Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,151cataloged exploits
35,370CVEs with public exploitation
24,695lab-tested
22,233 exploits
Referência
CVE-2026-11867
Frontend Admin by DynamiApps < 3.29.7 - Subscriber+ Taxonomy Term Creation/Modification/Deletion via Missing Authorization
33RISK
open
Referência
CVE-2014-8810
SQL injection vulnerability in ajax/mail_functions.php in the WP Symposium plugin before 14.11 for WordPress allows remo
23RISK
open
ReferênciaVexDay Proof
R2K Gallery 1.7 - 'galeria.php?lang2' Local File Inclusion
CVE-2007-2642webappsphp
Directory traversal vulnerability in galeria.php in R2K Gallery 1.7 allows remote attackers to read arbitrary files via
23RISK
open
Referência
CVE-2014-9305
SQL injection vulnerability in the shortcodeProductsTable function in models/Cart66Ajax.php in the Cart66 Lite plugin be
23RISK
open
Referência
CVE-2014-9305
SQL injection vulnerability in the shortcodeProductsTable function in models/Cart66Ajax.php in the Cart66 Lite plugin be
23RISK
open
Referência
CVE-2017-8469
The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2,
23RISK
open
ReferênciaVexDay Proof
Orbit Downloader 2.8.7 - Arbitrary File Deletion
CVE-2009-1064remotewindows
Argument injection vulnerability in orbitmxt.dll 2.1.0.2 in the Orbit Downloader 2.8.7 and earlier ActiveX control allow
23RISK
open
ReferênciaVexDay Proof
FlashChat 4.5.7 - 'aedating4CMS.php' Remote File Inclusion
CVE-2006-4583webappsphp
Multiple PHP remote file inclusion vulnerabilities in FlashChat before 4.6.2 allow remote attackers to execute arbitrary
23RISK
open
Referência
CVE-2017-8462
The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2,
23RISK
open
Referência
CVE-2011-0643
Cross-site request forgery (CSRF) vulnerability in admin/conf_users_edit.php in PHP Link Directory (phpLD) 4.1.0 allows
23RISK
open
Referência
CVE-2011-0644
SQL injection vulnerability in include/admin/model_field.class.php in PHPCMS 2008 V2 allows remote attackers to execute
23RISK
open
Referência
CVE-2011-0646
SQL injection vulnerability in viewfaqs.php in PHP LOW BIDS allows remote attackers to execute arbitrary SQL commands vi
23RISK
open
Referência
CVE-2014-2976
Directory traversal vulnerability in Sixnet SixView Manager 2.4.1 allows remote attackers to read arbitrary files via a
23RISK
open
Referência
CVE-2026-67184
TinyWeb 0.0.8 Null Pointer Dereference DoS via Malformed HTTP Request
41RISK
open
Referência
CVE-2018-25126
TVT NVMS-9000 Hard-coded API Credentials & Command Injection
48RISK
open
Referência
CVE-2018-25126
TVT NVMS-9000 Hard-coded API Credentials & Command Injection
48RISK
open
Referência
CVE-2017-15974
tPanel 2009 allows SQL injection for Authentication Bypass via 'or 1=1 or ''=' to login.php.
23RISK
open
Referência
CVE-2017-15974
tPanel 2009 allows SQL injection for Authentication Bypass via 'or 1=1 or ''=' to login.php.
23RISK
open
Referência
CVE-2019-17624
"" In X.Org X Server 1.20.4, there is a stack-based buffer overflow in the function XQueryKeymap. For example, by sendin
23RISK
open
Referência
CVE-2018-0968
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISK
open
Referência
Authenticated low-privileged RCE in Coolify via unsanitized shell commands in the Git Repository field.
Coolify Git Repository Field Command Injection in Project Deployment Workflow
48RISK
open
Referência
CVE-2015-2275
Cross-site scripting (XSS) vulnerability in WoltLab Community Gallery 2.0 before 2014-12-26 allows remote attackers to i
23RISK
open
ReferênciaVexDay Proof
Neon Labs Website 3.2 - 'nl.php?g_strRootDir' Remote File Inclusion
CVE-2007-0496webappsphp
PHP remote file inclusion vulnerability in lib/nl/nl.php in Neon Labs Website (nlws) 3.2 and earlier allows remote attac
23RISK
open
Referência
CVE-2022-39285
Stored Cross-Site Scripting Vulnerability In File Parameter in zoneminder
41RISK
open
Referência
CVE-2015-1028
Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2730B router (rev C1) with firmware GE_1.01 allow remo
23RISK
open
Referência
CVE-2026-4567
Tenda A15 UploadCfg stack-based overflow
48RISK
open
Referência
CVE-2022-3481
WooCommerce Dropshipping < 4.4 - Unauthenticated SQLi
63RISK
open
Referência
CVE-2020-14943
The Firstname and Lastname parameters in Global RADAR BSA Radar 1.6.7234.24750 and earlier are vulnerable to stored cros
23RISK
open
Referência
CVE-2006-4853
SQL injection vulnerability in kategorix.asp in Haberx 1.02 through 1.1 allows remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
TeamCalPro 3.1.000 - Multiple Local/Remote File Inclusions
CVE-2007-6553webappsphp
Multiple PHP remote file inclusion vulnerabilities in TeamCal Pro 3.1.000 and earlier allow remote attackers to execute
23RISK
open
previouspage 396 / 742next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.