Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,449cataloged exploits
35,552CVEs with public exploitation
24,695lab-tested
22,367 exploits
Referência
CVE-2026-14745
code-projects Real State Services single-list_rent.php sql injection
33RISK
open
Referência
CVE-2026-14738
exo-explore exo Vision Feature Cache vision.py _image_cache_key weak hash
33RISK
open
Referência
CVE-2026-14737
Hanwang e-Face General Management Platform querySysAuthStr.do sql injection
33RISK
open
ReferênciaVexDay Proof
Mail Machine 3.989 - Local File Inclusion
CVE-2007-3702webappsphp
Directory traversal vulnerability in the load function in cgi-bin/mail/mailmachine.cgi in Mail Machine 3.989 and earlier
23RISK
open
ReferênciaVexDay Proof
HP Digital Imaging 'hpqvwocx.dll 2.1.0.556' - 'SaveToFile()' File Write
CVE-2007-3649remotewindows
Absolute path traversal vulnerability in a certain ActiveX control in hpqvwocx.dll 2.1.0.556 in Hewlett-Packard (HP) Dig
23RISK
open
ReferênciaVexDay Proof
PsNews 1.1 - 'show.php?newspath' Local File Inclusion
CVE-2007-3772webappsphp
Directory traversal vulnerability in news/show.php in PsNews 1.1 allows remote attackers to include and execute arbitrar
23RISK
open
Referência
CVE-2026-58053
Gitea act_runner - Container Hardening Bypass via Workflow Container Options
48RISK
open
Referência
CVE-2026-58052
7-Zip - Mark-of-the-Web Bypass via RAR5 Alternate Data Stream Name Collision
33RISK
open
ReferênciaVexDay Proof
Traffic Stats - 'referralUrl.php?offset' SQL Injection
CVE-2007-3840webappsphp
SQL injection vulnerability in referralUrl.php in Traffic Stats allows remote attackers to execute arbitrary SQL command
23RISK
open
Referência
CVE-2019-25761
Joomla! Component JoomCRM 1.1.1 SQL Injection via deal_id
41RISK
open
Referência
CVE-2017-17637
Car Rental Script 2.0.4 has SQL Injection via the countrycode1.php val parameter.
23RISK
open
ReferênciaVexDay Proof
Pictures Rating - 'index.php?msgid' SQL Injection
CVE-2007-3881webappsphp
SQL injection vulnerability in index.php in Pictures Rating (Picture Rating) allows remote attackers to execute arbitrar
23RISK
open
Referência
CVE-2007-3808
SQL injection vulnerability in includes/search.php in paFileDB 3.6 allows remote attackers to execute arbitrary SQL comm
23RISK
open
Referência
CVE-2017-17637
Car Rental Script 2.0.4 has SQL Injection via the countrycode1.php val parameter.
23RISK
open
ReferênciaVexDay Proof
Data Dynamics ActiveBar - ActiveX 'actbar3.ocx 3.1' Insecure Methods
CVE-2007-3883remotewindows
The Data Dynamics ActiveBar ActiveX control (actbar3.ocx) 3.2 and earlier allows remote attackers to create or overwrite
23RISK
open
Referência
CVE-2017-17638
Groupon Clone Script 3.01 has SQL Injection via the city_ajax.php state_id parameter.
23RISK
open
ReferênciaVexDay Proof
Microsoft DirectX SAMI File Parsing - Remote Stack Overflow
CVE-2007-3901remotewindows
Stack-based buffer overflow in the DirectShow Synchronized Accessible Media Interchange (SAMI) parser in quartz.dll for
50RISK
open
Referência
CVE-2017-17638
Groupon Clone Script 3.01 has SQL Injection via the city_ajax.php state_id parameter.
23RISK
open
ReferênciaVexDay Proof
A-shop 0.70 - Remote File Deletion
CVE-2007-3937webappsasp
Multiple SQL injection vulnerabilities in A-shop 0.70 and earlier allow remote attackers to execute arbitrary SQL comman
23RISK
open
ReferênciaVexDay Proof
LinkedIn Toolbar 3.0.2.1098 - Remote Buffer Overflow
CVE-2007-3955remotewindows
Buffer overflow in the IEToolbar.IEContextMenu.1 ActiveX control in LinkedInIEToolbar.dll in the LinkedIn Toolbar 3.0.2.
23RISK
open
ReferênciaVexDay Proof
Microsoft Windows Explorer - '.GIF' Image Denial of Service
CVE-2007-3958doswindows
Microsoft Windows Explorer (explorer.exe) allows user-assisted remote attackers to cause a denial of service via a certa
28RISK
open
ReferênciaVexDay Proof
PHP 4.4.7/5.2.3 - MySQL/MySQLi 'Safe_Mode' Bypass
CVE-2007-3997localmultiple
The (1) MySQL and (2) MySQLi extensions in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, allow remote attackers to bypass
28RISK
open
Referência
CVE-2017-17721
CWEBNET/WOSummary/List in ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 allows SQL injection via the tradestatus, assetno, ass
23RISK
open
Referência
CVE-2017-17721
CWEBNET/WOSummary/List in ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 allows SQL injection via the tradestatus, assetno, ass
23RISK
open
Referência
CVE-2016-4372
HPE iMC PLAT before 7.2 E0403P04, iMC EAD before 7.2 E0405P05, iMC APM before 7.2 E0401P04, iMC NTA before 7.2 E0401P01,
28RISK
open
Referência
CVE-2017-17737
The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) has XSS via the REF parameter to /network_diag
23RISK
open
Referência
CVE-2017-17738
The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) allows renaming and modifying files via /tools
23RISK
open
Referência
CVE-2017-17752
Ability Mail Server 3.3.2 has Cross Site Scripting (XSS) via the body of an e-mail message, with JavaScript code execute
23RISK
open
Referência
CVE-2017-17849
A buffer overflow vulnerability in GetGo Download Manager 5.3.0.2712 and earlier could allow remote HTTP servers to exec
28RISK
open
Referência
CVE-2017-17849
A buffer overflow vulnerability in GetGo Download Manager 5.3.0.2712 and earlier could allow remote HTTP servers to exec
28RISK
open
previouspage 468 / 746next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.