Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,151cataloged exploits
35,370CVEs with public exploitation
24,695lab-tested
22,175 exploits
Referência
CVE-2009-5019
Web Wiz NewsPad stores sensitive information under the web root with insufficient access control, which allows remote at
23RISK
open
Referência
CVE-2015-4039
Multiple cross-site scripting (XSS) vulnerabilities in the WP Membership plugin 1.2.3 for WordPress allow remote authent
23RISK
open
Referência
CVE-2025-7795
Tenda FH451 P2pListFilter fromP2pListFilter stack-based overflow
41RISK
open
ReferênciaVexDay Proof
Virtual Path 1.0 - '/vp/configure.php' Remote File Inclusion
CVE-2007-0591webappsphp
PHP remote file inclusion vulnerability in configure.php in Vu Le An Virtual Path (VirtualPath) 1.0 allows remote attack
23RISK
open
Referência
CVE-2013-7382
VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier has a hardcoded password of donotedit for t
23RISK
open
ReferênciaVexDay Proof
Black Ice Software Inc Barcode SDK - 'BIDIB.ocx' Multiple Vulnerabilities
CVE-2008-2683remotewindows
The BIDIB.BIDIBCtrl.1 ActiveX control in BIDIB.ocx 10.9.3.0 in Black Ice Barcode SDK 5.01 allows remote attackers to for
50RISK
open
Referência
CVE-2010-1372
SQL injection vulnerability in the HD FLV Player (com_hdflvplayer) component 1.3 for Joomla! allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
Aj Classifieds - Authentication Bypass
CVE-2008-7041webappsphp
AJ Classifieds allows remote attackers to bypass authentication and gain administrator privileges via a direct request t
23RISK
open
Referência
CVE-2015-1428
Multiple SQL injection vulnerabilities in Sefrengo before 1.6.2 allow (1) remote attackers to execute arbitrary SQL comm
23RISK
open
Referência
CVE-2014-3442
Winamp 5.666 and earlier allows remote attackers to cause a denial of service (memory corruption and crash) via a malfor
23RISK
open
Referência
CVE-2015-7569
SQL injection vulnerability in "yeager/y.php/tab_USERLIST" in Yeager CMS 1.2.1 allows local users to execute arbitrary S
23RISK
open
Referência
CVE-2015-7569
SQL injection vulnerability in "yeager/y.php/tab_USERLIST" in Yeager CMS 1.2.1 allows local users to execute arbitrary S
23RISK
open
Referência
CVE-2010-2312
SQL injection vulnerability in index.php in HauntmAx Haunted House Directory Listing CMS allows remote attackers to exec
23RISK
open
Referência
CVE-2019-0805
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), ak
23RISK
open
Referência
CVE-2019-0805
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), ak
23RISK
open
Referência
CVE-2010-0984
Acidcat CMS 3.5.3 and earlier stores sensitive information under the web root with insufficient access control, which al
23RISK
open
Referência
CVE-2010-0984
Acidcat CMS 3.5.3 and earlier stores sensitive information under the web root with insufficient access control, which al
23RISK
open
ReferênciaVexDay Proof
Site-Assistant 0990 - 'paths[version]' Remote File Inclusion
CVE-2007-0867webappsphp
PHP remote file inclusion vulnerability in classes/menu.php in Site-Assistant 0990 and earlier allows remote attackers t
23RISK
open
ReferênciaVexDay Proof
ttCMS 4 - 'ez_sql.php?lib_path' Remote File Inclusion
CVE-2007-1708webappsphp
PHP remote file inclusion vulnerability in lib/db/ez_sql.php in ttCMS 4 and earlier allows remote attackers to execute a
23RISK
open
ReferênciaVexDay Proof
CyBoards PHP Lite 1.21 - 'script_path' Remote File Inclusion
CVE-2007-1983webappsphp
PHP remote file inclusion vulnerability in include/default_header.php in Cyboards PHP Lite 1.21 allows remote attackers
23RISK
open
ReferênciaVexDay Proof
Sisplet CMS 05.10 - 'site_path' Remote File Inclusion
CVE-2007-2347webappsphp
PHP remote file inclusion vulnerability in main/forum/komentar.php in OneClick CMS (aka Sisplet CMS) 05.10 and earlier a
23RISK
open
ReferênciaVexDay Proof
Sendcard 3.4.1 - 'sendcard.php?form' Local File Inclusion
CVE-2007-2471webappsphp
Directory traversal vulnerability in sendcard.php in Sendcard 3.4.1 and earlier allows remote attackers to read arbitrar
23RISK
open
ReferênciaVexDay Proof
6ALBlog - 'newsid' SQL Injection
CVE-2007-3451webappsphp
PHP remote file inclusion vulnerability in admin/index.php in 6ALBlog allows remote authenticated administrators to exec
23RISK
open
ReferênciaVexDay Proof
XOOPS 2.0.18 - Local File Inclusion / URL Redirecting
CVE-2008-0612webappsphp
Directory traversal vulnerability in htdocs/install/index.php in XOOPS 2.0.18 allows remote attackers to include and exe
23RISK
open
ReferênciaVexDay Proof
Web Slider 0.6 - Insecure Cookie/Authentication Handling
CVE-2008-2298webappsphp
Admin.php in Web Slider 0.6 allows remote attackers to bypass authentication and gain privileges by setting the admin co
23RISK
open
ReferênciaVexDay Proof
txtSQL 2.2 Final - 'startup.php' Remote File Inclusion
CVE-2008-3595webappsphp
PHP remote file inclusion vulnerability in examples/txtSQLAdmin/startup.php in txtSQL 2.2 Final allows remote attackers
23RISK
open
ReferênciaVexDay Proof
PhpBlock a8.5 - Multiple Remote File Inclusions
CVE-2008-5210webappsphp
Multiple PHP remote file inclusion vulnerabilities in PhpBlock A8.5 allow remote attackers to execute arbitrary PHP code
23RISK
open
Referência
CVE-2021-30150
Composr 10.0.36 allows XSS in an XML script.
23RISK
open
Referência
CVE-2022-1631
Users Account Pre-Takeover or Users Account Takeover. in microweber/microweber
33RISK
open
Referência
CVE-2010-4612
Multiple SQL injection vulnerabilities in index.php in Hycus CMS 1.0.3, when magic_quotes_gpc is disabled, allow remote
23RISK
open
previouspage 386 / 740next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.