Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,231cataloged exploits
35,420CVEs with public exploitation
24,695lab-tested
22,233 exploits
ReferênciaVexDay Proof
polypager 1.0rc2 - SQL Injection / Cross-Site Scripting
CVE-2008-3506webappsphp
SQL injection vulnerability in PolyPager 1.0 rc2 and earlier allows remote attackers to execute arbitrary SQL commands v
23RISK
open
ReferênciaVexDay Proof
LoveCMS 1.6.2 Final - Update Settings
CVE-2008-3509webappsphp
LoveCMS 1.6.2 does not require administrative authentication for (1) addblock.php, (2) blocks.php, and (3) themes.php in
23RISK
open
Referência
CVE-2020-2944
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Common Desktop Environment). Supported version
41RISK
open
Referência
CVE-2025-34056
AVTECH IP camera, DVR, and NVR Devices Authenticated Root Command Execution
48RISK
open
Referência
CVE-2025-34056
AVTECH IP camera, DVR, and NVR Devices Authenticated Root Command Execution
48RISK
open
Referência
CVE-2025-8191
macrozheng mall Swagger UI index.html cross site scripting
33RISK
open
Referência
CVE-2015-7515
The aiptek_probe function in drivers/input/tablet/aiptek.c in the Linux kernel before 4.4 allows physically proximate at
23RISK
open
Referência
CVE-2022-43684
ACL bypass in Reporting functionality
48RISK
open
ReferênciaVexDay Proof
acFTP FTP Server 1.5 - 'REST/PBSZ' Remote Denial of Service
CVE-2006-6775doswindows
acFTP 1.5 allows remote authenticated users to cause a denial of service via a crafted argument to the (1) REST or (2) P
23RISK
open
Referência
CVE-2015-1423
Multiple SQL injection vulnerabilities in Gecko CMS 2.2 and 2.3 allow remote administrators to execute arbitrary SQL com
23RISK
open
Referência
CVE-2015-1423
Multiple SQL injection vulnerabilities in Gecko CMS 2.2 and 2.3 allow remote administrators to execute arbitrary SQL com
23RISK
open
Referência
CVE-2014-10033
SQL injection vulnerability in the update_zone function in catalog/admin/geo_zones.php in osCommerce Online Merchant 2.3
23RISK
open
Referência
CVE-2017-15727
In phpMyFAQ before 2.9.9, there is Stored Cross-site Scripting (XSS) via an HTML attachment.
23RISK
open
Referência
CVE-2016-3136
The mct_u232_msr_to_state function in drivers/usb/serial/mct_u232.c in the Linux kernel before 4.5.1 allows physically p
23RISK
open
Referência
CVE-2018-11403
DomainMod v4.09.03 has XSS via the assets/edit/account-owner.php oid parameter.
23RISK
open
Referência
CVE-2017-0146
CVE-2017-0146HIGHunder attackransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Referência
CVE-2018-19750
DomainMOD through 4.11.01 has XSS via the admin/domain-fields/ notes field in an Add Custom Field action for Custom Doma
23RISK
open
Referência
CVE-2009-4658
Xerver 4.32 allows remote authenticated users to cause a denial of service (daemon crash) via a non-numeric web port ass
23RISK
open
Referência
CVE-2017-8838
XSS via syncid exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380h
23RISK
open
Referência
CVE-2017-0146
CVE-2017-0146HIGHunder attackransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
ReferênciaVexDay Proof
IceBB 1.0-rc5 - Remote Code Execution
CVE-2007-1725webappsphp
SQL injection vulnerability in index.php in IceBB 1.0-rc5 allows remote authenticated users to execute arbitrary SQL com
23RISK
open
ReferênciaVexDay Proof
IceBB 1.0-rc5 - Remote Create Admin
CVE-2007-1725webappsphp
SQL injection vulnerability in index.php in IceBB 1.0-rc5 allows remote authenticated users to execute arbitrary SQL com
23RISK
open
Referência
CVE-2010-2156
ISC DHCP 4.1 before 4.1.1-P1 and 4.0 before 4.0.2-P1 allows remote attackers to cause a denial of service (server exit)
60RISK
open
Referência
CVE-2009-3512
Multiple cross-site scripting (XSS) vulnerabilities in MyWeight 1.0 allow remote attackers to inject arbitrary web scrip
23RISK
open
Referência
CVE-2026-5978
Totolink A7100RU CGI cstecgi.cgi setWiFiAclRules os command injection
48RISK
open
Referência
CVE-2026-10165
Edimax BR-6478AC POST Request formWanTcpipSetup stack-based overflow
41RISK
open
ReferênciaVexDay Proof
AuraCMS 2.2 - 'albums' Pramater SQL Injection
CVE-2008-0735webappsphp
SQL injection vulnerability in mod/gallery/ajax/gallery_data.php in AuraCMS 2.2 allows remote attackers to execute arbit
23RISK
open
Referência
CVE-2017-0199
CVE-2017-0199HIGHunder attackransomware
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISK
open
ReferênciaVexDay Proof
Yblog 0.2.2.2 - Cross-Site Scripting / SQL Injection
CVE-2008-2668webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in yBlog 0.2.2.2 allow remote attackers to inject arbitrary web scri
23RISK
open
Referência
CVE-2017-0199
CVE-2017-0199HIGHunder attackransomware
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISK
open
previouspage 408 / 742next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.