Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,231cataloged exploits
35,420CVEs with public exploitation
24,695lab-tested
22,266 exploits
ReferênciaVexDay Proof
Joomla! Component joovideo 1.2.2 - 'id' SQL Injection
CVE-2008-1460webappsphp
SQL injection vulnerability in the Joovideo (com_joovideo) 1.0 and 1.2.2 component for Mambo and Joomla! allows remote a
23RISK
open
Referência
CVE-2019-13493
In Sitecore 9.0 rev 171002, Persistent XSS exists in the Media Library and File Manager. An authenticated unprivileged u
23RISK
open
Referência
CVE-2018-10365
An XSS issue was discovered in the Threads to Link plugin 1.3 for MyBB. When editing a thread, the user is given the opt
23RISK
open
Referência
CVE-2018-5263
The StackIdeas EasyDiscuss (aka com_easydiscuss) extension before 4.0.21 for Joomla! allows XSS.
23RISK
open
Referência
CVE-2010-3209
Multiple PHP remote file inclusion vulnerabilities in Seagull 0.6.7 allow remote attackers to execute arbitrary PHP code
23RISK
open
Referência
CVE-2010-3209
Multiple PHP remote file inclusion vulnerabilities in Seagull 0.6.7 allow remote attackers to execute arbitrary PHP code
23RISK
open
Referência
CVE-2016-6689
Binder in the kernel in Android before 2016-10-05 on Nexus devices allows attackers to obtain sensitive information via
23RISK
open
Referência
CVE-2016-8742
The Windows installer that the Apache CouchDB team provides was vulnerable to local privilege escalation. All files in t
23RISK
open
Referência
CVE-2017-0091
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers
28RISK
open
Referência
CVE-2010-1874
SQL injection vulnerability in the Real Estate Property (com_properties) component 3.1.22-03 for Joomla! allows remote a
23RISK
open
Referência
CVE-2017-0092
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers
28RISK
open
ReferênciaVexDay Proof
PHP Classifieds Script 05122008 - SQL Injection
CVE-2008-2453webappsphp
Multiple SQL injection vulnerabilities in PHP Classifieds Script allow remote attackers to execute arbitrary SQL command
23RISK
open
Referência
Neo Billing 3.5 - Persistent Cross-Site Scripting
CVE-2020-23518webappsphp
Cross Site Scripting (XSS) vulnerability in UltimateKode Neo Billing - Accounting, Invoicing And CRM Software up to vers
23RISK
open
ReferênciaVexDay Proof
Mambo Component Pearl 1.6 - Multiple Remote File Inclusions
CVE-2006-3340webappsphp
Multiple PHP remote file inclusion vulnerabilities in Pearl For Mambo module 1.6 for Mambo, when register_globals is ena
28RISK
open
ReferênciaVexDay Proof
FizzMedia 1.51.2 - SQL Injection
CVE-2008-3378webappsphp
SQL injection vulnerability in comment.php in Fizzmedia 1.51.2 allows remote attackers to execute arbitrary SQL commands
23RISK
open
ReferênciaVexDay Proof
MojoAuto - Blind SQL Injection
CVE-2008-3383webappscgi
SQL injection vulnerability in mojoAuto.cgi in MojoAuto allows remote attackers to execute arbitrary SQL commands via th
23RISK
open
ReferênciaVexDay Proof
Joomla! Component Ignite Gallery 0.8.3 - SQL Injection
CVE-2008-6182webappsphp
SQL injection vulnerability in the Ignite Gallery (com_ignitegallery) component 0.8.0 through 0.8.3 for Joomla! allows r
23RISK
open
ReferênciaVexDay Proof
Peel Shopping 3.1 - 'rubid' SQL Injection
CVE-2008-6892webappsphp
SQL injection vulnerability in lire/index.php in Peel 3.1 allows remote attackers to execute arbitrary SQL commands via
23RISK
open
Referência
CVE-2023-27040
Simple Image Gallery v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the username paramet
48RISK
open
Referência
CVE-2017-0115
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers
28RISK
open
Referência
CVE-2022-3141
Translatepress Multilinugal < 2.3.3 - Admin+ SQLi
23RISK
open
Referência
CVE-2009-2218
Multiple PHP remote file inclusion vulnerabilities in phpCollegeExchange 0.1.5c, when register_globals is enabled, allow
23RISK
open
Referência
CVE-2026-9367
NousResearch hermes-agent terminal_tool approval.py detect_dangerous_command os command injection
33RISK
open
Referência
CVE-2009-3359
Multiple cross-site scripting (XSS) vulnerabilities in Match Agency BiZ 1.0 allow remote attackers to inject arbitrary w
23RISK
open
Referência
CVE-2009-3186
Multiple cross-site scripting (XSS) vulnerabilities in VideoGirls BiZ allow remote attackers to inject arbitrary web scr
23RISK
open
ReferênciaVexDay Proof
LiveCMS 3.4 - 'categoria.php?cid' SQL Injection
CVE-2007-3291webappsphp
Cross-site scripting (XSS) vulnerability in LiveCMS 3.4 and earlier allows remote attackers to inject arbitrary web scri
23RISK
open
Referência
CVE-2009-3715
Multiple SQL injection vulnerabilities in scr_login.php in MCshoutbox 1.1, when magic_quotes_gpc is disabled, allow remo
23RISK
open
ReferênciaVexDay Proof
Dokeos 1.8.4 - Arbitrary File Upload
CVE-2007-6479webappsphp
Unrestricted file upload vulnerability in the "My productions" component for main/auth/profile.php (aka the "My profile"
23RISK
open
Referência
CVE-2017-0116
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers
28RISK
open
Referência
CVE-2018-18858
Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS.
23RISK
open
previouspage 411 / 743next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.