Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,231cataloged exploits
35,420CVEs with public exploitation
24,695lab-tested
22,233 exploits
Referência
CVE-2010-4635
SQL injection vulnerability in detail.asp in Site2Nite Vacation Rental (VRBO) Listings allows remote attackers to execut
23RISK
open
Referência
CVE-2010-4635
SQL injection vulnerability in detail.asp in Site2Nite Vacation Rental (VRBO) Listings allows remote attackers to execut
23RISK
open
Referência
CVE-2010-2354
SQL injection vulnerability in subscribe.php in Pilot Group (PG) eLMS Pro allows remote attackers to execute arbitrary S
23RISK
open
Referência
CVE-2010-2354
SQL injection vulnerability in subscribe.php in Pilot Group (PG) eLMS Pro allows remote attackers to execute arbitrary S
23RISK
open
Referência
CVE-2010-4791
SQL injection vulnerability in infusions/mg_user_fotoalbum_panel/mg_user_fotoalbum.php in the MG User-Fotoalbum (mg_user
23RISK
open
Referência
CVE-2026-14840
YOP Poll < 7.0.6 - Unauthenticated Vote Restriction Bypass via IP Header Spoofing
33RISK
open
ReferênciaVexDay Proof
doITlive CMS 2.50 - SQL Injection / Cross-Site Scripting
CVE-2008-2843webappsasp
Multiple SQL injection vulnerabilities in doITLive CMS 2.50 and earlier allow remote attackers to execute arbitrary SQL
23RISK
open
Referência
CVE-2010-2338
Multiple SQL injection vulnerabilities in redir.asp in VU Web Visitor Analyst allow remote attackers to execute arbitrar
23RISK
open
Referência
CVE-2010-2338
Multiple SQL injection vulnerabilities in redir.asp in VU Web Visitor Analyst allow remote attackers to execute arbitrar
23RISK
open
Referência
CVE-2011-1055
SQL injection vulnerability in api/ice_media.cfc in Lingxia I.C.E CMS 1.0 allows remote attackers to execute arbitrary S
23RISK
open
Referência
CVE-2010-0701
SQL injection vulnerability in ForceChangePassword.jsp in Newgen Software OmniDocs allows remote attackers to execute ar
23RISK
open
Referência
CVE-2010-0701
SQL injection vulnerability in ForceChangePassword.jsp in Newgen Software OmniDocs allows remote attackers to execute ar
23RISK
open
Referência
CVE-2010-1660
SQL injection vulnerability in help-details.php in CLScript Classifieds Script allows remote attackers to execute arbitr
23RISK
open
Referência
CVE-2010-1660
SQL injection vulnerability in help-details.php in CLScript Classifieds Script allows remote attackers to execute arbitr
23RISK
open
Referência
CVE-2010-1070
SQL injection vulnerability in index.php in ImagoScripts Deviant Art Clone allows remote attackers to execute arbitrary
23RISK
open
Referência
CVE-2010-1070
SQL injection vulnerability in index.php in ImagoScripts Deviant Art Clone allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
ZeeReviews - SQL Injection
CVE-2008-3669webappsphp
SQL injection vulnerability in comments.php in ZeeScripts Reviews Opinions Rating Posting Engine Web-Site PHP Script (ak
23RISK
open
Referência
CVE-2010-2696
SQL injection vulnerability in gallery/index.php in Sijio Community Software allows remote attackers to execute arbitrar
23RISK
open
ReferênciaVexDay Proof
zeeproperty - 'adid' SQL Injection
CVE-2008-4621webappsphp
SQL injection vulnerability in bannerclick.php in ZeeScripts Zeeproperty allows remote attackers to execute arbitrary SQ
23RISK
open
ReferênciaVexDay Proof
Online Booking Manager 2.2 - 'id' SQL Injection
CVE-2008-5194webappsphp
SQL injection vulnerability in checkavail.php in SoftVisions Software Online Booking Manager (obm) 2.2 allows remote att
23RISK
open
ReferênciaVexDay Proof
Domain Seller Pro 1.5 - 'id' SQL Injection
CVE-2008-5788webappsphp
SQL injection vulnerability in index.php in Domain Seller Pro 1.5 allows remote attackers to execute arbitrary SQL comma
23RISK
open
Referência
CVE-2010-1529
SQL injection vulnerability in the Freestyle FAQs Lite (com_fsf) component, possibly 1.3, for Joomla! allows remote atta
23RISK
open
Referência
CVE-2010-1529
SQL injection vulnerability in the Freestyle FAQs Lite (com_fsf) component, possibly 1.3, for Joomla! allows remote atta
23RISK
open
ReferênciaVexDay Proof
bugmall shopping cart 2.5 - SQL Injection / Cross-Site Scripting
CVE-2007-3447webappsphp
SQL injection vulnerability in BugMall Shopping Cart 2.5 and earlier allows remote attackers to execute arbitrary SQL co
23RISK
open
Referência
CVE-2012-10026
WordPress Plugin Asset-Manager <= 2.0 PHP File Upload
63RISK
open
Referência
CVE-2012-10026
WordPress Plugin Asset-Manager <= 2.0 PHP File Upload
63RISK
open
Referência
CVE-2012-10026
WordPress Plugin Asset-Manager <= 2.0 PHP File Upload
63RISK
open
Referência
CVE-2012-10026
WordPress Plugin Asset-Manager <= 2.0 PHP File Upload
63RISK
open
Referência
CVE-2017-12930
SQL Injection in the admin interface in TecnoVISION DLX Spot Player4 version >1.5.10 allows remote unauthenticated users
23RISK
open
Referência
CVE-2010-4793
SQL injection vulnerability in detail.asp in Site2Nite Auto e-Manager allows remote attackers to execute arbitrary SQL c
23RISK
open
previouspage 405 / 742next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.