Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,231cataloged exploits
35,420CVEs with public exploitation
24,695lab-tested
22,266 exploits
Referência
CVE-2010-4269
SQL injection vulnerability in managechat.php in Collabtive 0.65 allows remote attackers to execute arbitrary SQL comman
23RISK
open
Referência
CVE-2010-4272
SQL injection vulnerability in the Pulse Infotech Sponsor Wall (com_sponsorwall) component 1.1 for Joomla! allows remote
23RISK
open
Referência
CVE-2010-4633
SQL injection vulnerability in cart.php in digiSHOP 2.0.2 allows remote attackers to execute arbitrary SQL commands via
23RISK
open
Referência
CVE-2012-3152
CVE-2012-3152CRITICALunder attack
Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and
100RISK
open
Referência
CVE-2018-15473
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open
Referência
CVE-2026-16293
Blubrry PowerPress < 11.16.11 - Contributor+ Stored XSS via Podcast Episode Chapters URL
33RISK
open
ReferênciaVexDay Proof
EasyCalendar 4.0tr - Multiple Vulnerabilities
CVE-2008-1345webappsphp
Cross-site scripting (XSS) vulnerability in plugins/calendar/calendar_backend.php in MyioSoft EasyCalendar 4.0tr and ear
23RISK
open
Referência
CVE-2010-4636
SQL injection vulnerability in detail.asp in Site2Nite Business e-Listings allows remote attackers to execute arbitrary
23RISK
open
Referência
CVE-2010-4638
SQL injection vulnerability in the submitSurvey function in controller.php in JQuarks4s (com_jquarks4s) component 1.0.0
23RISK
open
Referência
CVE-2010-4737
SQL injection vulnerability in resorts.asp in HotWebScripts HotWeb Rentals allows remote attackers to execute arbitrary
23RISK
open
Referência
CVE-2010-4738
Multiple SQL injection vulnerabilities in Rae Media INC Real Estate Single and Multi Agent System 3.0 allow remote attac
23RISK
open
Referência
CVE-2010-4740
Stack-based buffer overflow in WTclient.dll in SCADA Engine BACnet OPC Client before 1.0.25 allows user-assisted remote
50RISK
open
Referência
CVE-2010-4770
SQL injection vulnerability in index.php in CommodityRentals DVD Rentals Script allows remote attackers to execute arbit
23RISK
open
Referência
CVE-2010-4770
SQL injection vulnerability in index.php in CommodityRentals DVD Rentals Script allows remote attackers to execute arbit
23RISK
open
Referência
CVE-2010-4771
SQL injection vulnerability to viewforum.php in S-CMS 2.5 allows remote attackers to execute arbitrary SQL commands via
23RISK
open
Referência
CVE-2010-4772
Cross-site scripting (XSS) vulnerability in blocks/lang.php in S-CMS 2.5 allows remote attackers to inject arbitrary web
23RISK
open
Referência
CVE-2015-1427
CVE-2015-1427CRITICALunder attack
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the s
100RISK
open
Referência
CVE-2010-4774
SQL injection vulnerability in pdf.php in AuraCMS 1.62 allows remote attackers to execute arbitrary SQL commands via the
23RISK
open
Referência
CVE-2010-4776
SQL injection vulnerability in takefreestart.php in PreProjects Pre Online Tests Generator Pro allows remote attackers t
23RISK
open
Referência
CVE-2010-4776
SQL injection vulnerability in takefreestart.php in PreProjects Pre Online Tests Generator Pro allows remote attackers t
23RISK
open
Referência
CVE-2026-61524
WebsiteBaker CMS < 2.13.10 File Upload RCE via Module Installation
41RISK
open
ReferênciaVexDay Proof
EasyGallery 5.0tr - Multiple Vulnerabilities
CVE-2008-1346webappsphp
SQL injection vulnerability in staticpages/easygallery/index.php in MyioSoft EasyGallery 5.0tr and earlier allows remote
23RISK
open
ReferênciaVexDay Proof
EasyGallery 5.0tr - Multiple Vulnerabilities
CVE-2008-1347webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in staticpages/easygallery/index.php in MyioSoft EasyGallery 5.0tr a
23RISK
open
ReferênciaVexDay Proof
Fully Modded phpBB - 'kb.php' SQL Injection
CVE-2008-1350webappsphp
SQL injection vulnerability in kb.php in Fully Modded phpBB (phpbbfm) 80220 allows remote attackers to execute arbitrary
23RISK
open
Referência
CVE-2019-5736
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open
Referência
CVE-2019-5736
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open
Referência
CVE-2019-5736
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open
ReferênciaVexDay Proof
XOOPS Module tutorials 2.1b - 'printpage.php' SQL Injection
CVE-2008-1351webappsphp
SQL injection vulnerability in the Tutorials 2.1b module for XOOPS allows remote attackers to execute arbitrary SQL comm
23RISK
open
ReferênciaVexDay Proof
KAPhotoservice - 'album.asp' SQL Injection
CVE-2008-1426webappsasp
SQL injection vulnerability in album.asp in KAPhotoservice allows remote attackers to execute arbitrary SQL commands via
23RISK
open
Referência
CVE-2024-0737
Xlightftpd Xlight FTP Server Login denial of service
33RISK
open
previouspage 413 / 743next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.