Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,058cataloged exploits
35,300CVEs with public exploitation
24,695lab-tested
22,175 exploits
ReferênciaVexDay Proof
Redaxo 3.2 - 'INCLUDE_PATH' Remote File Inclusion
CVE-2006-2843webappsphp
PHP remote file inclusion vulnerability in Redaxo 2.7.4 allows remote attackers to execute arbitrary PHP code via a URL
23RISK
open
Referência
CVE-2010-0755
PHP remote file inclusion vulnerability in include/WBmap.php in WikyBlog 1.7.3 rc2 allows remote attackers to execute ar
23RISK
open
Referência
CVE-2010-0755
PHP remote file inclusion vulnerability in include/WBmap.php in WikyBlog 1.7.3 rc2 allows remote attackers to execute ar
23RISK
open
Referência
CVE-2016-3053
IBM AIX contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privile
23RISK
open
Referência
CVE-2024-22638
liveSite v2019.1 was discovered to contain a remote code execution (RCE) vulenrabiity via the component /livesite/edit_d
48RISK
open
Referência
CVE-2024-22638
liveSite v2019.1 was discovered to contain a remote code execution (RCE) vulenrabiity via the component /livesite/edit_d
48RISK
open
Referência
CVE-2003-20001
An issue was discovered on Mitel ICP VoIP 3100 devices. When a remote user attempts to log in via TELNET during the logi
33RISK
open
Referência
CVE-2018-15608
Zoho ManageEngine ADManager Plus 6.5.7 allows HTML Injection on the "AD Delegation" "Help Desk Technicians" screen.
23RISK
open
Referência
CVE-2019-13029
Multiple stored Cross-site scripting (XSS) issues in the admin panel and survey system in REDCap 8 before 8.10.20 and 9
23RISK
open
Referência
CVE-2018-12111
Cross-site scripting (XSS) vulnerability in the Canon PrintMe EFI webinterface allows remote attackers to inject arbitra
23RISK
open
Referência
CVE-2014-1915
Multiple cross-site request forgery (CSRF) vulnerabilities in Command School Student Management System 1.06.01 allow rem
23RISK
open
ReferênciaVexDay Proof
PHP Coupon Script 3.0 - 'bus' SQL Injection
CVE-2007-2672webappsphp
SQL injection vulnerability in index.php in PHP Coupon Script 3.0 allows remote attackers to execute arbitrary SQL comma
23RISK
open
ReferênciaVexDay Proof
Newswriter SW 1.4.2 - 'main.inc.php' Remote File Inclusion
CVE-2006-5180webappsphp
PHP remote file inclusion vulnerability in include/main.inc.php in Sebastian Baumann and Philipp Wolfer Newswriter SW 1.
23RISK
open
Referência
CVE-2012-2586
Multiple cross-site scripting (XSS) vulnerabilities in Mailtraq 2.17.3.3150 allow remote attackers to inject arbitrary w
23RISK
open
Referência
CVE-2021-32403
Intelbras Router RF 301K Firmware 1.1.2 is vulnerable to Cross Site Request Forgery (CSRF) due to lack of security mecha
23RISK
open
ReferênciaVexDay Proof
xml2owl 0.1.1 - 'showcode.php' Remote Command Execution
CVE-2007-6632webappsphp
showCode.php in xml2owl 0.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the path
23RISK
open
Referência
CVE-2012-2578
Multiple cross-site scripting (XSS) vulnerabilities in SmarterMail 9.2 allow remote attackers to inject arbitrary web sc
23RISK
open
Referência
CVE-2014-5100
Multiple cross-site request forgery (CSRF) vulnerabilities in Omeka before 2.2.1 allow remote attackers to hijack the au
23RISK
open
Referência
CVE-2014-5100
Multiple cross-site request forgery (CSRF) vulnerabilities in Omeka before 2.2.1 allow remote attackers to hijack the au
23RISK
open
ReferênciaVexDay Proof
PHPMyCart 1.3 - 'cat' SQL Injection
CVE-2008-2904webappsphp
SQL injection vulnerability in shop.php in Conkurent PHPMyCart allows remote attackers to execute arbitrary SQL commands
23RISK
open
Referência
CVE-2017-14620
SmarterStats Version 11.3.6347 will Render the Referer Field of HTTP Logfiles from URL /Data/Reports/ReferringURLsWithQu
23RISK
open
ReferênciaVexDay Proof
Mambo 4.6.4 - 'Output.php' Remote File Inclusion
CVE-2008-2905webappsphp
PHP remote file inclusion vulnerability in includes/Cache/Lite/Output.php in the Cache_Lite package in Mambo 4.6.4 and e
43RISK
open
ReferênciaVexDay Proof
Micro CMS 0.3.5 - Remote Add/Delete/Password Change
CVE-2008-6553webappsphp
microcms-admin-home.php in Implied by Design Micro CMS (Micro-CMS) 3.5 (aka 0.3.5) does not require authentication as an
23RISK
open
Referência
CVE-2014-9113
CCH Wolters Kluwer ProSystem fx Engagement (aka PFX Engagement) 7.1 and earlier uses weak permissions (Authenticated Use
23RISK
open
Referência
CVE-2014-9113
CCH Wolters Kluwer ProSystem fx Engagement (aka PFX Engagement) 7.1 and earlier uses weak permissions (Authenticated Use
23RISK
open
Referência
CVE-2012-1049
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine ADManager Plus 5.2 Build 5210 allow remote attackers
23RISK
open
Referência
CVE-2011-10026
Spreecommerce < 0.50.x API RCE
63RISK
open
Referência
CVE-2011-10026
Spreecommerce < 0.50.x API RCE
63RISK
open
Referência
CVE-2023-33383
Shelly 4PM Pro four-channel smart switch 0.11.0 allows an attacker to trigger a BLE out of bounds read fault condition t
23RISK
open
Referência
CVE-2014-3868
Multiple SQL injection vulnerabilities in ZeusCart 4.x.
23RISK
open
previouspage 376 / 740next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.