Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,058cataloged exploits
35,300CVEs with public exploitation
24,695lab-tested
22,175 exploits
Referência
CVE-2018-0877
The Desktop Bridge Virtual File System (VFS) in Windows 10 1607, 1703, and 1709, Windows Server 2016 and Windows Server,
23RISK
open
Referência
CVE-2013-6882
Multiple cross-site scripting (XSS) vulnerabilities in CRU Ditto Forensic FieldStation with firmware 2013Oct15a and earl
23RISK
open
Referência
CVE-2013-6882
Multiple cross-site scripting (XSS) vulnerabilities in CRU Ditto Forensic FieldStation with firmware 2013Oct15a and earl
23RISK
open
ReferênciaVexDay Proof
mebiblio 0.4.7 - SQL Injection / Arbitrary File Upload / Cross-Site Scripting
CVE-2008-2646webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in meBiblio 0.4.7 allow remote attackers to inject arbitrary web scr
23RISK
open
Referência
CVE-2015-1722
Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista S
23RISK
open
Referência
CVE-2015-1722
Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista S
23RISK
open
ReferênciaVexDay Proof
mebiblio 0.4.7 - SQL Injection / Arbitrary File Upload / Cross-Site Scripting
CVE-2008-2647webappsphp
SQL injection vulnerability in admin/journal_change_mask.inc.php in meBiblio 0.4.7 allows remote attackers to execute ar
23RISK
open
Referência
CVE-2014-3840
Multiple cross-site scripting (XSS) vulnerabilities in apps/common/templates/calculate_form_title.html in Mayan EDMS 0.1
23RISK
open
Referência
CVE-2010-2147
Cross-site scripting (XSS) vulnerability in the My Car (com_mycar) component 1.0 for Joomla! allows remote attackers to
23RISK
open
Referência
CVE-2017-6366
Cross-site request forgery (CSRF) vulnerability in NETGEAR DGN2200 routers with firmware 10.0.0.20 through 10.0.0.50 all
23RISK
open
Referência
CVE-2018-11628
Data input into EMS Master Calendar before 8.0.0.201805210 via URL parameters is not properly sanitized, allowing malici
23RISK
open
Referência
CVE-2019-11398
Multiple cross-site scripting (XSS) vulnerabilities in UliCMS 2019.2 and 2019.1 allow remote attackers to inject arbitra
23RISK
open
Referência
CVE-2019-11398
Multiple cross-site scripting (XSS) vulnerabilities in UliCMS 2019.2 and 2019.1 allow remote attackers to inject arbitra
23RISK
open
Referência
CVE-2010-1363
SQL injection vulnerability in the JProjects (com_j-projects) component for Joomla! allows remote attackers to execute a
23RISK
open
Referência
CVE-2006-2465
Buffer overflow in MP3Info 0.8.4 allows attackers to execute arbitrary code via a long command line argument. NOTE: if
23RISK
open
ReferênciaVexDay Proof
saPHP Lesson 2.0 - 'forumid' SQL Injection
CVE-2005-3363webappsphp
SQL injection vulnerability in Saphp Lesson, possibly saphp Lesson1.1 and saphpLesson2.0, allows remote attackers to exe
23RISK
open
Referência
CVE-2011-3923
Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class an
60RISK
open
Referência
CVE-2009-3247
Cross-site scripting (XSS) vulnerability in the Activities module in vtiger CRM 5.0.4 allows remote attackers to inject
23RISK
open
Referência
CVE-2020-7108
The LearnDash LMS plugin before 3.1.2 for WordPress allows XSS via the ld-profile search field.
23RISK
open
Referência
CVE-2017-0214
Windows COM in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2
23RISK
open
Referência
CVE-2022-1388
CVE-2022-1388CRITICALunder attackransomware
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
ReferênciaVexDay Proof
Nuked-klaN 1.7.6 - Remote Code Execution
CVE-2007-2556webappsphp
SQL injection vulnerability in Nuked-klaN 1.7.6 allows remote attackers to execute arbitrary SQL commands via the X-Forw
23RISK
open
ReferênciaVexDay Proof
Built2Go PHP Movie Review 2B - Remote File Inclusion
CVE-2006-2008webappsphp
PHP remote file inclusion vulnerability in movie_cls.php in Built2Go PHP Movie Review 2B and earlier allows remote attac
23RISK
open
ReferênciaVexDay Proof
sk.log 0.5.3 - 'skin_url' Remote File Inclusion
CVE-2007-5089webappsphp
PHP remote file inclusion vulnerability in php-inc/log.inc.php in sk.log 0.5.3 and earlier allows remote attackers to ex
23RISK
open
Referência
CVE-2004-1493
Master of Orion III 1.2.5 and earlier allows remote attackers to cause a denial of service (server crash) via multiple c
23RISK
open
Referência
CVE-2010-1366
Multiple SQL injection vulnerabilities in admin/admin_login.php in Uiga Fan Club 1.0 and earlier allow remote attackers
23RISK
open
Referência
CVE-2010-1366
Multiple SQL injection vulnerabilities in admin/admin_login.php in Uiga Fan Club 1.0 and earlier allow remote attackers
23RISK
open
ReferênciaVexDay Proof
mg.applanix 1.3.1 - 'apx_root_path' Remote File Inclusion
CVE-2006-6341webappsphp
Multiple PHP remote file inclusion vulnerabilities in mg.applanix 1.3.1 and earlier allow remote attackers to execute ar
23RISK
open
ReferênciaVexDay Proof
Insanely Simple Blog 0.5 - SQL Injection
CVE-2008-2670webappsphp
Multiple SQL injection vulnerabilities in index.php in Insanely Simple Blog 0.5 allow remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
Joomla! Component iJoomla! News Portal 1.0 - 'itemID' SQL Injection
CVE-2008-2676webappsphp
SQL injection vulnerability in the iJoomla News Portal (com_news_portal) component 1.0 and earlier for Joomla! allows re
23RISK
open
previouspage 371 / 740next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.