Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,302cataloged exploits
35,469CVEs with public exploitation
24,695lab-tested
22,301 exploits
Referência
CVE-2010-4946
SQL injection vulnerability in product_info.php in ALLPC 2.5 allows remote attackers to execute arbitrary SQL commands v
23RISK
open
ReferênciaVexDay Proof
Pre Podcast Portal - SQL Injection
CVE-2008-6230webappsphp
SQL injection vulnerability in Tour.php in Pre Projects Pre Podcast Portal allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
RakhiSoftware Shopping Cart - SQL Injection
CVE-2008-6277webappsphp
SQL injection vulnerability in product.php in RakhiSoftware Price Comparison Script (aka Shopping Cart) allows remote at
23RISK
open
Referência
CVE-2010-4947
Cross-site scripting (XSS) vulnerability in advanced_search_result.php in ALLPC 2.5 allows remote attackers to inject ar
23RISK
open
Referência
CVE-2010-4948
PHP remote file inclusion vulnerability in libs/adodb/adodb.inc.php in PHP Free Photo Gallery script allows remote attac
23RISK
open
ReferênciaVexDay Proof
PHP TV Portal 2.0 - 'mid' SQL Injection
CVE-2008-6285webappsphp
SQL injection vulnerability in index.php in PHP TV Portal 2.0 and earlier allows remote attackers to execute arbitrary S
23RISK
open
Referência
CVE-2010-3150
Untrusted search path vulnerability in Adobe Premier Pro CS4 4.0.0 (314 (MC: 160820)) allows local users, and possibly r
28RISK
open
Referência
CVE-2026-9570
Taskbuilder < 5.0.8 - Reflected XSS via Shortcode
41RISK
open
ReferênciaVexDay Proof
Vastal I-Tech MMORPG Zone - 'game_id' SQL Injection
CVE-2008-4460webappsphp
SQL injection vulnerability in game.php in Vastal I-Tech MMORPG Zone allows remote attackers to execute arbitrary SQL co
23RISK
open
Referência
CVE-2010-3151
Untrusted search path vulnerability in Adobe On Location CS4 Build 315 allows local users, and possibly remote attackers
28RISK
open
Referência
CVE-2017-15992
Website Broker Script allows SQL Injection via the 'status_id' Parameter to status_list.php.
23RISK
open
Referência
CVE-2026-50656
Microsoft Defender Elevation of Privilege Vulnerability
46RISK
open
ReferênciaVexDay Proof
Vastal I-Tech Dating Zone - 'fage' SQL Injection
CVE-2008-4461webappsphp
SQL injection vulnerability in advanced_search_results.php in Vastal I-Tech Dating Zone, possibly 0.9.9, allows remote a
23RISK
open
ReferênciaVexDay Proof
Web3news 0.95 - 'PHPSECURITYADMIN_PATH' Remote File Inclusion
CVE-2006-4452webappsphp
PHP remote file inclusion vulnerability in security/include/_class.security.php in Web3news 0.95 and earlier, when regis
23RISK
open
ReferênciaVexDay Proof
Vastal I-Tech Visa Zone - 'news_id' SQL Injection
CVE-2008-4462webappsphp
SQL injection vulnerability in view_news.php in Vastal I-Tech Visa Zone allows remote attackers to execute arbitrary SQL
23RISK
open
Referência
CVE-2017-15993
Zomato Clone Script allows SQL Injection via the restaurant-menu.php resid parameter.
23RISK
open
Referência
CVE-2017-16001
In HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.1, a local attacker or malware can silently su
23RISK
open
Referência
CVE-2017-16237
In Vir.IT eXplorer Anti-Virus before 8.5.42, the driver file (VIAGLT64.SYS) contains an Arbitrary Write vulnerability be
23RISK
open
Referência
CVE-2017-16244
Cross-Site Request Forgery exists in OctoberCMS 1.0.426 (aka Build 426) due to improper validation of CSRF tokens for po
23RISK
open
Referência
CVE-2026-7785
A-G-U-P-T-A wireshark-mcp pyshark_mcp.py quick_capture os command injection
33RISK
open
Referência
CVE-2026-7784
RTGS2017 NagaAgent Skills Endpoint extensions.py path traversal
33RISK
open
Referência
CVE-2026-7783
CodeCanyon Perfex CRM Admin Kanban Endpoint AbstractKanban.php applySortQuery sql injection
33RISK
open
Referência
CVE-2026-7782
CodeCanyon Perfex CRM Tenant Clients.php project authorization
33RISK
open
Referência
CVE-2026-7781
Open5GS amf-3gpp-access Endpoint nudm-handler.c udm_nudm_uecm_handle_amf_registration_update denial of service
33RISK
open
ReferênciaVexDay Proof
GuildFTPd 0.999.8.11/0.999.14 - Heap Corruption (PoC) / Denial of Service
CVE-2008-4572doswindows
GuildFTPd 0.999.14, and possibly other versions, allows remote attackers to cause a denial of service (crash) and possib
50RISK
open
ReferênciaVexDay Proof
MunzurSoft Wep Portal W3 - 'kat' SQL Injection
CVE-2008-4573webappsasp
SQL injection vulnerability in kategori.asp in MunzurSoft Wep Portal W3 allows remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
Ayco Okul Portali - 'linkid' SQL Injection
CVE-2008-4574webappsasp
SQL injection vulnerability in default.asp in Ayco Okul Portali allows remote attackers to execute arbitrary SQL command
23RISK
open
ReferênciaVexDay Proof
Chilkat FTP ActiveX 2.0 - 'ChilkatCert.dll' Insecure Method
CVE-2008-4583remotewindows
Insecure method vulnerability in the Chilkat FTP 2.0 ActiveX component (ChilkatCert.dll) allows remote attackers to over
23RISK
open
Referência
CVE-2010-3210
Multiple PHP remote file inclusion vulnerabilities in Multi-lingual E-Commerce System 0.2 allow remote attackers to exec
23RISK
open
Referência
CVE-2010-3211
Multiple SQL injection vulnerabilities in the JE FAQ Pro (com_jefaqpro) component 1.5.0 for Joomla! allow remote attacke
23RISK
open
previouspage 436 / 744next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.