Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,620cataloged exploits
35,647CVEs with public exploitation
24,695lab-tested
22,429 exploits
Referência
CVE-2008-6364
SQL injection vulnerability in logon_process.jsp in Ad Server Solutions Banner Exchange Solution Java allows remote atta
23RISK
open
ReferênciaVexDay Proof
Banner Exchange Java - Authentication Bypass
CVE-2008-6364webappsasp
SQL injection vulnerability in logon_process.jsp in Ad Server Solutions Banner Exchange Solution Java allows remote atta
23RISK
open
ReferênciaVexDay Proof
Ad Management Java - Authentication Bypass
CVE-2008-6365webappsasp
SQL injection vulnerability in logon.jsp in Ad Server Solutions Ad Management Software Java allows remote attackers to e
23RISK
open
ReferênciaVexDay Proof
@lex Guestbook 4.0.2 - Remote Command Execution
CVE-2007-0205webappsphp
Directory traversal vulnerability in admin/skins.php for @lex Guestbook 4.0.2 and earlier allows remote attackers to cre
23RISK
open
Referência
CVE-2020-6287
CVE-2020-6287CRITICALunder attack
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication c
100RISK
open
ReferênciaVexDay Proof
Affiliate Software Java 4.0 - Authentication Bypass
CVE-2008-6366webappsasp
SQL injection vulnerability in logon.jsp in Ad Server Solutions Affiliate Software Java 4.0 allows remote attackers to e
23RISK
open
ReferênciaVexDay Proof
Ocean12 Contact Manager Pro - SQL Injection / Cross-Site Scripting / File Disclosure
CVE-2008-6369webappsphp
SQL injection vulnerability in default.asp in Ocean12 Contact Manager Pro 1.02 allows remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
vp-asp shopping cart 6.09 - SQL Injection / Cross-Site Scripting
CVE-2007-0224webappsasp
SQL injection vulnerability in shopgiftregsearch.asp in VP-ASP Shopping Cart 6.09 and earlier allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
JV2 Folder Gallery 3.0 - 'download.php' Remote File Disclosure
CVE-2007-0329webappsphp
download.php in Joonas Viljanen JV2 Folder Gallery allows remote attackers to read sensitive files via a relative pathna
23RISK
open
Referência
CVE-2018-17456
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x be
60RISK
open
Referência
CVE-2023-27524
CVE-2023-27524HIGHunder attack
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISK
open
Referência
CVE-2020-17506
Artica Web Proxy 4.30.00000000 allows remote attacker to bypass privilege detection and gain web backend administrator p
60RISK
open
Referência
CVE-2023-27524
CVE-2023-27524HIGHunder attack
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISK
open
ReferênciaVexDay Proof
Rae Media Contact MS - Authentication Bypass
CVE-2008-6389webappsphp
SQL injection vulnerability in asadmin/default.asp in Rae Media Contact Management Software SOHO, Standard, and Enterpri
23RISK
open
Referência
CVE-2015-7857
SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.p
60RISK
open
Referência
CVE-2015-7857
SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.p
60RISK
open
Referência
CVE-2019-16172
LimeSurvey before v3.17.14 allows stored XSS for escalating privileges from a low-privileged account to, for example, Su
23RISK
open
Referência
CVE-2017-5753
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of
55RISK
open
Referência
CVE-2008-6392
SQL injection vulnerability in showads.php in Z1Exchange allows remote attackers to execute arbitrary SQL commands via t
23RISK
open
Referência
CVE-2018-14933
CVE-2018-14933CRITICALunder attack
upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir par
100RISK
open
Referência
CyberArk Viewfinity 5.5.10.95 - Local Privilege Escalation
CVE-2017-11197HIGHlocalwindows
In CyberArk Viewfinity 5.5.10.95 and 6.x before 6.1.1.220, a low privilege user can escalate to an administrative user v
41RISK
open
Referência
CVE-2015-5122
CVE-2015-5122HIGHunder attack
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player
100RISK
open
Referência
CVE-2017-1129
IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it coul
50RISK
open
Referência
CVE-2022-40022
Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability.
85RISK
open
Referência
CVE-2023-23488
The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerabilit
85RISK
open
Referência
CVE-2021-40870
CVE-2021-40870CRITICALunder attack
An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous
100RISK
open
Referência
CVE-2022-24706
CVE-2022-24706CRITICALunder attack
Remote Code Execution Vulnerability in Packaging
100RISK
open
ReferênciaVexDay Proof
e107 Plugin BLOG Engine 2.2 - 'uid' SQL Injection
CVE-2008-6438webappsphp
SQL injection vulnerability in macgurublog_menu/macgurublog.php in the MacGuru BLOG Engine plugin 2.2 for e107 allows re
23RISK
open
Referência
Inosoft VisiWin 7 2022-2.1 - Insecure Folders Permissions
CVE-2023-31468HIGHlocalwindows
An issue was discovered in Inosoft VisiWin 7 through 2022-2.1 (Runtime RT7.3 RC3 20221209.5). The "%PROGRAMFILES(X86)%\I
41RISK
open
ReferênciaVexDay Proof
SoftComplex PHP Image Gallery - 'ctg' SQL Injection
CVE-2008-6485webappsphp
SQL injection vulnerability in index.php in SoftComplex PHP Image Gallery allows remote attackers to execute arbitrary S
23RISK
open
previouspage 501 / 748next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.