Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,151cataloged exploits
35,370CVEs with public exploitation
24,695lab-tested
22,233 exploits
ReferênciaVexDay Proof
2532/Gigs 1.2.2 Stable - Multiple Vulnerabilities
CVE-2008-6901webappsphp
Multiple directory traversal vulnerabilities in 2532designs 2532|Gigs 1.2.2 Stable, when register_globals is enabled and
23RISK
open
ReferênciaVexDay Proof
PHPRunner 4.2 - 'SearchOption' Blind SQL Injection
CVE-2009-0964webappsphp
UserView_list.php in PHPRunner 4.2, and possibly earlier, stores passwords in cleartext in the database, which allows at
23RISK
open
ReferênciaVexDay Proof
TorrentVolve 1.4 - 'deleteTorrent' Delete Arbitrary File
CVE-2009-2101webappsphp
Directory traversal vulnerability in archive.php in TorrentVolve 1.4, when register_globals is enabled, allows remote at
23RISK
open
Referência
CVE-2021-30637
htmly 2.8.0 allows stored XSS via the blog title, Tagline, or Description to config.html.php.
23RISK
open
Referência
CVE-2017-16819
A stored cross-site scripting vulnerability in the Icon Time Systems RTC-1000 v2.5.7458 and earlier time clock allows re
23RISK
open
Referência
CVE-2018-7355
All versions up to V1.0.0B05 of ZTE MF65 and all versions up to V1.0.0B02 of ZTE MF65M1 are impacted by cross-site scrip
23RISK
open
Referência
CVE-2016-7391
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 3
23RISK
open
Referência
CVE-2017-14757
OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might b
23RISK
open
Referência
CVE-2013-10051
InstantCMS <= 1.6 Remote PHP Code Execution
63RISK
open
Referência
CVE-2013-10051
InstantCMS <= 1.6 Remote PHP Code Execution
63RISK
open
Referência
CVE-2013-10051
InstantCMS <= 1.6 Remote PHP Code Execution
63RISK
open
Referência
CVE-2025-6121
D-Link DIR-632 HTTP POST Request get_pure_content stack-based overflow
48RISK
open
Referência
CVE-2009-3424
Multiple PHP remote file inclusion vulnerabilities in MaxCMS 3.11.20b, when register_globals is enabled, allow remote at
23RISK
open
ReferênciaVexDay Proof
EggBlog 3.1.0 - Cookies SQL Injection
CVE-2008-0159webappsphp
SQL injection vulnerability in index.php in eggBlog 3.1.0 and earlier allows remote attackers to execute arbitrary SQL c
23RISK
open
Referência
CVE-2009-0431
SQL injection vulnerability in Default.asp in LinksPro Standard Edition allows remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
Ruby 1.9 - regex engine Remote Socket Memory Leak
CVE-2008-3443dosmultiple
The regular expression engine (regex.c) in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, an
28RISK
open
Referência
CVE-2017-0144
CVE-2017-0144HIGHunder attackransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Referência
CVE-2017-0144
CVE-2017-0144HIGHunder attackransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Referência
CVE-2017-0144
CVE-2017-0144HIGHunder attackransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
ReferênciaVexDay Proof
Dagger CMS 2008 - 'dir_inc' Remote File Inclusion
CVE-2008-6636webappsphp
PHP remote file inclusion vulnerability in skins/default.php in Geody Labs Dagger - The Cutting Edge r12feb2008, when re
23RISK
open
ReferênciaVexDay Proof
SCMS 1 - Local File Inclusion
CVE-2009-0330webappsphp
Directory traversal vulnerability in index.php in Simple Content Management System (SCMS) 1 allows remote attackers to i
23RISK
open
Referência
CVE-2010-2124
SQL injection vulnerability in firma.php in Bartels Schone ConPresso 4.0.7 allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
phpskelsite 1.4 - Local File Inclusion / Remote File Inclusion / Cross-Site Scripting
CVE-2009-0596webappsphp
Directory traversal vulnerability in skysilver/login.tpl.php in phpSkelSite 1.4, when register_globals is enabled, allow
23RISK
open
ReferênciaVexDay Proof
pastelcms 0.8.0 - Local File Inclusion / SQL Injection
CVE-2009-1405webappsphp
Directory traversal vulnerability in index.php in PastelCMS 0.8.0, when magic_quotes_gpc is disabled, allows remote atta
23RISK
open
Referência
CVE-2009-3948
JetAudio 7.5.3 COWON Media Center allows remote attackers to cause a denial of service (memory consumption and applicati
23RISK
open
Referência
CVE-2009-4659
Unspecified vulnerability in MP3-Cutter Ease Audio Cutter 1.20 allows user-assisted remote attackers to cause a denial o
23RISK
open
Referência
CVE-2018-11124
Cross-site scripting (XSS) vulnerability in Attributes functionality in Open-AudIT Community edition before 2.2.2 allows
23RISK
open
Referência
CVE-2013-4867
Electronic Arts Karotz Smart Rabbit 12.07.19.00 allows Python module hijacking
23RISK
open
ReferênciaVexDay Proof
XRms 1.99.2 - Remote File Inclusion / Cross-Site Scripting / Information Gathering
CVE-2008-3398webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in XRMS CRM 1.99.2 allow remote attackers to inject arbitrary web sc
23RISK
open
Referência
CVE-2012-4251
Multiple cross-site scripting (XSS) vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to inject arbitrary web
23RISK
open
previouspage 395 / 742next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.