Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,231cataloged exploits
35,420CVEs with public exploitation
24,695lab-tested
22,266 exploits
Referência
CVE-2012-5683
Multiple cross-site request forgery (CSRF) vulnerabilities in ZPanel 10.0.1 and earlier allow remote attackers to hijack
23RISK
open
Referência
CVE-2009-3184
Multiple SQL injection vulnerabilities in index.php in Pirates of The Caribbean in the E-Gold Game Series allow remote a
23RISK
open
Referência
CVE-2013-4945
Multiple SQL injection vulnerabilities in BMC Service Desk Express (SDE) 10.2.1.95 allow remote attackers to execute arb
23RISK
open
Referência
CVE-2022-42064
Online Diagnostic Lab Management System version 1.0 remote exploit that bypasses login with SQL injection and then uploa
48RISK
open
Referência
CVE-2023-4382
tdevs Hyip Rio Profile Settings settings cross site scripting
28RISK
open
Referência
CVE-2016-3984
The McAfee VirusScan Console (mcconsol.exe) in McAfee Active Response (MAR) before 1.1.0.161, Agent (MA) 5.x before 5.0.
23RISK
open
ReferênciaVexDay Proof
e-Vision CMS 2.02 - SQL Injection / Remote Code Execution
CVE-2007-3214webappsphp
SQL injection vulnerability in style.php in e-Vision CMS 2.02 and earlier, when magic_quotes_gpc is disabled, allows rem
23RISK
open
Referência
CVE-2017-12969
Buffer overflow in the ViewerCtrlLib.ViewerCtrl ActiveX control in Avaya IP Office Contact Center before 10.1.1 allows r
28RISK
open
Referência
CVE-2021-35312
A vulnerability was found in CIR 2000 / Gestionale Amica Prodigy v1.7. The Amica Prodigy's executable "RemoteBackup.Serv
23RISK
open
Referência
CVE-2021-35312
A vulnerability was found in CIR 2000 / Gestionale Amica Prodigy v1.7. The Amica Prodigy's executable "RemoteBackup.Serv
23RISK
open
Referência
CVE-2015-5466
Silicon Integrated Systems XGI WindowsXP Display Manager (aka XGI VGA Driver Manager and VGA Display Manager) 6.14.10.10
23RISK
open
ReferênciaVexDay Proof
Myspace Clone Script - SQL Injection
CVE-2007-5992webappsphp
SQL injection vulnerability in index.php in datecomm Social Networking Script (aka Myspace Clone Script) allows remote a
23RISK
open
Referência
CVE-2024-7815
CodeAstro Online Railway Reservation System Update Employee Page admin-update-employee.php cross site scripting
33RISK
open
ReferênciaVexDay Proof
icblogger 2.0 - 'YID' SQL Injection
CVE-2006-4597webappsasp
SQL injection vulnerability in devam.asp in ICBlogger 2.0 and earlier allows remote attackers to execute arbitrary SQL c
23RISK
open
Referência
CVE-2010-2709
Stack-based buffer overflow in webappmon.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote at
50RISK
open
Referência
CVE-2017-1297
IBM DB2 for Linux, UNIX and Windows 9.2, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) is vulnerable to a stack-bas
23RISK
open
ReferênciaVexDay Proof
ProActive CMS - 'template' Local File Inclusion
CVE-2008-4187webappsphp
Directory traversal vulnerability in index.php in ProActive CMS allows remote attackers to read arbitrary files via a ..
23RISK
open
ReferênciaVexDay Proof
FreeWebShop.org script 2.2.2 - Multiple Vulnerabilities
CVE-2006-5772webappsphp
Multiple SQL injection vulnerabilities in index.php in FreeWebshop 2.2.1 and earlier allow remote attackers to execute a
23RISK
open
ReferênciaVexDay Proof
Joomla! Component RD-Autos 1.5.5 - SQL Injection
CVE-2009-0420webappsphp
SQL injection vulnerability in the RD-Autos (com_rdautos) 1.5.5 Stable component for Joomla! allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
PHPMesFilms 1.0 - 'index.php?id' SQL Injection
CVE-2009-0598webappsphp
SQL injection vulnerability in index.php in PhpMesFilms 1.0 and 1.8 allows remote attackers to execute arbitrary SQL com
23RISK
open
ReferênciaVexDay Proof
vidshare pro - SQL Injection / Cross-Site Scripting
CVE-2009-1734webappsphp
SQL injection vulnerability in listing_video.php in VidSharePro allows remote attackers to execute arbitrary SQL command
23RISK
open
Referência
CVE-2010-5287
SQL injection vulnerability in default.php in Cornerstone Technologies webConductor allows remote attackers to execute a
23RISK
open
Referência
CVE-2010-5287
SQL injection vulnerability in default.php in Cornerstone Technologies webConductor allows remote attackers to execute a
23RISK
open
Referência
CVE-2012-5291
SQL injection vulnerability in team.php in Posse Softball Director CMS allows remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
BP Blog 7.0 - 'layout' SQL Injection
CVE-2007-1445webappsasp
SQL injection vulnerability in the heme preview feature for default.asp in BP Blog 7.0 through 7.0.2 allows remote attac
23RISK
open
Referência
CVE-2015-0179
Notes System Diagnostic (NSD) in IBM Domino 8.5.x before 8.5.3 FP6 IF6 and 9.x before 9.0.1 FP3 IF1 allows local users t
23RISK
open
ReferênciaVexDay Proof
Prozilla Hosting Index - 'cat_id' SQL Injection
CVE-2008-2083webappsphp
SQL injection vulnerability in directory.php in Prozilla Hosting Index, when magic_quotes_gpc is disabled, allows remote
23RISK
open
ReferênciaVexDay Proof
Openswan 2.4.12/2.6.16 - Insecure Temp File Creation Privilege Escalation
CVE-2008-4190locallinux
The IPSEC livetest tool in Openswan 2.4.12 and earlier, and 2.6.x through 2.6.16, allows local users to overwrite arbitr
23RISK
open
Referência
CVE-2008-4897
SQL injection vulnerability in fichiers/add_url.php in Logz podcast CMS 1.3.1, when magic_quotes_gpc is disabled, allows
23RISK
open
Referência
CVE-2010-4784
Multiple SQL injection vulnerabilities in member.php in PHP Web Scripts Easy Banner Free 2009.05.18, when magic_quotes_g
23RISK
open
previouspage 420 / 743next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.