Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,533cataloged exploits
35,607CVEs with public exploitation
24,695lab-tested
22,407 exploits
Referência
CVE-2023-3846
mooSocial mooDating URL pages cross site scripting
43RISK
open
ReferênciaVexDay Proof
Crystal Reports XI Release 2 (Enterprise Tree Control) - ActiveX Buffer Overflow (Denial of Service) (PoC)
CVE-2008-0379doswindows
Race condition in the Enterprise Tree ActiveX control (EnterpriseControls.dll 11.5.0.313) in Crystal Reports XI Release
23RISK
open
ReferênciaVexDay Proof
OpenBSD 4.2 - 'rtlabel_id2name()' Local Null Pointer Dereference Denial of Service
CVE-2008-0384dosbsd
OpenBSD 4.2 allows local users to cause a denial of service (kernel panic) by calling the SIOCGIFRTLABEL IOCTL on an int
23RISK
open
ReferênciaVexDay Proof
alitalk 1.9.1.1 - Multiple Vulnerabilities
CVE-2008-0391webappsphp
inc/elementz.php in aliTalk 1.9.1.1 does not properly verify authentication, which allows remote attackers to add an arb
23RISK
open
ReferênciaVexDay Proof
Microsoft Visual Basic Enterprise 6 SP6 - '.dsr' File Handling Buffer Overflow
CVE-2008-0392localwindows
Multiple buffer overflows in Microsoft Visual Basic Enterprise Edition 6.0 SP6 allow user-assisted remote attackers to e
35RISK
open
ReferênciaVexDay Proof
aflog 1.01 - Cross-Site Scripting / SQL Injection
CVE-2008-0398webappsphp
Cross-site scripting (XSS) vulnerability in aflog 1.01, and possibly earlier versions, allows remote attackers to inject
23RISK
open
ReferênciaVexDay Proof
Toshiba Surveillance - 'MeIpCamX.dll 1.0.0.4' Remote Buffer Overflow
CVE-2008-0399remotewindows
Multiple buffer overflows in Toshiba Surveillance (Surveillix) RecordSend ActiveX control (MeIpCamX.DLL 1.0.0.4) allow r
23RISK
open
ReferênciaVexDay Proof
Invision Gallery 2.0.7 - SQL Injection
CVE-2008-0421webappsphp
SQL injection vulnerability in Invision Gallery 2.0.7 and earlier allows remote attackers to execute arbitrary SQL comma
23RISK
open
ReferênciaVexDay Proof
bloofox 0.3 - SQL Injection / File Disclosure
CVE-2008-0428webappsphp
Multiple SQL injection vulnerabilities in the login function in system/class_permissions.php in bloofoxCMS 0.3 allow rem
23RISK
open
ReferênciaVexDay Proof
IDM-OS 1.0 - 'Filename' File Disclosure
CVE-2008-0431webappsphp
Directory traversal vulnerability in administrator/download.php in IDMOS (aka Phoenix) 1.0 allows remote attackers to re
23RISK
open
ReferênciaVexDay Proof
Foojan Wms 1.0 - 'story' SQL Injection
CVE-2008-0447webappsphp
SQL injection vulnerability in index.php in Foojan WMS PHP Weblog 1.0 allows remote attackers to execute arbitrary SQL c
23RISK
open
ReferênciaVexDay Proof
Easysitenetwork Recipe - 'categoryId' SQL Injection
CVE-2008-0453webappsphp
SQL injection vulnerability in list.php in Easysitenetwork Recipe allows remote attackers to execute arbitrary SQL comma
23RISK
open
ReferênciaVexDay Proof
Liquid-Silver CMS 0.1 - 'update' Local File Inclusion
CVE-2008-0459webappsphp
Directory traversal vulnerability in update/index.php in Liquid-Silver CMS 0.35, when magic_quotes_gpc is disabled, allo
23RISK
open
Referência
CVE-2018-18428
TP-Link TL-SC3130 1.6.18P12_121101 devices allow unauthenticated RTSP stream access, as demonstrated by a /jpg/image.jpg
28RISK
open
Referência
CVE-2018-18437
In AXIOS ITALIA Axioscloud Sissiweb Registro Elettronico 1.7.0, secret/relogoff.aspx has XSS via the Error_Desc paramete
23RISK
open
Referência
CVE-2018-18763
SaltOS 3.1 r8126 allows action=ajax&query=numbers&page=usuarios&action2=[SQL] SQL Injection.
23RISK
open
Referência
CVE-2018-18763
SaltOS 3.1 r8126 allows action=ajax&query=numbers&page=usuarios&action2=[SQL] SQL Injection.
23RISK
open
Referência
CVE-2003-0727
Multiple buffer overflows in the XML Database (XDB) functionality for Oracle 9i Database Release 2 allow local users to
50RISK
open
Referência
CVE-2018-18772
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=send_ssh, as dem
23RISK
open
Referência
CVE-2018-18772
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=send_ssh, as dem
23RISK
open
Referência
CVE-2018-18773
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=rootpwd, as demo
23RISK
open
Referência
CVE-2018-18774
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows XSS via the admin/index.php module parameter.
23RISK
open
Referência
CVE-2018-18774
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows XSS via the admin/index.php module parameter.
23RISK
open
Referência
CVE-2018-18776
Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (
23RISK
open
Referência
CVE-2018-18776
Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (
23RISK
open
Referência
CVE-2018-19113
The Pronestor PNHM (aka Health Monitoring or HealthMonitor) add-in before 8.1.13.0 for Outlook has "BUILTIN\Users:(I)(F)
23RISK
open
Referência
CVE-2018-19135
ClipperCMS 1.3.3 does not have CSRF protection on its kcfinder file upload (enabled by default). This can be used by an
23RISK
open
Referência
CVE-2018-19246
PHP-Proxy 5.1.0 allows remote attackers to read local files if the default "pre-installed version" (intended for users w
28RISK
open
Referência
CVE-2018-19276
OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated use
85RISK
open
Referência
CVE-2018-19276
OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated use
85RISK
open
previouspage 482 / 747next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.