Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,151cataloged exploits
35,370CVEs with public exploitation
24,695lab-tested
22,233 exploits
Referência
CVE-2018-13457
qh_echo in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to
23RISK
open
Referência
CVE-2014-1906
Multiple cross-site scripting (XSS) vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5
23RISK
open
Referência
CVE-2020-7680
docsify prior to 4.11.4 is susceptible to Cross-site Scripting (XSS). Docsify.js uses fragment identifiers (parameters a
23RISK
open
Referência
CVE-2020-7680
docsify prior to 4.11.4 is susceptible to Cross-site Scripting (XSS). Docsify.js uses fragment identifiers (parameters a
23RISK
open
Referência
CVE-2014-2994
Stack-based buffer overflow in Acunetix Web Vulnerability Scanner (WVS) 8 build 20120704 allows remote attackers to exec
28RISK
open
ReferênciaVexDay Proof
Ventrilo 3.0.2 - Null Pointer Remote Denial of Service
CVE-2008-3680dosmultiple
The decryption function in Flagship Industries Ventrilo 3.0.2 and earlier allows remote attackers to cause a denial of s
23RISK
open
ReferênciaVexDay Proof
Microsoft Visual Studio - 'Msmask32.ocx' ActiveX Remote Buffer Overflow
CVE-2008-3704remotewindows
Heap-based buffer overflow in the MaskedEdit ActiveX control in Msmask32.ocx 6.0.81.69, and possibly other versions befo
50RISK
open
ReferênciaVexDay Proof
fresh email script 1.0 - Multiple Vulnerabilities
CVE-2008-7043webappsphp
Cross-site scripting (XSS) vulnerability in register.php in FreshScripts Fresh Email Script 1.0 through 1.11 allows remo
23RISK
open
Referência
CVE-2009-4092
Cross-site request forgery (CSRF) vulnerability in user.php in Simplog 0.9.3.2, and possibly earlier, allows remote atta
23RISK
open
ReferênciaVexDay Proof
TorrentTrader Classic 1.09 - Multiple Vulnerabilities
CVE-2009-2158webappsphp
account-recover.php in TorrentTrader Classic 1.09 chooses random passwords from an insufficiently large set, which makes
23RISK
open
Referência
CVE-2018-20782
The GloBee plugin before 1.1.2 for WooCommerce mishandles IPN messages.
28RISK
open
Referência
CVE-2021-28379
web/upload/UploadHandler.php in Vesta Control Panel (aka VestaCP) through 0.9.8-27 and myVesta through 0.9.8-26-39 allow
23RISK
open
Referência
CVE-2013-2474
Directory traversal vulnerability in AWS XMS 2.5 allows remote attackers to view arbitrary files via the 'what' paramete
28RISK
open
Referência
CVE-2013-0238
The try_parse_v4_netmask function in hostmask.c in IRCD-Hybrid before 8.0.6 does not properly validate masks, which allo
23RISK
open
Referência
CVE-2015-2291
CVE-2015-2291HIGHunder attackransomware
(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows all
71RISK
open
Referência
CVE-2018-7538
A SQL injection vulnerability in the tracker functionality of Enalean Tuleap software engineering platform before 9.18 a
23RISK
open
ReferênciaVexDay Proof
Hewlett Packard 1.0.0.309 - 'hpqvwocx.dll' ActiveX Magview Overflow (PoC)
CVE-2007-2656doswindows
Stack-based buffer overflow in the Hewlett-Packard (HP) Magview ActiveX control in hpqvwocx.dll 1.0.0.309 allows remote
23RISK
open
Referência
CVE-2016-9351
An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. The directory traversal/file upload error
23RISK
open
Referência
CVE-2009-4097
Stack-based buffer overflow in the MplayInputFile function in Serenity Audio Player 3.2.3 and earlier allows remote atta
23RISK
open
ReferênciaVexDay Proof
NVR SP2 2.0 'nvUnifiedControl.dll 1.1.45.0' - 'SetText()' Command Execution
CVE-2007-4582remotewindows
Buffer overflow in the nvUnifiedControl.AUnifiedControl.1 ActiveX control in nvUnifiedControl.dll 1.1.45.0 in ACTi Netwo
23RISK
open
Referência
CVE-2014-3120
CVE-2014-3120HIGHunder attack
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execut
100RISK
open
ReferênciaVexDay Proof
Ipswitch WS_FTP Home/Professional FTP Client - Remote Format String (PoC)
CVE-2008-3734doswindows
Format string vulnerability in Ipswitch WS_FTP Home 2007.0.0.2 and WS_FTP Professional 2007.1.0.0 allows remote FTP serv
28RISK
open
Referência
CVE-2008-3765
SQL injection vulnerability in code.php in Quick Poll Script allows remote attackers to execute arbitrary SQL commands v
23RISK
open
Referência
CVE-2020-7934
In LifeRay Portal CE 7.1.0 through 7.2.1 GA2, the First Name, Middle Name, and Last Name fields for user accounts in MyA
23RISK
open
Referência
CVE-2010-1538
SQL injection vulnerability in print_raincheck.php in phpRAINCHECK 1.0.1 and earlier allows remote attackers to execute
23RISK
open
Referência
CVE-2015-2182
Multiple cross-site scripting (XSS) vulnerabilities in ZeusCart 4 allow remote attackers to inject arbitrary web script
23RISK
open
Referência
CVE-2015-2182
Multiple cross-site scripting (XSS) vulnerabilities in ZeusCart 4 allow remote attackers to inject arbitrary web script
23RISK
open
ReferênciaVexDay Proof
5 star review - Cross-Site Scripting / SQL Injection
CVE-2008-3779webappsphp
Cross-site scripting (XSS) vulnerability in search/index.php in Five Star Review Script allows remote attackers to injec
23RISK
open
Referência
CVE-2014-5464
Cross-site scripting (XSS) vulnerability in the nDPI traffic classification library in ntopng (aka ntop) before 1.2.1 al
23RISK
open
ReferênciaVexDay Proof
5 star review - Cross-Site Scripting / SQL Injection
CVE-2008-3780webappsphp
SQL injection vulnerability in recommend.php in Five Star Review Script allows remote attackers to execute arbitrary SQL
23RISK
open
previouspage 393 / 742next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.