open
Referência
CVE-2009-4688
Multiple cross-site scripting (XSS) vulnerabilities in index.php in PHP Shopping Cart Selling Website Script allow remot
23RISK
open
Referência
CVE-2014-8493
ZTE ZXHN H108L with firmware 4.0.0d_ZRQ_GR4 allows remote attackers to modify the CWMP configuration via a crafted reque
23RISK
open
Referência
CVE-2009-4689
SQL injection vulnerability in index.php in PHP Shopping Cart Selling Website Script allows remote attackers to execute
23RISK
open
Referência
CVE-2014-8577
Multiple cross-site scripting (XSS) vulnerabilities in Croogo before 2.1.0 allow remote attackers to inject arbitrary we
23RISK
open
Referência
CVE-2014-8577
Multiple cross-site scripting (XSS) vulnerabilities in Croogo before 2.1.0 allow remote attackers to inject arbitrary we
23RISK
open
Referência
CVE-2014-8596
Multiple SQL injection vulnerabilities in PHP-Fusion 7.02.07 allow remote authenticated users to execute arbitrary SQL c
23RISK
open
Referência
CVE-2014-8596
Multiple SQL injection vulnerabilities in PHP-Fusion 7.02.07 allow remote authenticated users to execute arbitrary SQL c
23RISK
open
Referência
CVE-2014-8654
Multiple cross-site request forgery (CSRF) vulnerabilities in Compal Broadband Networks (CBN) CH6640E and CG6640E Wirele
23RISK
open
Referência
CVE-2014-9612
SQL injection vulnerability in remotereporter/load_logfiles.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1
23RISK
open
Referência
CVE-2014-9633
The bdisk.sys driver in COMODO Backup before 4.4.1.23 allows remote attackers to gain privileges via a crafted device ha
23RISK
open
Referência
CVE-2023-46805
CVE-2023-46805HIGHunder attackransomware
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a re
100RISK
open
Referência
CVE-2023-22527
CVE-2023-22527CRITICALunder attackransomware
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RISK
open
Referência
CVE-2026-10062
TRENDnet TEW-432BRP formSetRoute stack-based overflow
41RISK
open
Referência
CVE-2026-10061
TRENDnet TEW-432BRP formWPS command injection
33RISK
open
ReferênciaVexDay Proof
mxBB Module mx_tinies 1.3.0 - Remote File Inclusion
CVE-2006-6295webappsphp
PHP remote file inclusion vulnerability in includes/mx_common.php in the mx_tinies 1.3.0 Module for MxBB Portal 1.06 all
23RISK
open
previouspage 365 / 739next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.