Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,533cataloged exploits
35,607CVEs with public exploitation
24,695lab-tested
22,367 exploits
ReferênciaVexDay Proof
PHP-Fusion Mod TI - 'id' SQL Injection
CVE-2008-5733webappsphp
SQL injection vulnerability in blog.php in the Team Impact TI Blog System mod for PHP-Fusion allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
Calendar Script 1.1 - Authentication Bypass
CVE-2008-5737webappsphp
SQL injection vulnerability in index.php in Nodstrum MySQL Calendar 1.1 and 1.2 allows remote attackers to execute arbit
23RISK
open
ReferênciaVexDay Proof
CoolPlayer 2.19 - '.Skin' Local Buffer Overflow
CVE-2008-5735localwindows
Stack-based buffer overflow in skin.c in CoolPlayer 2.17 through 2.19 allows remote attackers to execute arbitrary code
23RISK
open
ReferênciaVexDay Proof
CoolPlayer 2.19 - '.Skin' Local Buffer Overflow
CVE-2008-5735localwindows
Stack-based buffer overflow in skin.c in CoolPlayer 2.17 through 2.19 allows remote attackers to execute arbitrary code
23RISK
open
ReferênciaVexDay Proof
Microsoft Windows Media Player - '.wav' Remote Crash (PoC)
CVE-2008-5745doswindows
Integer overflow in quartz.dll in the DirectShow framework in Microsoft Windows Media Player (WMP) 9, 10, and 11, includ
28RISK
open
ReferênciaVexDay Proof
Google Chrome - 'ChromeHTML://' Remote Parameter Injection
CVE-2008-5750remotewindows
Argument injection vulnerability in Microsoft Internet Explorer 8 beta 2 on Windows XP SP3 allows remote attackers to ex
28RISK
open
ReferênciaVexDay Proof
Alstrasoft Web Email Script Enterprise - 'id' SQL Injection
CVE-2008-5751webappsphp
SQL injection vulnerability in index.php in AlstraSoft Web Email Script Enterprise (ESE) allows remote attackers to exec
23RISK
open
Referência
CVE-2018-7581
\ProgramData\WebLog Expert\WebServer\WebServer.cfg in WebLog Expert Web Server Enterprise 9.4 has weak permissions (BUIL
23RISK
open
Referência
CVE-2018-7581
\ProgramData\WebLog Expert\WebServer\WebServer.cfg in WebLog Expert Web Server Enterprise 9.4 has weak permissions (BUIL
23RISK
open
Referência
CVE-2018-7584
In PHP through 5.6.33, 7.0.x before 7.0.28, 7.1.x through 7.1.14, and 7.2.x through 7.2.2, there is a stack-based buffer
45RISK
open
Referência
CVE-2018-7600
CVE-2018-7600CRITICALunder attackransomware
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
Referência
CVE-2018-6005
SQL Injection exists in the Realpin through 1.5.04 component for Joomla! via the pinboard parameter.
23RISK
open
Referência
CVE-2018-6191
The js_strtod function in jsdtoa.c in Artifex MuJS through 1.0.2 has an integer overflow because of incorrect exponent v
23RISK
open
Referência
CVE-2018-6193
A Cross-Site Scripting (XSS) vulnerability was found in Routers2 2.24, affecting the 'rtr' GET parameter in a page=graph
23RISK
open
Referência
CVE-2018-6221
An unvalidated software update vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a man-in-the-middle
23RISK
open
Referência
CVE-2026-16009
itsourcecode Hospital Management System prescriptionorderdetail.php sql injection
33RISK
open
Referência
CVE-2026-12684
Customer Reviews for WooCommerce < 5.113.0 - Unauthenticated Arbitrary Media Upload via cr_upload_media
33RISK
open
Referência
CVE-2026-12585
Abandoned Cart Lite for WooCommerce < 6.8.2 - Unauthenticated Account Takeover via Malleable Recovery-Link Token
41RISK
open
Referência
CVE-2026-12525
Redux Framework < 4.5.13 - Subscriber+ Privilege Escalation to Administrator
41RISK
open
Referência
CVE-2026-12510
AI Engine < 3.5.5 - Subscriber+Chatbot Discussion Disclosure and Takeover via IDOR
33RISK
open
Referência
CVE-2026-12512
Quotes Llama < 3.1.6 - Unauthenticated SQL Injection via sc Parameter
41RISK
open
Referência
CVE-2026-12281
Shibboleth < 2.5.4 - Unauthenticated Administrator Account Creation via Identity Header Spoofing
41RISK
open
Referência
CVE-2026-15523
CodeAstro Simple Online Leave Management System dashboard.php sql injection
33RISK
open
Referência
CVE-2026-15522
tugcantopaloglu godot-mcp run_project index.js validatePath path traversal
33RISK
open
Referência
CVE-2026-15521
makafeli n8n-workflow-builder update_node_from_file server.cjs path traversal
33RISK
open
Referência
CVE-2026-15520
GNU LibreDWG R2004 Section Decompression decode.c decompress_R2004_section heap-based overflow
33RISK
open
Referência
CVE-2026-15518
AREA 17 Twill CMS Media Library Insert FileLibraryController.php storeFile unrestricted upload
33RISK
open
Referência
CVE-2026-15753
zhinianboke xianyu-auto-reply review approve trusting http permission methods on the server side
33RISK
open
Referência
CVE-2026-15517
Jinher OA PlanGiveOut.aspx sql injection
33RISK
open
Referência
CVE-2026-15516
MacCMS Pro Installation Index.php step5 authorization
33RISK
open
previouspage 479 / 746next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.