Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,449cataloged exploits
35,552CVEs with public exploitation
24,695lab-tested
22,367 exploits
ReferênciaVexDay Proof
Vizayn Urun Tanitim Sistemi 0.2 - 'tr' SQL Injection
CVE-2007-2803webappsasp
SQL injection vulnerability in default.asp in Vizayn Urun Tanitim Sitesi 0.2 allows remote attackers to execute arbitrar
23RISK
open
ReferênciaVexDay Proof
Ol BookMarks Manager 0.7.4 - 'root' Remote File Inclusion
CVE-2007-2816webappsphp
Multiple PHP remote file inclusion vulnerabilities in ol'bookmarks 0.7.4 allow remote attackers to execute arbitrary PHP
28RISK
open
Referência
CVE-2017-17598
Affiliate MLM Script 1.0 has SQL Injection via the product-category.php key parameter.
23RISK
open
ReferênciaVexDay Proof
Ol BookMarks Manager 0.7.4 - SQL Injection
CVE-2007-2817webappsphp
SQL injection vulnerability in read/index.php in ol'bookmarks 0.7.4 allows remote attackers to execute arbitrary SQL com
23RISK
open
Referência
CVE-2007-2821
SQL injection vulnerability in wp-admin/admin-ajax.php in WordPress before 2.2 allows remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
TutorialCMS 1.01 - Authentication Bypass
CVE-2007-2822webappsphp
TutorialCMS 1.01 and earlier, when register_globals is enabled, allows remote attackers to bypass authentication via the
23RISK
open
Referência
CVE-2026-14239
Tourmaster < 5.4.8 - Stored XSS via CSRF
41RISK
open
Referência
CVE-2026-13395
Bookly < 27.8 - Unauthenticated SQL Injection via staff_id
41RISK
open
Referência
CVE-2026-13345
Essential Addons for Elementor - Lite < 6.6.10 - Unauthenticated Draft/Private WooCommerce Product Disclosure via Compare Table
33RISK
open
Referência
CVE-2026-13344
Essential Addons for Elementor - Lite < 6.6.10 - Contributor+ Stored XSS via Pricing Table Title Tag
33RISK
open
Referência
CVE-2026-13330
Animation Addons for Elementor < 2.7.0 - Author+ Stored XSS via SVG Upload
33RISK
open
Referência
CVE-2026-13178
Eventin < 4.1.16 - Unauthenticated Payment Bypass via Order Status Manipulation
41RISK
open
Referência
CVE-2026-13145
WP Travel < 11.8.1 - Subscriber+ Booking PII Disclosure via IDOR
33RISK
open
Referência
CVE-2026-13143
WP Travel < 11.8.1 - Unauthenticated Payment Bypass via Forged PayPal IPN
33RISK
open
Referência
CVE-2026-15513
Wavlink WL-NU516U1 adm.cgi wlink_uci_set_value os command injection
33RISK
open
Referência
CVE-2026-15512
pig-mesh Pig pig-codegen GeneratorServiceImpl.java code injection
33RISK
open
Referência
CVE-2026-14778
SourceCodester Onlne Examination & Learning Management System Enrollment Management ajax_enroll.php improper authorization
33RISK
open
ReferênciaVexDay Proof
Pheap 2.0 - Authentication Bypass / Remote Code Execution
CVE-2007-2985webappsphp
Pheap 2.0 allows remote attackers to bypass authentication by setting a pheap_login cookie value to the administrator's
23RISK
open
ReferênciaVexDay Proof
Inout Search Engine - Remote Code Execution
CVE-2007-2988webappsphp
A certain admin script in Inout Meta Search Engine sends a redirect to the web browser but does not exit when administra
23RISK
open
Referência
CVE-2017-17601
Cab Booking Script 1.0 has SQL Injection via the /service-list city parameter.
23RISK
open
Referência
CVE-2017-17601
Cab Booking Script 1.0 has SQL Injection via the /service-list city parameter.
23RISK
open
Referência
CVE-2026-13536
GotoHTTP reg.12x cross site scripting
33RISK
open
Referência
CVE-2026-13535
CodeAstro Human Resource Management System View Endpoint Employee_model.php GetFileInfo sql injection
33RISK
open
ReferênciaVexDay Proof
Acoustica MP3 CD Burner 4.32 - Local Buffer Overflow (PoC)
CVE-2007-3006doswindows
Buffer overflow in Acoustica MP3 CD Burner 4.32 allows user-assisted remote attackers to execute arbitrary code via a .a
23RISK
open
ReferênciaVexDay Proof
Acoustica MP3 CD Burner 4.51 Build 147 - '.asx' Local Buffer Overflow
CVE-2007-3006localwindows
Buffer overflow in Acoustica MP3 CD Burner 4.32 allows user-assisted remote attackers to execute arbitrary code via a .a
23RISK
open
Referência
CVE-2017-17603
Advanced Real Estate Script 4.0.7 has SQL Injection via the search-results.php Projectmain, proj_type, searchtext, sell_
23RISK
open
ReferênciaVexDay Proof
Microsoft Windows Message Queuing Service - RPC Buffer Overflow (MS07-065) (1)
CVE-2007-3039remotewindows
Stack-based buffer overflow in the Microsoft Message Queuing (MSMQ) service in Microsoft Windows 2000 Server SP4, Window
50RISK
open
ReferênciaVexDay Proof
Microsoft Windows Message Queuing Service - RPC Buffer Overflow (MS07-065) (2)
CVE-2007-3039remotewindows
Stack-based buffer overflow in the Microsoft Message Queuing (MSMQ) service in Microsoft Windows 2000 Server SP4, Window
50RISK
open
ReferênciaVexDay Proof
Microsoft Windows Server 2000 SP4 (Advanced Server) - Message Queue (MS07-065)
CVE-2007-3039remotewindows
Stack-based buffer overflow in the Microsoft Message Queuing (MSMQ) service in Microsoft Windows 2000 Server SP4, Window
50RISK
open
ReferênciaVexDay Proof
PNPHPBB2 < 1.2 - 'index.php' SQL Injection
CVE-2007-3052webappsphp
SQL injection vulnerability in index.php in the PNphpBB2 1.2i and earlier module for PostNuke allows remote attackers to
23RISK
open
previouspage 461 / 746next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.