Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,453cataloged exploits
35,554CVEs with public exploitation
24,695lab-tested
22,367 exploits
ReferênciaVexDay Proof
Limbo CMS 1.0.4.2 - 'catid' SQL Injection
CVE-2006-2363webappsphp
SQL injection vulnerability in the weblinks option (weblinks.html.php) in Limbo CMS allows remote attackers to execute a
23RISK
open
Referência
CVE-2017-17604
Entrepreneur Bus Booking Script 3.0.4 has SQL Injection via the booker_details.php sourcebus parameter.
23RISK
open
Referência
CVE-2017-17604
Entrepreneur Bus Booking Script 3.0.4 has SQL Injection via the booker_details.php sourcebus parameter.
23RISK
open
Referência
CVE-2017-17605
Consumer Complaints Clone Script 1.0 has SQL Injection via the other-user-profile.php id parameter.
23RISK
open
Referência
CVE-2017-17605
Consumer Complaints Clone Script 1.0 has SQL Injection via the other-user-profile.php id parameter.
23RISK
open
Referência
CVE-2017-17606
Co-work Space Search Script 1.0 has SQL Injection via the /list city parameter.
23RISK
open
Referência
CVE-2017-17606
Co-work Space Search Script 1.0 has SQL Injection via the /list city parameter.
23RISK
open
Referência
CVE-2017-17608
Child Care Script 1.0 has SQL Injection via the /list city parameter.
23RISK
open
Referência
CVE-2017-17608
Child Care Script 1.0 has SQL Injection via the /list city parameter.
23RISK
open
Referência
CVE-2017-17609
Chartered Accountant Booking Script 1.0 has SQL Injection via the /service-list city parameter.
23RISK
open
Referência
CVE-2017-17609
Chartered Accountant Booking Script 1.0 has SQL Injection via the /service-list city parameter.
23RISK
open
Referência
CVE-2017-17610
E-commerce MLM Software 1.0 has SQL Injection via the service_detail.php pid parameter, event_detail.php eventid paramet
23RISK
open
Referência
CVE-2017-17610
E-commerce MLM Software 1.0 has SQL Injection via the service_detail.php pid parameter, event_detail.php eventid paramet
23RISK
open
Referência
CVE-2006-2315
PHP remote file inclusion vulnerability in session.inc.php in ISPConfig 2.2.2 and earlier allows remote attackers to exe
23RISK
open
Referência
CVE-2026-18766
chetans9 core-php-admin-panel customers.php sql injection
33RISK
open
ReferênciaVexDay Proof
Internet Download Accelerator 5.2 - Remote Buffer Overflow (PoC)
CVE-2007-3162doswindows
Buffer overflow in the NotSafe function in the idaiehlp ActiveX control in idaiehlp.dll 1.9.1.74 in Internet Download Ac
23RISK
open
ReferênciaVexDay Proof
EDraw Office Viewer Component - Unsafe Method
CVE-2007-3168remotewindows
A certain ActiveX control in the EDraw Office Viewer Component (edrawofficeviewer.ocx) 4.0.5.20, and other versions befo
23RISK
open
ReferênciaVexDay Proof
GeometriX Download Portal - 'down_indir.asp?id' SQL Injection
CVE-2007-3188webappsasp
SQL injection vulnerability in down_indir.asp in Fullaspsite GeometriX Download Portal allows remote attackers to execut
23RISK
open
Referência
CVE-2017-17611
Doctor Search Script 1.0 has SQL Injection via the /list city parameter.
23RISK
open
Referência
CVE-2017-17613
Freelance Website Script 2.0.6 has SQL Injection via the jobdetails.php pr_id parameter or the searchbycat_list.php cati
23RISK
open
Referência
CVE-2017-17613
Freelance Website Script 2.0.6 has SQL Injection via the jobdetails.php pr_id parameter or the searchbycat_list.php cati
23RISK
open
Referência
CVE-2017-17614
Food Order Script 1.0 has SQL Injection via the /list city parameter.
23RISK
open
Referência
CVE-2026-18646
danpros HTMLy Author Name htmly.php path traversal
33RISK
open
Referência
CVE-2026-18631
jeequan jeepay PreAuthorize SysLogController.java WebSecurityConfig authorization
33RISK
open
Referência
CVE-2017-17614
Food Order Script 1.0 has SQL Injection via the /list city parameter.
23RISK
open
Referência
CVE-2017-17616
Event Search Script 1.0 has SQL Injection via the /event-list city parameter.
23RISK
open
Referência
CVE-2017-17616
Event Search Script 1.0 has SQL Injection via the /event-list city parameter.
23RISK
open
Referência
CVE-2017-17617
Foodspotting Clone Script 1.0 has SQL Injection via the quicksearch.php q parameter.
23RISK
open
Referência
CVE-2017-17617
Foodspotting Clone Script 1.0 has SQL Injection via the quicksearch.php q parameter.
23RISK
open
Referência
CVE-2026-14864
JetEngine < 3.8.12 - Contributor+ Stored XSS via jet_engine Shortcode
33RISK
open
previouspage 471 / 746next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.