Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,151cataloged exploits
35,370CVEs with public exploitation
24,695lab-tested
22,175 exploits
Referência
CVE-2016-10074
The mail transport (aka Swift_Transport_MailTransport) in Swift Mailer before 5.4.5 might allow remote attackers to pass
35RISK
open
ReferênciaVexDay Proof
ibProArcade 3.3.0 - SQL Injection
CVE-2008-0770webappsphp
SQL injection vulnerability in arcade.php in ibProArcade 3.3.0 and earlier allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
Mambo Component Comments 0.5.8.5g - SQL Injection
CVE-2008-0773webappsphp
SQL injection vulnerability in Phil Taylor Comments (com_comments, aka Review Script) 0.5.8.5g and earlier component for
23RISK
open
ReferênciaVexDay Proof
ITechBids 6.0 - 'item_id' SQL Injection
CVE-2008-0776webappsphp
SQL injection vulnerability in detail.php in iTechBids Gold 6.0 allows remote attackers to execute arbitrary SQL command
23RISK
open
Referência
CVE-2016-1011
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows
28RISK
open
Referência
CVE-2016-10176
The NETGEAR WNR2000v5 router allows an administrator to perform sensitive actions by invoking the apply.cgi URL on the w
60RISK
open
Referência
CVE-2010-0711
Cross-site request forgery (CSRF) vulnerability in default.asp in ASPCode CMS 1.5.8, 2.0.0 Build 103, and possibly other
23RISK
open
Referência
CVE-2023-28771
CVE-2023-28771CRITICALunder attack
Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware vers
100RISK
open
ReferênciaVexDay Proof
MoinMoin 1.5.x - 'MOIND_ID' Cookie Login Bypass
CVE-2008-0782webappsphp
Directory traversal vulnerability in MoinMoin 1.5.8 and earlier allows remote attackers to overwrite arbitrary files via
28RISK
open
ReferênciaVexDay Proof
PHP Live! 3.2.2 - 'questid' SQL Injection (1)
CVE-2008-0821webappsphp
SQL injection vulnerability in admin/traffic/knowledge_searchm.php in OSI Codes Inc. PHP Live! 3.2.2 allows remote attac
23RISK
open
ReferênciaVexDay Proof
Simple CMS 1.0.3 - 'area' SQL Injection
CVE-2008-0835webappsphp
SQL injection vulnerability in indexen.php in Simple CMS 1.0.3 and earlier allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
Joomla! Component com_clasifier - 'cat_id' SQL Injection
CVE-2008-0842webappsphp
SQL injection vulnerability in index.php in the Classifier (com_clasifier) component for Joomla! allows remote attackers
23RISK
open
ReferênciaVexDay Proof
Joomla! Component com_pccookbook - 'user_id' SQL Injection
CVE-2008-0844webappsphp
SQL injection vulnerability in index.php in the PccookBook (com_pccookbook) component for Joomla! allows remote attacker
23RISK
open
ReferênciaVexDay Proof
Now SMS/Mms Gateway 5.5 - Remote Buffer Overflow
CVE-2008-0871remotewindows
Multiple stack-based buffer overflows in Now SMS/MMS Gateway 2007.06.27 and earlier allow remote attackers to execute ar
50RISK
open
Referência
CVE-2010-2334
Directory traversal vulnerability in themes/default/download.php in Yamamah Photo Gallery 1.00, as distributed before 20
23RISK
open
Referência
CVE-2010-2358
PHP remote file inclusion vulnerability in modules/catalog/upload_photo.php in Nakid CMS 0.5.2, when magic_quotes_gpc is
23RISK
open
Referência
CVE-2010-2458
Cross-site scripting (XSS) vulnerability in video.php in 2daybiz Video Community Portal Script 1.0 allows remote attacke
23RISK
open
Referência
CVE-2010-2461
SQL injection vulnerability in storecat.php in JCE-Tech Overstock 1 allows remote attackers to execute arbitrary SQL com
23RISK
open
Referência
CVE-2010-2461
SQL injection vulnerability in storecat.php in JCE-Tech Overstock 1 allows remote attackers to execute arbitrary SQL com
23RISK
open
Referência
CVE-2010-2464
Multiple cross-site scripting (XSS) vulnerabilities in the RSComments (com_rscomments) component 1.0.0 Rev 2 for Joomla!
23RISK
open
Referência
CVE-2026-8098
code-projects Feedback System checklogin.php sql injection
33RISK
open
ReferênciaVexDay Proof
Globsy 1.0 - 'file' Remote File Disclosure
CVE-2008-0905webappsphp
Directory traversal vulnerability in globsy_edit.php in Globsy 1.0 allows remote attackers to read arbitrary files via a
23RISK
open
ReferênciaVexDay Proof
PHP-Nuke Module Docum - 'artid' SQL Injection
CVE-2008-0906webappsphp
SQL injection vulnerability in the Docum module in PHP-Nuke allows remote attackers to execute arbitrary SQL commands vi
23RISK
open
ReferênciaVexDay Proof
PHP-Nuke Module Inhalt - 'cid' SQL Injection
CVE-2008-0907webappsphp
SQL injection vulnerability in the Inhalt module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands
23RISK
open
Referência
CVE-2010-0721
SQL injection vulnerability in news.php in Auktionshaus Gelb 3.0 allows remote attackers to execute arbitrary SQL comman
23RISK
open
Referência
CVE-2010-0721
SQL injection vulnerability in news.php in Auktionshaus Gelb 3.0 allows remote attackers to execute arbitrary SQL comman
23RISK
open
Referência
CVE-2010-0722
SQL injection vulnerability in news.php in Php Auktion Pro allows remote attackers to execute arbitrary SQL commands via
23RISK
open
Referência
CVE-2020-14750
CVE-2020-14750CRITICALunder attack
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
ReferênciaVexDay Proof
MultiCart 2.0 - 'productdetails.php' SQL Injection
CVE-2008-0911webappsphp
SQL injection vulnerability in productdetails.php in iScripts MultiCart 2.0 allows remote authenticated users to execute
23RISK
open
Referência
CVE-2010-2613
Cross-site scripting (XSS) vulnerability in the JExtensions JE Awd Song (com_awd_song) component for Joomla! allows remo
23RISK
open
previouspage 380 / 740next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.