Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,533cataloged exploits
35,607CVEs with public exploitation
24,695lab-tested
22,367 exploits
Referência
CVE-2009-4693
Multiple PHP remote file inclusion vulnerabilities in GraFX MiniCWB 2.3.0 allow remote attackers to execute arbitrary PH
23RISK
open
Referência
CVE-2009-5089
Directory traversal vulnerability in index.php in IdeaCart 0.02 and 0.02a allows remote attackers to read arbitrary file
23RISK
open
Referência
CVE-2013-7184
Gretech GOM Media Player 2.2.56.5158 and earlier allows remote attackers to cause a denial of service (memory corruption
23RISK
open
Referência
CVE-2015-8398
Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.8.17 allows remote attackers to inject arbitra
23RISK
open
Referência
CVE-2015-3624
Cross-site request forgery (CSRF) vulnerability in Test/WorkArea/DmsMenu/menuActions/MenuActions.aspx in Ektron Content
23RISK
open
Referência
CVE-2015-3624
Cross-site request forgery (CSRF) vulnerability in Test/WorkArea/DmsMenu/menuActions/MenuActions.aspx in Ektron Content
23RISK
open
Referência
CVE-2012-1898
Multiple cross-site scripting (XSS) vulnerabilities in wolfcms/admin/user/add in Wolf CMS 0.75 and earlier allow remote
23RISK
open
Referência
CVE-2016-5740
An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev5. JavaScript code can be used as part of ical atta
23RISK
open
ReferênciaVexDay Proof
Minerva 2.0.8a Build 237 - 'phpbb_root_path' File Inclusion
CVE-2006-3028webappsphp
PHP remote file inclusion vulnerability in stat_modules/users_age/module.php in Minerva 2.0.8a Build 237 and earlier all
23RISK
open
ReferênciaVexDay Proof
PHP-Update 2.7 - '/admin/uploads.php' Remote Code Execution
CVE-2006-6878webappsphp
admin/uploads.php in PHP-Update 2.7 and earlier allows remote attackers to gain privileges by setting the rights[7] para
23RISK
open
ReferênciaVexDay Proof
Joomla! Component module autostand 1.0 - Remote File Inclusion
CVE-2007-2319webappsphp
PHP remote file inclusion vulnerability in the AutoStand 1.1 and earlier module for Joomla! allows remote attackers to e
23RISK
open
ReferênciaVexDay Proof
Blakord Portal Beta 1.3.A (All Modules) - SQL Injection
CVE-2007-6565webappsphp
Multiple SQL injection vulnerabilities in Blakord Portal 1.3.A Beta and earlier allow remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
Adobe Reader - 'util.printf()' JavaScript Function Stack Overflow (2)
CVE-2008-2992HIGHunder attackransomwarelocalwindows
Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary c
100RISK
open
ReferênciaVexDay Proof
Libra PHP File Manager 1.18/2.0 - Local File Inclusion
CVE-2008-4319webappsphp
fileadmin.php in Libra File Manager (aka Libra PHP File Manager) 1.18 and earlier allows remote attackers to bypass auth
23RISK
open
Referência
CVE-2012-4993
torrent_functions.php in RivetTracker 1.03 and earlier does not properly restrict access, which allows remote attackers
23RISK
open
Referência
CVE-2010-1945
Multiple PHP remote file inclusion vulnerabilities in openMairie Openfoncier 2.00, when register_globals is enabled, all
23RISK
open
Referência
CVE-2010-2926
SQL injection vulnerability in index.php in sNews 1.7 allows remote attackers to execute arbitrary SQL commands via the
23RISK
open
ReferênciaVexDay Proof
MiNBank 1.5.0 - Multiple Remote File Inclusions
CVE-2008-6006webappsphp
Multiple PHP remote file inclusion vulnerabilities in Micronation Banking System (minba) 1.5.0 allow remote attackers to
23RISK
open
Referência
CVE-2010-2932
Buffer overflow in BarCodeWiz BarCode 3.29 ActiveX control (BarcodeWiz.dll) allows remote attackers to execute arbitrary
23RISK
open
Referência
CVE-2010-1337
Multiple PHP remote file inclusion vulnerabilities in definitions.php in Lussumo Vanilla 1.1.10, and possibly 0.9.2 and
23RISK
open
ReferênciaVexDay Proof
Sofi WebGui 0.6.3 PRE - 'mod_dir' Remote File Inclusion
CVE-2008-6402webappsphp
PHP remote file inclusion vulnerability in hu/modules/reg-new/modstart.php in Sofi WebGui 0.6.3 PRE and earlier allows r
23RISK
open
Referência
CVE-2015-4630
Multiple cross-site request forgery (CSRF) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x
23RISK
open
Referência
CVE-2010-1272
PHP remote file inclusion vulnerability in includes/tgpinc.php in Gnat-TGP 1.2.20 and earlier allows remote attackers to
23RISK
open
Referência
CVE-2010-1272
PHP remote file inclusion vulnerability in includes/tgpinc.php in Gnat-TGP 1.2.20 and earlier allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
Apple Mac OSX Safari 2.0.3 (417.9.2) - 'ROWSPAN' Denial of Service (PoC)
CVE-2006-2019dososx
Apple Mac OS X Safari 2.0.3, 1.3.1, and possibly other versions allows remote attackers to cause a denial of service (CP
23RISK
open
Referência
CVE-2018-12705
DIGISOL DG-BR4000NG devices have XSS via the SSID (it is validated only on the client side).
23RISK
open
ReferênciaVexDay Proof
YapBB 1.2 Beta2 - 'yapbb_session.php' Remote File Inclusion
CVE-2006-6633webappsphp
PHP remote file inclusion vulnerability in include/yapbb_session.php in YapBB 1.2 Beta2 and earlier allows remote attack
23RISK
open
Referência
CVE-2009-20010
Dogfood CRM spell.php RCE
63RISK
open
Referência
CVE-2009-20010
Dogfood CRM spell.php RCE
63RISK
open
ReferênciaVexDay Proof
mxBB Module mx_blogs 2.0.0-beta - Remote File Inclusion
CVE-2008-1712webappsphp
PHP remote file inclusion vulnerability in includes/functions_weblog.php in mxBB mx_blogs 2.0.0 beta allows remote attac
23RISK
open
previouspage 473 / 746next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.