Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,343cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
22,573 exploits
ReferênciaVexDay Proof
Uploader & Downloader 3.0 - 'id_user' SQL Injection
CVE-2006-6716webappsphp
SQL injection vulnerability in administration/administre2.php in Eric GUILLAUME uploader&downloader 3 allows remote atta
23RISK
open
ReferênciaVexDay Proof
Bandwebsite 1.5 - 'LOGIN' Remote Add Admin
CVE-2006-6722webappsphp
Bandwebsite (aka Bandsite portal system) 1.5 allows remote attackers to create administrative accounts via a direct requ
23RISK
open
ReferênciaVexDay Proof
MiniBB 2.2 - Cross-Site Scripting / SQL Injection / Full Path Disclosure
CVE-2008-2024webappsphp
Cross-site scripting (XSS) vulnerability in index.php in miniBB 2.2, and possibly earlier, when register_globals is enab
23RISK
open
Referência
CVE-2025-34028
CVE-2025-34028CRITICALunder attack
Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal
100RISK
open
Referência21
watchtowrlabs/watchTowr-vs-Commvault-PreAuth-RCE-CVE-2025-34028
CVE-2025-34028CRITICALunder attack
Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal
100RISK
open
Referência
Payara Micro Community 5.2021.6 - Directory Traversal
CVE-2021-41381webappsmultiple
Payara Micro Community 5.2021.6 and below allows Directory Traversal.
50RISK
open
Referência
CVE-2023-1671
CVE-2023-1671CRITICALunder attack
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10
100RISK
open
Referência
CVE-2019-7256
CVE-2019-7256CRITICALunder attack
Linear eMerge E3-Series devices allow Command Injections.
100RISK
open
Referência
CVE-2026-19791
Tenda G0 httpd web management interface module addStaticRoute stack-based overflow
41RISK
open
Referência
CVE-2021-41773
CVE-2021-41773HIGHunder attackransomware
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
Referência
CVE-2026-19790
Tenda G0 httpd Web Management module formSetPortMirror stack-based overflow
41RISK
open
Referência
CVE-2026-19789
Tenda AC1206 httpd web management interface WifiGuestSet set_wl_guest_iplist stack-based overflow
41RISK
open
Referência
CVE-2026-19788
Tenda AC1206 httpd web management interface SetOnlineDevName set_device_name stack-based overflow
41RISK
open
Referência
CVE-2021-41773
CVE-2021-41773HIGHunder attackransomware
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
Referência
CVE-2021-41773
CVE-2021-41773HIGHunder attackransomware
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
Referência
CVE-2021-41773
CVE-2021-41773HIGHunder attackransomware
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
ReferênciaVexDay Proof
MiniBB 2.2 - Cross-Site Scripting / SQL Injection / Full Path Disclosure
CVE-2008-2029webappsphp
Multiple SQL injection vulnerabilities in (1) setup_mysql.php and (2) setup_options.php in miniBB 2.2 and possibly earli
23RISK
open
ReferênciaVexDay Proof
Siteman 2.x - Code Execution / Local File Inclusion / Cross-Site Scripting
CVE-2008-2081webappsphp
Directory traversal vulnerability in index.php in Siteman 2.0.x2 allows remote authenticated administrators to include a
23RISK
open
Referência
CVE-2023-26360
CVE-2023-26360HIGHunder attack
Adobe ColdFusion Improper Access Control Arbitrary code execution
100RISK
open
ReferênciaVexDay Proof
PHP Forge 3 Beta 2 - 'id' SQL Injection
CVE-2008-2088webappsphp
SQL injection vulnerability in admin/news.php in PHP Forge 3.0 beta 2 allows remote attackers to execute arbitrary SQL c
23RISK
open
Referência
CVE-2018-9206
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
60RISK
open
ReferênciaVexDay Proof
Joomla! Component FlippingBook 1.0.4 - SQL Injection
CVE-2008-2095webappsphp
SQL injection vulnerability in index.php in the FlippingBook (com_flippingbook) 1.0.4 component for Joomla! allows remot
23RISK
open
ReferênciaVexDay Proof
BackLinkSpider 1.1 - 'cat_id' SQL Injection
CVE-2008-2096webappsphp
SQL injection vulnerability in BackLinkSpider allows remote attackers to execute arbitrary SQL commands via the cat_id p
23RISK
open
ReferênciaVexDay Proof
Netartmedia Jobs Portal 1.3 - Multiple SQL Injections
CVE-2008-6030webappsphp
Multiple SQL injection vulnerabilities in NetArtMedia Jobs Portal 1.3 allow remote attackers to execute arbitrary SQL co
23RISK
open
ReferênciaVexDay Proof
WSN Links 2.22/2.23 - 'vote.php' SQL Injection
CVE-2008-6031webappsphp
SQL injection vulnerability in vote.php in WSN Links 2.22 and 2.23 allows remote attackers to execute arbitrary SQL comm
23RISK
open
Referência
CVE-2019-12255
Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4). This is a IPNET security vulnerability: TC
45RISK
open
Referência
CVE-2023-0297
Code Injection in pyload/pyload
85RISK
open
Referência
CVE-2023-0297
Code Injection in pyload/pyload
85RISK
open
ReferênciaVexDay Proof
Pre Shopping Mall 1.1 - 'search.php' SQL Injection
CVE-2008-2114webappsphp
SQL injection vulnerability in emall/search.php in Pre Shopping Mall 1.1 allows remote attackers to execute arbitrary SQ
23RISK
open
Referência
CVE-2026-19756
Dromara lamp-cloud Code Generator DefGenProjectController.java path traversal
33RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.