Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,284cataloged exploits
35,465CVEs with public exploitation
24,695lab-tested
22,266 exploits
ReferênciaVexDay Proof
Photocart 3.9 - Multiple SQL Injections
CVE-2008-3788webappsphp
Multiple SQL injection vulnerabilities in PICTURESPRO Photo Cart 3.9, when magic_quotes_gpc is disabled, allow remote at
23RISK
open
ReferênciaVexDay Proof
D2-Shoutbox 4.2 IPB Mod - 'load' SQL Injection
CVE-2006-1153webappsphp
SQL injection vulnerability in D2-Shoutbox 4.2 allows remote attackers to execute arbitrary SQL commands via the load pa
23RISK
open
Referência
CVE-2017-14087
A Host Header Injection vulnerability in Trend Micro OfficeScan XG (12.0) may allow an attacker to spoof a particular Ho
23RISK
open
Referência
CVE-2017-14087
A Host Header Injection vulnerability in Trend Micro OfficeScan XG (12.0) may allow an attacker to spoof a particular Ho
23RISK
open
Referência
CVE-2010-4872
SQL injection vulnerability in newsroom.asp in ASPilot Pilot Cart 7.3 allows remote attackers to execute arbitrary SQL c
23RISK
open
Referência
CVE-2012-5342
Multiple SQL injection vulnerabilities in SenseSites CommonSense CMS allow remote attackers to execute arbitrary SQL com
23RISK
open
Referência
CVE-2012-1415
Cross-site request forgery (CSRF) vulnerability in lib/logout.php in DFLabs PTK 1.0.5 and earlier allows remote attacker
23RISK
open
Referência
CVE-2012-1203
Cross-site request forgery (CSRF) vulnerability in starnet/index.php in SyndeoCMS 3.0 and earlier allows remote attacker
23RISK
open
Referência
CVE-2022-3915
Dokan < 3.7.6 - Unauthenticated SQLi
48RISK
open
Referência
CVE-2010-2853
SQL injection vulnerability in flashPlayer/playVideo.php in iScripts VisualCaster allows remote attackers to execute arb
23RISK
open
Referência
CVE-2010-2853
SQL injection vulnerability in flashPlayer/playVideo.php in iScripts VisualCaster allows remote attackers to execute arb
23RISK
open
ReferênciaVexDay Proof
Mambo Component MamboWiki 0.9.6 - Remote File Inclusion
CVE-2006-4282webappsphp
PHP remote file inclusion vulnerability in MamboLogin.php in the MamboWiki component (com_mambowiki) 0.9.6 and earlier f
23RISK
open
ReferênciaVexDay Proof
Joomla! Component jooget 2.6.8 - SQL Injection
CVE-2008-0829webappsphp
SQL injection vulnerability in jooget.php in the Joomlapixel Jooget! (com_jooget) 2.6.8 component for Joomla! and Mambo
23RISK
open
ReferênciaVexDay Proof
PHP-Nuke Modules Okul 1.0 - 'okulid' SQL Injection
CVE-2008-0881webappsphp
SQL injection vulnerability in modules.php in the Okul 1.0 module for PHP-Nuke allows remote attackers to execute arbitr
23RISK
open
Referência
CVE-2017-14097
An improper access control vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below coul
28RISK
open
Referência
IOTransfer V4 - Unquoted Service Path
CVE-2022-37197HIGHlocalwindows
IOBit IOTransfer V4 is vulnerable to Unquoted Service Path.
41RISK
open
ReferênciaVexDay Proof
EQdkp 1.3.2f - 'user_id' Authentication Bypass
CVE-2008-2222webappsphp
SQL injection vulnerability in login.php in EQdkp 1.3.2f allows remote attackers to bypass EQdkp user authentication via
23RISK
open
ReferênciaVexDay Proof
Link Bid Script 1.5 - Multiple SQL Injections
CVE-2008-4175webappsphp
Multiple SQL injection vulnerabilities in Link Bid Script 1.5 allow remote attackers to execute arbitrary SQL commands v
23RISK
open
ReferênciaVexDay Proof
FlashGet 1.9.0.1012 - 'FTP PWD Response' SEH Stack Overflow
CVE-2008-4321remotewindows
Buffer overflow in FlashGet (formerly JetCar) FTP 1.9 allows remote FTP servers to execute arbitrary code via a long res
23RISK
open
ReferênciaVexDay Proof
Microsoft Windows Explorer - '.zip' Denial of Service
CVE-2008-4323doswindows
Windows Explorer in Microsoft Windows XP SP3 allows user-assisted attackers to cause a denial of service (application cr
23RISK
open
Referência
CVE-2010-4907
Cross-site scripting (XSS) vulnerability in zp-core/admin.php in Zenphoto 1.3 allows remote attackers to inject arbitrar
23RISK
open
Referência
CVE-2017-14627
Stack-based buffer overflows in CyberLink LabelPrint 2.5 allow remote attackers to execute arbitrary code via the (1) au
43RISK
open
ReferênciaVexDay Proof
TAGWORX.CMS 3.00.02 - Multiple SQL Injections
CVE-2008-2394webappsphp
Multiple SQL injection vulnerabilities in TAGWORX.CMS 3.00.02 allow remote attackers to execute arbitrary SQL commands v
23RISK
open
Referência
CVE-2009-3595
SQL injection vulnerability in results.php in VS PANEL 7.5.5 allows remote attackers to execute arbitrary SQL commands v
23RISK
open
Referência
CVE-2023-23408
Azure Apache Ambari Spoofing Vulnerability
33RISK
open
Referência
CVE-2009-3314
SQL injection vulnerability in ladders.php in Elite Gaming Ladders 3.2 allows remote attackers to execute arbitrary SQL
23RISK
open
Referência
CVE-2017-14627
Stack-based buffer overflows in CyberLink LabelPrint 2.5 allow remote attackers to execute arbitrary code via the (1) au
43RISK
open
Referência
CVE-2010-2910
SQL injection vulnerability in the Ozio Gallery (com_oziogallery) component for Joomla! allows remote attackers to execu
23RISK
open
Referência
CVE-2017-6178
The IofCallDriver function in USBPcap 1.1.0.0 allows local users to gain privileges via a crafted 0x00090028 IOCTL call,
23RISK
open
Referência
CVE-2017-14712
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Phonecall Notes Title parameter.
23RISK
open
previouspage 425 / 743next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.