Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,449cataloged exploits
35,552CVEs with public exploitation
24,695lab-tested
22,301 exploits
Referência
CVE-2010-1496
SQL injection vulnerability in the JoltCard (com_joltcard) component 1.2.1 for Joomla! allows remote attackers to execut
23RISK
open
Referência
CVE-2010-1496
SQL injection vulnerability in the JoltCard (com_joltcard) component 1.2.1 for Joomla! allows remote attackers to execut
23RISK
open
Referência
CVE-2024-10758
code-projects/anirbandutta9 Content Management System/News-Buzz index.php sql injection
33RISK
open
Referência
CVE-2008-3774
SQL injection vulnerability in index.php in Simasy CMS allows remote attackers to execute arbitrary SQL commands via the
23RISK
open
Referência
CVE-2017-1000370
The offset2lib patch as used in the Linux Kernel contains a vulnerability that allows a PIE binary to be execve()'ed wit
23RISK
open
ReferênciaVexDay Proof
Venalsur on-line Booking Centre - Cross-Site Scripting / SQL Injection
CVE-2008-6216webappsphp
SQL injection vulnerability in cadena_ofertas_ext.php in Venalsur Booking Centre Booking System for Hotels Group allows
23RISK
open
ReferênciaVexDay Proof
VP-ASP 6.00 - 'shopcurrency.asp' SQL Injection
CVE-2006-2263webappsasp
SQL injection vulnerability in shopcurrency.asp in VP-ASP 6.00 allows remote attackers to execute arbitrary SQL commands
23RISK
open
Referência
CVE-2012-2585
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine ServiceDesk Plus 8.1 allow remote attackers to injec
23RISK
open
Referência
CVE-2011-5185
Cross-site scripting (XSS) vulnerability in video_comments.php in Online Subtitles Workshop before 2.0 rev 131 allows re
23RISK
open
Referência
CVE-2015-7892
Stack-based buffer overflow in the m2m1shot_compat_ioctl32 function in the Samsung m2m1shot driver framework, as used in
23RISK
open
Referência
CVE-2015-7892
Stack-based buffer overflow in the m2m1shot_compat_ioctl32 function in the Samsung m2m1shot driver framework, as used in
23RISK
open
Referência
CVE-2026-8260
D-Link DCS-935L HNAP Service hnap_service SetDeviceSettings buffer overflow
41RISK
open
Referência
CVE-2014-8347
An Authentication Bypass vulnerability exists in the MatchPasswordData function in DBEngine.dll in Filemaker Pro 13.03 a
23RISK
open
Referência
CVE-2014-8347
An Authentication Bypass vulnerability exists in the MatchPasswordData function in DBEngine.dll in Filemaker Pro 13.03 a
23RISK
open
ReferênciaVexDay Proof
skyportal vrc6 - Multiple Vulnerabilities
CVE-2007-6078webappsphp
Multiple SQL injection vulnerabilities in SkyPortal RC6 allow remote attackers to execute arbitrary SQL commands via uns
23RISK
open
Referência
CVE-2015-6810
Cross-site scripting (XSS) vulnerability in Invision Power Services IPS Community Suite (aka Invision Power Board, IPB,
23RISK
open
Referência302
Android kernel exploit for CVE-2025-38352, previously exploited in-the-wild. Targets vulnerable x86_64 Linux kernels v5.10.x.
CVE-2025-38352HIGHunder attack
posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()
71RISK
open
Referência
CVE-2013-10055
Havalite CMS Arbitary File Upload RCE
63RISK
open
Referência
CVE-2013-10055
Havalite CMS Arbitary File Upload RCE
63RISK
open
ReferênciaVexDay Proof
Ipswitch WS_FTP Home/Professional FTP Client - Remote Format String (PoC)
CVE-2008-3795doswindows
Buffer overflow in Ipswitch WS_FTP Home client allows remote FTP servers to have an unknown impact via a long "message r
28RISK
open
Referência
CVE-2017-1000408
A memory leak in glibc 2.1.1 (released on May 24, 1999) can be reached and amplified through the LD_HWCAP_MASK environme
23RISK
open
ReferênciaVexDay Proof
Lansuite 2.1.0 Beta - 'fid' SQL Injection
CVE-2006-1001webappsphp
SQL injection vulnerability in the board module in LanSuite LanParty Intranet System 2.0.6 and 2.1.0 beta allows remote
23RISK
open
Referência
CVE-2010-4142
Multiple stack-based buffer overflows in DATAC RealWin 2.0 Build 6.1.8.10 and earlier allow remote attackers to cause a
50RISK
open
Referência
CVE-2011-5160
Cross-site scripting (XSS) vulnerability in setup.php in OpenEMR 4 allows remote attackers to inject arbitrary web scrip
23RISK
open
ReferênciaVexDay Proof
Anserv Auction XL - 'cat' SQL Injection
CVE-2008-2189webappsphp
SQL injection vulnerability in viewfaqs.php in AnServ Auction XL allows remote attackers to execute arbitrary SQL comman
23RISK
open
Referência
CVE-2014-3246
SQL injection vulnerability in Collabtive 1.2 allows remote authenticated users to execute arbitrary SQL commands via th
23RISK
open
Referência
CVE-2024-8580
TOTOLINK AC1200 T8 shadow.sample hard-coded password
48RISK
open
Referência
CVE-2016-2288
Cogent DataHub before 7.3.10 allows local users to gain privileges by leveraging the user or guest role to modify a file
23RISK
open
Referência
CVE-2014-100011
SQL injection vulnerability in /send-to in Sendy 1.1.9.1 allows remote attackers to execute arbitrary SQL commands via t
23RISK
open
ReferênciaVexDay Proof
iManage CMS 4.0.12 - 'absolute_path' Remote File Inclusion
CVE-2006-3771webappsphp
Multiple PHP remote file inclusion vulnerabilities in component.php in iManage CMS 4.0.12 and earlier allow remote attac
28RISK
open
previouspage 450 / 744next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.