Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,226cataloged exploits
35,420CVEs with public exploitation
24,695lab-tested
22,233 exploits
Referência
CVE-2016-9111
Incorrect access control mechanisms in Citrix Receiver Desktop Lock 4.5 allow an attacker to bypass the authentication r
23RISK
open
Referência
CVE-2016-9111
Incorrect access control mechanisms in Citrix Receiver Desktop Lock 4.5 allow an attacker to bypass the authentication r
23RISK
open
Referência7
CVE-2025-0364: BigAnt Server RCE Exploit
BigAntSoft BigAnt Server Account Registration Bypass to File Upload RCE
48RISK
open
Referência
CVE-2010-2143
Directory traversal vulnerability in index.php in Symphony CMS 2.0.7 allows remote attackers to read arbitrary files and
23RISK
open
Referência
CVE-2017-0147
CVE-2017-0147HIGHunder attackransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Referência
CVE-2017-0147
CVE-2017-0147HIGHunder attackransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
ReferênciaVexDay Proof
creative Guestbook 1.0 - Multiple Vulnerabilities
CVE-2007-1479webappsphp
Cross-site scripting (XSS) vulnerability in Guestbook.php in Creative Guestbook 1.0 allows remote attackers to inject ar
23RISK
open
ReferênciaVexDay Proof
k-links directory - SQL Injection / Cross-Site Scripting
CVE-2008-3581webappsphp
Cross-site scripting (XSS) vulnerability in index.php in Qsoft K-Links allows remote attackers to inject arbitrary web s
23RISK
open
ReferênciaVexDay Proof
Alstrasoft Article Manager Pro 1.6 - Authentication Bypass
CVE-2008-5649webappsphp
SQL injection vulnerability in admin/admin.php in AlstraSoft Article Manager Pro 1.6 allows remote attackers to execute
23RISK
open
Referência
CVE-2010-2156
ISC DHCP 4.1 before 4.1.1-P1 and 4.0 before 4.0.2-P1 allows remote attackers to cause a denial of service (server exit)
60RISK
open
Referência
CVE-2009-3512
Multiple cross-site scripting (XSS) vulnerabilities in MyWeight 1.0 allow remote attackers to inject arbitrary web scrip
23RISK
open
Referência
CVE-2026-5978
Totolink A7100RU CGI cstecgi.cgi setWiFiAclRules os command injection
48RISK
open
Referência
CVE-2026-10165
Edimax BR-6478AC POST Request formWanTcpipSetup stack-based overflow
41RISK
open
ReferênciaVexDay Proof
AuraCMS 2.2 - 'albums' Pramater SQL Injection
CVE-2008-0735webappsphp
SQL injection vulnerability in mod/gallery/ajax/gallery_data.php in AuraCMS 2.2 allows remote attackers to execute arbit
23RISK
open
Referência
CVE-2017-0199
CVE-2017-0199HIGHunder attackransomware
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISK
open
ReferênciaVexDay Proof
Yblog 0.2.2.2 - Cross-Site Scripting / SQL Injection
CVE-2008-2668webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in yBlog 0.2.2.2 allow remote attackers to inject arbitrary web scri
23RISK
open
Referência
CVE-2017-0199
CVE-2017-0199HIGHunder attackransomware
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISK
open
ReferênciaVexDay Proof
TubeGuru Video Sharing Script - 'UID' SQL Injection
CVE-2008-3674webappsphp
SQL injection vulnerability in ugroups.php in PozScripts TubeGuru Video Sharing Script allows remote attackers to execut
23RISK
open
Referência
CVE-2017-0199
CVE-2017-0199HIGHunder attackransomware
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISK
open
ReferênciaVexDay Proof
OneCMS 2.4 - SQL Injection / Upload
CVE-2008-7208webappsphp
Multiple SQL injection vulnerabilities in OneCMS 2.4, and possibly earlier, allow remote attackers to execute arbitrary
23RISK
open
Referência
CVE-2022-37061
All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command Injection. This
60RISK
open
Referência
CVE-2022-37061
All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command Injection. This
60RISK
open
Referência
CVE-2011-1062
Multiple cross-site scripting (XSS) vulnerabilities in include/html/header.php in TaskFreak! 0.6.4 allow remote attacker
23RISK
open
Referência
CVE-2019-9553
Bolt 3.6.4 has XSS via the slug, teaser, or title parameter to editcontent/pages, a related issue to CVE-2017-11128 and
23RISK
open
ReferênciaVexDay Proof
YourFreeWorld Viral Marketing - SQL Injection
CVE-2008-3756webappsphp
SQL injection vulnerability in tr.php in YourFreeWorld Viral Marketing Script allows remote attackers to execute arbitra
23RISK
open
ReferênciaVexDay Proof
VMware Workstation 6.5.1 - 'hcmon.sys 6.0.0.45731' Local Denial of Service
CVE-2008-3761doswindows
hcmon.sys in VMware Workstation 6.5.1 and earlier, VMware Player 2.5.1 and earlier, VMware ACE 2.5.1 and earlier, and VM
23RISK
open
ReferênciaVexDay Proof
PHP Live Helper 2.0.1 - Multiple Vulnerabilities
CVE-2008-3762webappsphp
SQL injection vulnerability in onlinestatus_html.php in Turnkey PHP Live Helper 2.0.1 and earlier allows remote attacker
23RISK
open
Referência
CVE-2008-3756
SQL injection vulnerability in tr.php in YourFreeWorld Viral Marketing Script allows remote attackers to execute arbitra
23RISK
open
Referência
CVE-2018-8732
Cross-site scripting (XSS) vulnerability in WampServer 3.1.1 allows remote attackers to inject arbitrary web script or H
23RISK
open
ReferênciaVexDay Proof
aspwebalbum 3.2 - Multiple Vulnerabilities
CVE-2008-6977webappsasp
Cross-site scripting (XSS) vulnerability in album.asp in Full Revolution aspWebAlbum 3.2 allows remote attackers to inje
23RISK
open
previouspage 402 / 742next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.