Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,449cataloged exploits
35,552CVEs with public exploitation
24,695lab-tested
22,367 exploits
Referência
CVE-2017-14840
TeamWork TicketPlus allows Arbitrary File Upload in updateProfile.
23RISK
open
Referência
CVE-2017-14841
Mojoomla Annual Maintenance Contract (AMC) Management System allows Arbitrary File Upload in profilesetting image handli
23RISK
open
Referência
CVE-2006-1652
Multiple buffer overflows in (a) UltraVNC (aka Ultr@VNC) 1.0.1 and earlier and (b) tabbed_viewer 1.29 (1) allow user-ass
50RISK
open
Referência
CVE-2006-1652
Multiple buffer overflows in (a) UltraVNC (aka Ultr@VNC) 1.0.1 and earlier and (b) tabbed_viewer 1.29 (1) allow user-ass
50RISK
open
Referência
CVE-2017-14843
Mojoomla School Management System for WordPress allows SQL Injection via the id parameter.
23RISK
open
Referência
CVE-2017-14844
Mojoomla WPGYM WordPress Gym Management System allows SQL Injection via the id parameter.
23RISK
open
ReferênciaVexDay Proof
SQuery 4.5 - 'libpath' Remote File Inclusion
CVE-2006-1610webappsphp
PHP remote file inclusion vulnerability in lib/armygame.php in SQuery 4.5 and earlier, as used in products such as Auton
23RISK
open
Referência
CVE-2021-36260
CVE-2021-36260CRITICALunder attack
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISK
open
Referência
CVE-2015-4681
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows local users to have unspecified impact via vectors re
23RISK
open
Referência
CVE-2015-4681
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows local users to have unspecified impact via vectors re
23RISK
open
Referência
CVE-2018-25379
Collectric CMU 1.0 SQL Injection via lang Parameter
41RISK
open
Referência
CVE-2026-9435
Totolink A8000RU Web Management cstecgi.cgi setQosCfg os command injection
48RISK
open
Referência
CVE-2026-9417
code-projects Employee Management System myprofileup.php cross site scripting
33RISK
open
ReferênciaVexDay Proof
mxBB Module mx_tinies 1.3.0 - Remote File Inclusion
CVE-2006-6295webappsphp
PHP remote file inclusion vulnerability in includes/mx_common.php in the mx_tinies 1.3.0 Module for MxBB Portal 1.06 all
23RISK
open
Referência
CVE-2017-14845
Mojoomla WPCHURCH Church Management System for WordPress allows SQL Injection via the id parameter.
23RISK
open
ReferênciaVexDay Proof
Microsoft Windows - spoolss GetPrinterData() Remote Denial of Service
CVE-2006-6296doswindows
The RpcGetPrinterData function in the Print Spooler (spoolsv.exe) service in Microsoft Windows 2000 SP4 and earlier, and
28RISK
open
ReferênciaVexDay Proof
torrentflux 2.2 - Arbitrary File Create/ Execute/Delete
CVE-2006-6328webappsphp
Directory traversal vulnerability in index.php for TorrentFlux 2.2 allows remote attackers to create or overwrite arbitr
23RISK
open
ReferênciaVexDay Proof
torrentflux 2.2 - Arbitrary File Create/ Execute/Delete
CVE-2006-6329webappsphp
index.php for TorrentFlux 2.2 allows remote attackers to delete files by specifying the target filename in the delfile p
23RISK
open
Referência
CVE-2017-14846
Mojoomla Hospital Management System for WordPress allows SQL Injection via the id parameter.
23RISK
open
ReferênciaVexDay Proof
torrentflux 2.2 - Arbitrary File Create/ Execute/Delete
CVE-2006-6330webappsphp
index.php for TorrentFlux 2.2 allows remote registered users to execute arbitrary commands via shell metacharacters in t
23RISK
open
Referência
CVE-2017-14847
Mojoomla WPAMS Apartment Management System for WordPress allows SQL Injection via the id parameter.
23RISK
open
Referência
CVE-2017-14955
Check_MK before 1.2.8p26 mishandles certain errors within the failed-login save feature because of a race condition, whi
28RISK
open
ReferênciaVexDay Proof
The Classified Ad System 1.0 - 'main' SQL Injection
CVE-2006-6349webappsasp
Multiple SQL injection vulnerabilities in PWP Technologies The Classified Ad System allow remote attackers to execute ar
23RISK
open
ReferênciaVexDay Proof
F-Prot AntiVirus 4.6.6 - 'ACE' Denial of Service
CVE-2006-6352doslinux
FRISK Software F-Prot Antivirus before 4.6.7 allows user-assisted remote attackers to cause a denial of service (infinit
23RISK
open
ReferênciaVexDay Proof
awrate.com Message Board 1.0 - 'search.php' Remote File Inclusion
CVE-2006-6368webappsphp
PHP remote file inclusion vulnerability in login.php.inc in awrate 1.0 allows remote attackers to execute arbitrary PHP
23RISK
open
ReferênciaVexDay Proof
Ultimate HelpDesk - Cross-Site Scripting / Local File Disclosure
CVE-2006-6380webappsasp
Cross-site scripting (XSS) vulnerability in index.asp in Ultimate HelpDesk allows remote attackers to inject arbitrary w
23RISK
open
ReferênciaVexDay Proof
HR Assist 1.05 - 'vdateUsr.asp' Remote Authentication Bypass
CVE-2006-6524webappsasp
SQL injection vulnerability in vdateUsr.asp in EzHRS HR Assist 1.05 and earlier allows remote attackers to execute arbit
23RISK
open
ReferênciaVexDay Proof
SpotLight CRM 1.0 - 'login.asp' SQL Injection
CVE-2006-6543webappsasp
Multiple SQL injection vulnerabilities in login.asp in AppIntellect SpotLight CRM 1.0 allow remote attackers to execute
23RISK
open
Referência
CVE-2017-15081
In PHPSUGAR PHP Melody CMS 2.6.1, SQL Injection exists via the playlist parameter to playlists.php.
23RISK
open
ReferênciaVexDay Proof
mxBB Module ErrorDocs 1.0 - 'common.php' Remote File Inclusion
CVE-2006-6545webappsphp
PHP remote file inclusion vulnerability in includes/common.php in the ErrorDocs 1.0.0 and earlier module for mxBB (mx_er
23RISK
open
previouspage 467 / 746next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.