Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,302cataloged exploits
35,469CVEs with public exploitation
24,695lab-tested
22,301 exploits
Referência
CVE-2026-7233
Artifex MuPDF CFF Index subset-cff.c fz_subset_cff_for_gids out-of-bounds
33RISK
open
Referência
CVE-2010-3765
CVE-2010-3765CRITICALunder attack
Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, a
100RISK
open
Referência
CVE-2010-5000
SQL injection vulnerability in login/login_index.php in MCLogin System 1.1 and 1.2 allows remote attackers to execute ar
23RISK
open
Referência
CVE-2010-3765
CVE-2010-3765CRITICALunder attack
Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, a
100RISK
open
Referência
CVE-2010-3765
CVE-2010-3765CRITICALunder attack
Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, a
100RISK
open
ReferênciaVexDay Proof
Joomla! Component Volunteer 2.0 - SQL Injection
CVE-2008-6337webappsphp
SQL injection vulnerability in the Volunteer Management System (com_volunteer) module 2.0 for Joomla! allows remote atta
23RISK
open
ReferênciaVexDay Proof
SolarCMS 0.53.8 - 'Forum' Remote Cookies Disclosure
CVE-2008-6345webappsphp
SQL injection vulnerability in Forum.php in SolarCMS 0.53.8 and 1.0 allows remote attackers to execute arbitrary SQL com
23RISK
open
ReferênciaVexDay Proof
DevelopItEasy Photo Gallery 1.2 - SQL Injection
CVE-2008-6348webappsphp
Multiple SQL injection vulnerabilities in DevelopItEasy Photo Gallery 1.2 allow remote attackers to execute arbitrary SQ
23RISK
open
ReferênciaVexDay Proof
TurnkeyForms Business Survey Pro 1.0 - 'id' SQL Injection
CVE-2008-6349webappsphp
SQL injection vulnerability in survey_results_text.php in TurnkeyForms Business Survey Pro 1.0 allows remote attackers t
23RISK
open
ReferênciaVexDay Proof
TurnkeyForms Local Classifieds - Cross-Site Scripting / SQL Injection
CVE-2008-6350webappsphp
SQL injection vulnerability in listtest.php in TurnkeyForms Local Classifieds allows remote attackers to execute arbitra
23RISK
open
ReferênciaVexDay Proof
TurnkeyForms Local Classifieds - Cross-Site Scripting / SQL Injection
CVE-2008-6351webappsphp
Cross-site scripting (XSS) vulnerability in listtest.php in TurnkeyForms Local Classifieds allows remote attackers to in
23RISK
open
ReferênciaVexDay Proof
Xpoze 4.10 - 'menu' Blind SQL Injection
CVE-2008-6352webappsphp
SQL injection vulnerability in home.html in Xpoze Pro 4.10 allows remote attackers to execute arbitrary SQL commands via
23RISK
open
Referência
CVE-2020-37226
Joomla J2 JOBS 1.3.0 Authenticated SQL Injection via sortby
41RISK
open
ReferênciaVexDay Proof
ASP-CMS 1.0 - 'cha' SQL Injection
CVE-2008-6353webappsasp
SQL injection vulnerability in index.asp in ASP-CMS 1.0 allows remote attackers to execute arbitrary SQL commands via th
23RISK
open
ReferênciaVexDay Proof
The Net Guys ASPired2Protect - Database Disclosure
CVE-2008-6355webappsasp
The Net Guys ASPired2Protect stores sensitive information under the web root with insufficient access control, which all
23RISK
open
ReferênciaVexDay Proof
evCal Events Calendar - Database Disclosure
CVE-2008-6356webappsasp
evCal Events Calendar stores sensitive information under the web root with insufficient access control, which allows rem
23RISK
open
Referência
CVE-2026-7221
TencentCloudBase CloudBase-MCP open-url API Endpoint interactive-server.ts openUrl server-side request forgery
33RISK
open
Referência
CVE-2026-7220
jackwrichards FastlyMCP fastly_cli Tool fastly-mcp.mjs os command injection
33RISK
open
Referência
CVE-2026-7217
Deepractice PromptX Document File index.ts read_pdf absolute path traversal
33RISK
open
ReferênciaVexDay Proof
6rbScript 3.3 - 'section.php' Local File Inclusion
CVE-2008-6453webappsphp
Directory traversal vulnerability in section.php in 6rbScript 3.3, when magic_quotes_gpc is disabled, allows remote atta
23RISK
open
ReferênciaVexDay Proof
6rbScript 3.3 - 'singerid' SQL Injection
CVE-2008-6454webappsphp
SQL injection vulnerability in section.php in 6rbScript 3.3 allows remote attackers to execute arbitrary SQL commands vi
23RISK
open
ReferênciaVexDay Proof
e107 Plugin Image Gallery 0.9.6.2 - SQL Injection
CVE-2008-6466webappsphp
SQL injection vulnerability in image_gallery.php in the Akira Powered Image Gallery (image_gallery) plugin 0.9.6.2 for e
23RISK
open
ReferênciaVexDay Proof
Diesel Job Site - 'job_id' Blind SQL Injection
CVE-2008-6467webappsphp
SQL injection vulnerability in jobs/jobseekers/job-info.php in Diesel Job Site allows remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
Diesel Pay Script - 'area' SQL Injection
CVE-2008-6468webappsphp
SQL injection vulnerability in index.php in Diesel Pay allows remote attackers to execute arbitrary SQL commands via the
23RISK
open
Referência
CVE-2026-8321
inkeep agents runAuth Middleware runAuth.ts createDevContext authentication bypass
33RISK
open
ReferênciaVexDay Proof
Plaincart 1.1.2 - 'p' SQL Injection
CVE-2008-6469webappsphp
SQL injection vulnerability in index.php in PlainCart 1.1.2 allows remote attackers to execute arbitrary SQL commands vi
23RISK
open
Referência
CVE-2026-7067
D-Link DIR-822 udhcpd DHCP Service dhcpd.c system command injection
33RISK
open
Referência
CVE-2026-7066
choieastsea simple-openstack-mcp server.py exec_openstack os command injection
33RISK
open
Referência
CVE-2026-7065
BidingCC BuildingAI Remote Upload API file-storage.service.ts uploadRemoteFile server-side request forgery
33RISK
open
Referência
CVE-2026-7064
AgentDeskAI browser-tools-mcp browser-connector.ts os command injection
33RISK
open
previouspage 441 / 744next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.