Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,151cataloged exploits
35,370CVEs with public exploitation
24,695lab-tested
22,233 exploits
Referência
CVE-2015-1130
CVE-2015-1130HIGHunder attack
The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and o
86RISK
open
Referência
CVE-2009-4761
Stack-based buffer overflow in Mini-stream RM Downloader allows remote attackers to execute arbitrary code via a long st
23RISK
open
ReferênciaVexDay Proof
Easy Scripts Answer and Question Script - Multiple Vulnerabilities
CVE-2009-1664webappsphp
myaccount.php in Easy Scripts Answer and Question Script does not verify the original password before changing passwords
23RISK
open
ReferênciaVexDay Proof
TCPDB 3.8 - Arbitrary Add Admin Account
CVE-2009-1670webappsphp
user/index.php in TCPDB 3.8 does not require administrative authentication, which allows remote attackers to add admin a
23RISK
open
ReferênciaVexDay Proof
32bit FTP - 'PASV' Reply Client Remote Overflow (Metasploit)
CVE-2009-1675remotewindows_x86
Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a
43RISK
open
ReferênciaVexDay Proof
Flyspeck CMS 6.8 - Local/Remote File Inclusion / Change Add Admin
CVE-2009-1770webappsphp
Directory traversal vulnerability in includes/database/examples/addressbook.php in Flyspeck CMS 6.8 allows remote attack
23RISK
open
ReferênciaVexDay Proof
ST-Gallery 0.1a - Multiple SQL Injections
CVE-2009-1799webappsphp
Multiple SQL injection vulnerabilities in the getGalleryImage function in st_admin/gallery_output.php in ST-Gallery 0.1
23RISK
open
ReferênciaVexDay Proof
my-gesuad 0.9.14 - Authentication Bypass / SQL Injection / Cross-Site Scripting
CVE-2009-1811webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in myGesuad 0.9.14 (aka 0.9) allow remote attackers to inject arbitr
23RISK
open
ReferênciaVexDay Proof
PHPenpals 1.1 - 'mail.php?ID' SQL Injection
CVE-2009-1814webappsphp
SQL injection vulnerability in mail.php in PHPenpals 1.1 and earlier allows remote attackers to execute arbitrary SQL co
23RISK
open
ReferênciaVexDay Proof
Audioactive Player 1.93b - '.m3u' Local Buffer Overflow
CVE-2009-1815localwindows
Stack-based buffer overflow in Sonic Spot Audioactive Player 1.93b allows remote attackers to execute arbitrary code via
23RISK
open
ReferênciaVexDay Proof
Audioactive Player 1.93b - '.m3u' Local Buffer Overflow (SEH)
CVE-2009-1815localwindows
Stack-based buffer overflow in Sonic Spot Audioactive Player 1.93b allows remote attackers to execute arbitrary code via
23RISK
open
ReferênciaVexDay Proof
2DayBiz Custom T-shirt Design - SQL Injection / Cross-Site Scripting
CVE-2009-1819webappsphp
SQL injection vulnerability in product.php in 2daybiz Custom T-shirt Design Script allows remote attackers to execute ar
23RISK
open
ReferênciaVexDay Proof
2DayBiz Custom T-shirt Design - SQL Injection / Cross-Site Scripting
CVE-2009-1820webappsphp
Cross-site scripting (XSS) vulnerability in product.php in 2daybiz Custom T-shirt Design Script allows remote attackers
23RISK
open
ReferênciaVexDay Proof
ArcaVir 2009 < 9.4.320X.9 - 'ps_drv.sys' Local Privilege Escalation
CVE-2009-1824localwindows
The ps_drv.sys kernel driver in ArcaBit ArcaVir 2009 Antivirus Protection 9.4.3201.9 and earlier, ArcaVir 2009 Internet
23RISK
open
ReferênciaVexDay Proof
my-colex 1.4.2 - Authentication Bypass / SQL Injection / Cross-Site Scripting
CVE-2009-1825webappsphp
modules/admuser.php in myColex 1.4.2 does not require administrative authentication, which allows remote authenticated u
23RISK
open
ReferênciaVexDay Proof
my-gesuad 0.9.14 - Authentication Bypass / SQL Injection / Cross-Site Scripting
CVE-2009-1826webappsphp
modules/admuser.php in myGesuad 0.9.14 (aka 0.9) does not require administrative authentication, which allows remote aut
23RISK
open
Referência
CVE-2015-1187
CVE-2015-1187CRITICALunder attack
The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr
100RISK
open
Referência
CVE-2015-1305
McAfee Data Loss Prevention Endpoint (DLPe) before 9.3.400 allows local users to write to arbitrary memory locations, an
23RISK
open
Referência
CVE-2015-1325
Race condition in Apport before 2.17.2-0ubuntu1.1 as packaged in Ubuntu 15.04, before 2.14.70ubuntu8.5 as packaged in Ub
23RISK
open
Referência
CVE-2015-1328
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RISK
open
Referência
CVE-2015-1328
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RISK
open
Referência
CVE-2015-1336
The daily mandb cleanup job in Man-db before 2.7.6.1-1 as packaged in Ubuntu and Debian allows local users with access t
23RISK
open
Referência
CVE-2015-1338
kernel_crashdump in Apport before 2.19 allows local users to cause a denial of service (disk consumption) or possibly ga
23RISK
open
Referência
CVE-2015-1362
Buffer overflow in the Customize 35mm tab in Two Pilots Exif Pilot 4.7.2 allows remote attackers to execute arbitrary co
23RISK
open
Referência
CVE-2015-1368
Multiple cross-site scripting (XSS) vulnerabilities in Ansible Tower (aka Ansible UI) before 2.0.5 allow remote attacker
23RISK
open
Referência
CVE-2015-1368
Multiple cross-site scripting (XSS) vulnerabilities in Ansible Tower (aka Ansible UI) before 2.0.5 allow remote attacker
23RISK
open
Referência
CVE-2015-1375
pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not properly restrict access to the upload
28RISK
open
Referência
CVE-2015-1422
Multiple cross-site scripting (XSS) vulnerabilities in Gecko CMS 2.2 and 2.3 allow remote attackers to inject arbitrary
23RISK
open
Referência
CVE-2015-1422
Multiple cross-site scripting (XSS) vulnerabilities in Gecko CMS 2.2 and 2.3 allow remote attackers to inject arbitrary
23RISK
open
Referência
CVE-2022-41040
CVE-2022-41040HIGHunder attackransomware
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RISK
open
previouspage 389 / 742next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.