Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,151cataloged exploits
35,370CVEs with public exploitation
24,695lab-tested
22,233 exploits
Referência
CVE-2010-3483
cms_write.php in Primitive CMS 1.0.9 does not properly restrict access, which allows remote attackers to gain administra
23RISK
open
Referência
CVE-2013-2712
Cross-site scripting (XSS) vulnerability in services/get_article.php in KrisonAV CMS before 3.0.2 allows remote attacker
23RISK
open
Referência
CVE-2024-48445
An issue in compop.ca ONLINE MALL v.3.5.3 allows a remote attacker to execute arbitrary code via the rid, tid, et, and t
48RISK
open
Referência
CVE-2022-36633
Teleport 9.3.6 is vulnerable to Command injection leading to Remote Code Execution. An attacker can craft a malicious ss
35RISK
open
Referência
CVE-2014-0793
Multiple cross-site scripting (XSS) vulnerabilities in the StackIdeas Komento (com_komento) component before 1.7.3 for J
23RISK
open
Referência
CVE-2014-10018
Cross-site scripting (XSS) vulnerability in webconfig/wlan/country.html/country in the Teracom T2-B-Gawv1.4U10Y-BI modem
23RISK
open
Referência
CVE-2010-1146
The Linux kernel 2.6.33.2 and earlier, when a ReiserFS filesystem exists, does not restrict read or write access to the
23RISK
open
Referência
CVE-2012-2569
Cross-site scripting (XSS) vulnerability in Synametrics Technologies Xeams 4.4 Build 5720 allows remote attackers to inj
23RISK
open
Referência
CVE-2026-5995
Totolink A7100RU CGI cstecgi.cgi setMiniuiHomeInfoShow os command injection
48RISK
open
Referência
CVE-2026-10182
TRENDnet TEW-432BRP formWlanSetup command injection
33RISK
open
ReferênciaVexDay Proof
ASPPortal 4.0.0 - 'default1.asp' SQL Injection
CVE-2006-5879webappsasp
SQL injection vulnerability in default1.asp in ASPPortal 4.0.0 beta and earlier allows remote attackers to execute arbit
23RISK
open
Referência
CVE-2026-5996
Totolink A7100RU CGI cstecgi.cgi setAdvancedInfoShow os command injection
48RISK
open
ReferênciaVexDay Proof
NuRems 1.0 - 'propertysdetails.asp' SQL Injection
CVE-2006-5886webappsasp
SQL injection vulnerability in propertysdetails.asp in Dynamic Dataworx NuRealestate (NuRems) 1.0 and earlier allows rem
23RISK
open
Referência
CVE-2010-0678
PHP remote file inclusion vulnerability in includes/moderation.php in Katalog Stron Hurricane 1.3.5, and possibly earlie
23RISK
open
Referência
CVE-2010-0678
PHP remote file inclusion vulnerability in includes/moderation.php in Katalog Stron Hurricane 1.3.5, and possibly earlie
23RISK
open
Referência
CVE-2008-3513
SQL injection vulnerability in the Book Catalog module 1.0 for PHP-Nuke allows remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
Anata CMS 1.0b5 - 'change.php' Arbitrary Add Admin
CVE-2008-6665webappsphp
change.php in Ananta CMS 1.0b5, with magic_quotes_gpc disabled, allows remote attackers to gain administrator privileges
23RISK
open
Referência
CVE-2017-8422
KDE kdelibs before 4.14.32 and KAuth before 5.34 allow local users to gain root privileges by spoofing a callerID and le
23RISK
open
Referência
CVE-2010-3490
Directory traversal vulnerability in page.recordings.php in the System Recordings component in the configuration interfa
23RISK
open
Referência
CVE-2012-1787
Multiple cross-site scripting (XSS) vulnerabilities in wgarcmin.cgi in Webglimpse 2.20.0 and earlier allow remote attack
23RISK
open
Referência
CVE-2009-3360
Multiple cross-site scripting (XSS) vulnerabilities in Datemill 1.0 allow remote attackers to inject arbitrary web scrip
23RISK
open
Referência
CVE-2011-5140
Multiple SQL injection vulnerabilities in the blog module 1.0 for DiY-CMS allow remote attackers to execute arbitrary SQ
23RISK
open
ReferênciaVexDay Proof
NuSchool 1.0 - 'CampusNewsDetails.asp' SQL Injection
CVE-2006-5887webappsasp
SQL injection vulnerability in CampusNewsDetails.asp in Dynamic Dataworx NuSchool 1.0 allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
BolinOS 4.6.1 - Local File Inclusion / Cross-Site Scripting
CVE-2008-1556webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in BolinOS 4.6.1 allow remote attackers to inject arbitrary web scri
23RISK
open
Referência
CVE-2026-10178
code-projects Online Music Site AdminEditAlbum.php sql injection
33RISK
open
Referência
CVE-2026-13547
Hanwang e-Face General Management Platform upload.do unrestricted upload
33RISK
open
Referência
CVE-2010-2141
SQL injection vulnerability in index.php in NITRO Web Gallery allows remote attackers to execute arbitrary SQL commands
23RISK
open
Referência
CVE-2010-2141
SQL injection vulnerability in index.php in NITRO Web Gallery allows remote attackers to execute arbitrary SQL commands
23RISK
open
Referência
CVE-2008-3561
SQL injection vulnerability in s03.php in Powergap Shopsystem, when magic_quotes_gpc is disabled, allows remote attacker
23RISK
open
Referência
CVE-2017-0146
CVE-2017-0146HIGHunder attackransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
previouspage 399 / 742next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.