Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,058cataloged exploits
35,300CVEs with public exploitation
24,695lab-tested
22,175 exploits
Referência
CVE-2010-4857
SQL injection vulnerability in click.php in CAG CMS 0.2 Beta allows remote attackers to execute arbitrary SQL commands v
23RISK
open
Referência
CVE-2010-4860
SQL injection vulnerability in product_desc.php in MyPhpAuction 2010 allows remote attackers to execute arbitrary SQL co
23RISK
open
Referência
CVE-2010-4860
SQL injection vulnerability in product_desc.php in MyPhpAuction 2010 allows remote attackers to execute arbitrary SQL co
23RISK
open
Referência
CVE-2010-4861
SQL injection vulnerability in asearch.php in webSPELL 4.2.1 allows remote attackers to execute arbitrary SQL commands v
23RISK
open
Referência
CVE-2014-6242
Multiple SQL injection vulnerabilities in the All In One WP Security & Firewall plugin before 3.8.3 for WordPress allow
23RISK
open
Referência
CVE-2022-0847
CVE-2022-0847HIGHunder attack
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
Referência
CVE-2015-4066
Multiple SQL injection vulnerabilities in admin/handlers.php in the GigPress plugin before 2.3.9 for WordPress allow rem
23RISK
open
Referência
CVE-2015-4066
Multiple SQL injection vulnerabilities in admin/handlers.php in the GigPress plugin before 2.3.9 for WordPress allow rem
23RISK
open
Referência
CVE-2022-0847
CVE-2022-0847HIGHunder attack
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
Referência
CVE-2016-6707
An elevation of privilege vulnerability in System Server in Android 6.x before 2016-11-01 and 7.0 before 2016-11-01 coul
23RISK
open
Referência
CVE-2026-13389
WebToffee Cookie Consent < 3.5.3 - Consent Log Disclosure/Deletion, Page Creation & License Deactivation via Unprotected REST Routes
33RISK
open
Referência
CVE-2014-2023
Multiple SQL injection vulnerabilities in the Tapatalk plugin 4.9.0 and earlier and 5.x through 5.2.1 for vBulletin allo
23RISK
open
Referência
CVE-2025-15675
Charitable < 1.8.5.3 - Admin+ Stored XSS via Photo Field ALT Text
33RISK
open
ReferênciaVexDay Proof
VS-News-System 1.2.1 - 'newsordner' Remote File Inclusion
CVE-2007-1017webappsphp
PHP remote file inclusion vulnerability in show_news_inc.php in VirtualSystem VS-News-System 1.2.1 and earlier allows re
23RISK
open
Referência
CVE-2019-0836
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), ak
23RISK
open
Referência
CVE-2019-0836
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), ak
23RISK
open
Referência
CVE-2017-11567
Cross-site request forgery (CSRF) vulnerability in Mongoose Web Server before 6.9 allows remote attackers to hijack the
23RISK
open
ReferênciaVexDay Proof
PrecisionID Barcode ActiveX 1.3 - Denial of Service
CVE-2007-2657doswindows
Unspecified vulnerability in the PrecisionID Barcode 1.3 ActiveX control in PrecisionID_DataMatrix.DLL allows remote att
23RISK
open
ReferênciaVexDay Proof
EZContents CMS 2.0.0 - Multiple SQL Injections
CVE-2008-2135webappsphp
Multiple SQL injection vulnerabilities in VisualShapers ezContents 2.0.0 allow remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
Studio Lounge Address Book 2.5 - 'profile' Arbitrary File Upload
CVE-2009-1483webappsphp
Unrestricted file upload vulnerability in upload-file.php in Adam Patterson Studio Lounge Address Book 2.5, as reachable
23RISK
open
Referência
CVE-2010-4928
Cross-site scripting (XSS) vulnerability in the Restaurant Guide (com_restaurantguide) component 1.0.0 for Joomla! allow
23RISK
open
Referência
CVE-2010-4928
Cross-site scripting (XSS) vulnerability in the Restaurant Guide (com_restaurantguide) component 1.0.0 for Joomla! allow
23RISK
open
Referência
CVE-2010-4929
SQL injection vulnerability in the Joostina (com_ezautos) component for Joomla! allows remote attackers to execute arbit
23RISK
open
Referência
CVE-2013-5978
Multiple cross-site scripting (XSS) vulnerabilities in products.php in the Cart66 Lite plugin before 1.5.1.15 for WordPr
23RISK
open
Referência
CVE-2013-5219
Directory traversal vulnerability on the HOT HOTBOX router with software 2.1.11 allows remote attackers to read arbitrar
23RISK
open
Referência
CVE-2007-3340
BugHunter HTTP SERVER (httpsv.exe) 1.6.2 allows remote attackers to cause a denial of service (application crash) via a
23RISK
open
Referência
CVE-2012-5861
Sinapsi eSolar SQL Injection
41RISK
open
Referência
CVE-2026-14938
FluentBoards < 1.95.3 - Subscriber+ Cross-Board Task Disclosure via IDOR
33RISK
open
Referência
CVE-2015-1318
The crash reporting feature in Apport 2.13 through 2.17.x before 2.17.1 allows local users to gain privileges via a craf
38RISK
open
Referência
CVE-2015-1318
The crash reporting feature in Apport 2.13 through 2.17.x before 2.17.1 allows local users to gain privileges via a craf
38RISK
open
previouspage 367 / 740next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.