Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,449cataloged exploits
35,552CVEs with public exploitation
24,695lab-tested
22,367 exploits
ReferênciaVexDay Proof
JMweb - 'src' Local File Inclusion
CVE-2008-4522webappsphp
Multiple directory traversal vulnerabilities in JMweb MP3 Music Audio Search and Download Script allow remote attackers
23RISK
open
Referência
CVE-2017-17098
The writeLog function in fn_common.php in gps-server.net GPS Tracking Software (self hosted) through 3.0 allows remote a
23RISK
open
Referência
CVE-2010-3267
Multiple SQL injection vulnerabilities in BugTracker.NET before 3.4.5 allow remote authenticated users to execute arbitr
23RISK
open
Referência
CVE-2016-2184
The create_fixed_stream_quirk function in sound/usb/quirks.c in the snd-usb-audio driver in the Linux kernel before 4.5.
23RISK
open
Referência
CVE-2010-4970
SQL injection vulnerability in handlers/getpage.php in Wiki Web Help 0.28 allows remote attackers to execute arbitrary S
23RISK
open
Referência
CVE-2010-3275
libdirectx_plugin.dll in VideoLAN VLC Media Player before 1.1.8 allows remote attackers to execute arbitrary code via a
60RISK
open
ReferênciaVexDay Proof
NewsLetter 3.5 - 'NL_PATH' Remote File Inclusion
CVE-2006-3986webappsphp
PHP remote file inclusion vulnerability in index.php in Knusperleicht Newsletter 3.5 and earlier allows remote attackers
23RISK
open
Referência
CVE-2026-48558
SimpleHelp Authentication Bypass via Missing OIDC JWT Signature Verification
53RISK
open
ReferênciaVexDay Proof
k_fileManager 1.2 - 'dwl_include_path' Remote File Inclusion
CVE-2006-3987webappsphp
Multiple PHP remote file inclusion vulnerabilities in index.php in Knusperleicht FileManager 1.2 and earlier allow remot
23RISK
open
ReferênciaVexDay Proof
Joomla! Component actualite 1.0 - 'id' SQL Injection
CVE-2008-4617webappsphp
SQL injection vulnerability in the actualite module 1.0 for Joomla! allows remote attackers to execute arbitrary SQL com
23RISK
open
ReferênciaVexDay Proof
newsReporter 1.1 - 'index.php' Remote File Inclusion
CVE-2006-3988webappsphp
PHP remote file inclusion vulnerability in index.php in Knusperleicht newsReporter 1.1 and earlier allows remote attacke
23RISK
open
Referência
CVE-2026-6552
ReferênciaVexDay Proof
Meeting Room Booking System (MRBS) < 1.4 - SQL Injection
CVE-2008-4620webappsphp
SQL injection vulnerability in Meeting Room Booking System (MRBS) before 1.4 allows remote attackers to execute arbitrar
23RISK
open
ReferênciaVexDay Proof
Joomla! Component ds-syndicate - 'feed_id' SQL Injection
CVE-2008-4623webappsphp
SQL injection vulnerability in the DS-Syndicate (com_ds-syndicate) component 1.1.1 for Joomla allows remote attackers to
23RISK
open
Referência
CVE-2026-7713
crocodilestick Calibre-Web-Automated Kobo auth-token Route kobo_auth.py generate_auth_token improper authorization
33RISK
open
ReferênciaVexDay Proof
XOOPS Module makale 0.26 - SQL Injection
CVE-2008-4653webappsphp
SQL injection vulnerability in makale.php in Makale 0.26 and possibly other versions, a module for XOOPS, allows remote
23RISK
open
Referência
CVE-2017-17575
FS Groupon Clone 1.0 has SQL Injection via the item_details.php id parameter or the vendor_details.php id parameter.
23RISK
open
Referência
CVE-2026-12823
Browserbase Skills Autobrowse Trace Artifact default permission
33RISK
open
Referência
CVE-2017-20261
Joomla! Component Bargain Product VM3 1.0 SQL Injection
41RISK
open
Referência
CVE-2017-20260
Joomla! Component Price Alert 3.0.2 SQL Injection
41RISK
open
Referência
CVE-2017-20259
Joomla OSDownloads 1.7.4 SQL Injection via item view
41RISK
open
Referência
CVE-2017-20258
Joomla! Component RPC Responsive Portfolio 1.6.1 SQL Injection
41RISK
open
Referência
CVE-2026-8981
Lazy Blocks < 4.3.0 - Admin+ Stored XSS via Custom Block Frontend HTML
28RISK
open
Referência
CVE-2016-2386
CVE-2016-2386CRITICALunder attack
SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbi
100RISK
open
Referência
CVE-2016-2386
CVE-2016-2386CRITICALunder attack
SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbi
100RISK
open
Referência
CVE-2026-11585
CodeAstro Student Attendance Management System createClassArms.php sql injection
33RISK
open
Referência
CVE-2016-2386
CVE-2016-2386CRITICALunder attack
SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbi
100RISK
open
ReferênciaVexDay Proof
Top Auction 1.0 - 'viewcat.php' SQL Injection
CVE-2005-3952webappsphp
SQL injection vulnerability in PHP Labs Top Auction allows remote attackers to execute arbitrary SQL commands via the (1
23RISK
open
ReferênciaVexDay Proof
Libera CMS 1.12 - 'cookie' SQL Injection
CVE-2008-4700webappsphp
SQL injection vulnerability in admin.php in Libera CMS 1.12 and earlier, when magic_quotes_gpc is disabled, allows remot
23RISK
open
Referência
CVE-2026-8777
Edimax BR-6428NS POST Request formStaDrvSetup command injection
33RISK
open
previouspage 456 / 746next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.