Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,620cataloged exploits
35,647CVEs with public exploitation
24,695lab-tested
22,407 exploits
Referência
CVE-2022-24637
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, wh
60RISK
open
Referência
CVE-2022-24637
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, wh
60RISK
open
Referência
CVE-2022-24706
CVE-2022-24706CRITICALunder attack
Remote Code Execution Vulnerability in Packaging
100RISK
open
ReferênciaVexDay Proof
PHP Blue Dragon CMS 2.9.1 - Cross-Site Scripting / SQL Injection Code Execution
CVE-2006-4962webappsphp
Directory traversal vulnerability in pbd_engine.php in Php Blue Dragon 2.9.1 and earlier allows remote attackers to read
23RISK
open
Referência
CVE-2022-26134
CVE-2022-26134CRITICALunder attackransomware
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
ReferênciaVexDay Proof
PHP Blue Dragon CMS 3.0.0 - Remote Code Execution
CVE-2006-4962webappsphp
Directory traversal vulnerability in pbd_engine.php in Php Blue Dragon 2.9.1 and earlier allows remote attackers to read
23RISK
open
ReferênciaVexDay Proof
pNews 1.1.0 - 'nbs' Remote File Inclusion
CVE-2006-5022webappsphp
PHP remote file inclusion vulnerability in includes/global.php in Joshua Wilson pNews System 1.1.0 (aka PowerNews) allow
23RISK
open
ReferênciaVexDay Proof
PHPartenaire 1.0 - 'dix.php3' Remote File Inclusion
CVE-2006-5032webappsphp
PHP remote file inclusion vulnerability in dix.php3 in PHPartenaire 1.0 allows remote attackers to execute arbitrary PHP
23RISK
open
ReferênciaVexDay Proof
Joomla! Component Joomlaboard 1.1.1 - 'sbp' Remote File Inclusion
CVE-2006-5043webappsphp
Multiple PHP remote file inclusion vulnerabilities in the Joomlaboard Forum Component (com_joomlaboard) before 1.1.2 for
23RISK
open
ReferênciaVexDay Proof
Advaced-Clan-Script 3.4 - 'mcf.php' Remote File Inclusion
CVE-2006-5061webappsphp
PHP remote file inclusion vulnerability in mcf.php in Advanced-Clan-Script (AVCX) 3.4 and earlier allows remote attacker
23RISK
open
ReferênciaVexDay Proof
PBLang 4.66z - 'temppath' Remote File Inclusion
CVE-2006-5062webappsphp
PHP remote file inclusion vulnerability in templates/pb/language/lang_nl.php in PBLang (PBL) 4.66z and earlier allows re
23RISK
open
ReferênciaVexDay Proof
faceStones personal 2.0.42 - 'fs_form_links.php' File Inclusion
CVE-2006-5070webappsphp
PHP remote file inclusion vulnerability in fsl2/objects/fs_form_links.php in faceStones Personal 2.0.42 and earlier allo
23RISK
open
ReferênciaVexDay Proof
evoBB 0.3 - 'path' Remote File Inclusion
CVE-2006-5087webappsphp
Multiple PHP remote file inclusion vulnerabilities in evoBB 0.3 and earlier allow remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
NaviCOPA Web Server 2.01 - 'GET' Remote Buffer Overflow
CVE-2006-5112remotewindows
Buffer overflow in InterVations NaviCOPA Web Server 2.01 allows remote attackers to execute arbitrary code via a long HT
50RISK
open
Referência
CVE-2022-26986
SQL Injection in ImpressCMS 1.4.3 and earlier allows remote attackers to inject into the code in unintended way, this al
23RISK
open
Referência
CVE-2022-27308
A stored cross-site scripting (XSS) vulnerability in PHProjekt PhpSimplyGest v1.3.0 allows attackers to execute arbitrar
23RISK
open
Referência
CVE-2022-27412
Explore CMS v1.0 was discovered to contain a SQL injection vulnerability via a /page.php?id= request.
23RISK
open
Referência
CVE-2022-28117
A Server-Side Request Forgery (SSRF) in feed_parser class of Navigate CMS v2.9.4 allows remote attackers to force the ap
43RISK
open
Referência
CVE-2022-2846
Calendar Event Multi View < 1.4.07 - Unauthenticated Arbitrary Event Creation to Stored XSS
33RISK
open
Referência
CVE-2022-29296
A reflected cross-site scripting (XSS) vulnerability in the login portal of Avantune Genialcloud ProJ - 10 allows attack
23RISK
open
Referência
PyScript - Read Remote Python Source Code
CVE-2022-30286remotepython
pyscriptjs (aka PyScript Demonstrator) in PyScript through 2022-05-04 allows a remote user to read Python source code.
28RISK
open
Referência
CVE-2022-30525
CVE-2022-30525CRITICALunder attack
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Pat
100RISK
open
Referência
CVE-2022-30525
CVE-2022-30525CRITICALunder attack
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Pat
100RISK
open
ReferênciaVexDay Proof
Microsoft Office 2003 - '.PPT' Local Buffer Overflow (PoC)
CVE-2006-5296doswindows
PowerPoint in Microsoft Office 2003 does not properly handle a container object whose position value exceeds the record
28RISK
open
ReferênciaVexDay Proof
phpBB SpamBlocker Mod 1.0.2 - Remote File Inclusion
CVE-2006-5301webappsphp
PHP remote file inclusion vulnerability in includes/antispam.php in the SpamBlockerMODv 1.0.2 and earlier module for php
23RISK
open
Referência
CVE-2022-30781
Gitea before 1.16.7 does not escape git fetch remote.
60RISK
open
Referência
CVE-2022-30781
Gitea before 1.16.7 does not escape git fetch remote.
60RISK
open
ReferênciaVexDay Proof
Redaction System 1.0 - 'lang_prefix' Remote File Inclusion
CVE-2006-5302webappsphp
Multiple PHP remote file inclusion vulnerabilities in Redaction System 1.0000 allow remote attackers to execute arbitrar
23RISK
open
Referência
CVE-2022-31188
Server-Side Request Forgery Vulnerability in Computer Vision Annotation Tool (CVAT)
53RISK
open
ReferênciaVexDay Proof
phpBB Prillian French Mod 0.8.0 - Remote File Inclusion
CVE-2006-5309webappsphp
PHP remote file inclusion vulnerability in language/lang_french/lang_prillian_faq.php in the Prillian French 0.8.0 and e
23RISK
open
previouspage 497 / 747next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.