Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,620cataloged exploits
35,647CVEs with public exploitation
24,695lab-tested
22,429 exploits
Referência
CVE-2023-0777
Authentication Bypass by Primary Weakness in modoboa/modoboa
61RISK
open
ReferênciaVexDay Proof
KTP Computer Customer Database CMS 1.0 - Blind SQL Injection
CVE-2008-5952webappsphp
SQL injection vulnerability in KTP Computer Customer Database (KTPCCD) CMS, when magic_quotes_gpc is disabled, allows re
23RISK
open
Referência
CVE-2025-32433
CVE-2025-32433CRITICALunder attack
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
Referência
CVE-2026-7732
code-projects BloodBank Managing System request_blood.php unrestricted upload
33RISK
open
ReferênciaVexDay Proof
Active Test 2.1 - 'QuizID' Blind SQL Injection
CVE-2008-5958webappsasp
Multiple SQL injection vulnerabilities in Active Test 2.1 allow remote attackers to execute arbitrary SQL commands via t
23RISK
open
Referência
CVE-2024-10914
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISK
open
Referência
CVE-2026-19823
Tenda W20E QoS Rule Deletion delQos formQOSRuleDel stack-based overflow
41RISK
open
Referência
CVE-2026-19822
Tenda W20E QoS Edit editQos lstAdd stack-based overflow
41RISK
open
Referência
CVE-2019-9082
CVE-2019-9082HIGHunder attack
ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public/
100RISK
open
ReferênciaVexDay Proof
Active Price Comparison 4 - Authentication Bypass
CVE-2008-5974webappsasp
Multiple SQL injection vulnerabilities in login.aspx in Active Price Comparison 4.0 allow remote attackers to execute ar
23RISK
open
ReferênciaVexDay Proof
Netartmedia Jobs Portal 1.3 - Multiple SQL Injections
CVE-2008-6030webappsphp
Multiple SQL injection vulnerabilities in NetArtMedia Jobs Portal 1.3 allow remote attackers to execute arbitrary SQL co
23RISK
open
Referência
CVE-2025-34028
CVE-2025-34028CRITICALunder attack
Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal
100RISK
open
Referência21
watchtowrlabs/watchTowr-vs-Commvault-PreAuth-RCE-CVE-2025-34028
CVE-2025-34028CRITICALunder attack
Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal
100RISK
open
ReferênciaVexDay Proof
WSN Links 2.22/2.23 - 'vote.php' SQL Injection
CVE-2008-6031webappsphp
SQL injection vulnerability in vote.php in WSN Links 2.22 and 2.23 allows remote attackers to execute arbitrary SQL comm
23RISK
open
Referência
CVE-2023-1671
CVE-2023-1671CRITICALunder attack
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10
100RISK
open
Referência
CVE-2019-7256
CVE-2019-7256CRITICALunder attack
Linear eMerge E3-Series devices allow Command Injections.
100RISK
open
Referência
CVE-2026-19791
Tenda G0 httpd web management interface module addStaticRoute stack-based overflow
41RISK
open
Referência
CVE-2026-19790
Tenda G0 httpd Web Management module formSetPortMirror stack-based overflow
41RISK
open
Referência
CVE-2026-19789
Tenda AC1206 httpd web management interface WifiGuestSet set_wl_guest_iplist stack-based overflow
41RISK
open
Referência
CVE-2026-19788
Tenda AC1206 httpd web management interface SetOnlineDevName set_device_name stack-based overflow
41RISK
open
ReferênciaVexDay Proof
DomPHP 0.81 - 'cat' SQL Injection
CVE-2008-6064webappsphp
Multiple SQL injection vulnerabilities in DomPHP 0.81 allow remote attackers to execute arbitrary SQL commands via the c
23RISK
open
Referência
CVE-2023-26360
CVE-2023-26360HIGHunder attack
Adobe ColdFusion Improper Access Control Arbitrary code execution
100RISK
open
Referência
CVE-2021-44790
Possible buffer overflow when parsing multipart content in mod_lua of Apache HTTP Server 2.4.51 and earlier
45RISK
open
Referência
CVE-2018-9206
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
60RISK
open
Referência
CVE-2016-7089
WatchGuard RapidStream appliances allow local users to gain privileges and execute arbitrary commands via a crafted ifco
23RISK
open
Referência
CVE-2012-0782
Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/setup-config.php in the installation component in WordPr
23RISK
open
ReferênciaVexDay Proof
Titan FTP Server 6.26 build 630 - Remote Denial of Service
CVE-2008-6082doswindows
Titan FTP Server 6.26 build 630 allows remote attackers to cause a denial of service (CPU consumption) via the SITE WHO
50RISK
open
ReferênciaVexDay Proof
Iamma Simple Gallery 1.0/2.0 - Arbitrary File Upload
CVE-2008-6084webappsphp
Unrestricted file upload vulnerability in pages/download.php in Iamma Simple Gallery 1.0 and 2.0 allows remote attackers
23RISK
open
ReferênciaVexDay Proof
Back-End CMS 0.7.2.2 - 'BE_config.php' Remote File Inclusion
CVE-2006-2682webappsphp
PHP remote file inclusion vulnerability in BE_config.php in Back-End CMS 0.7.2.1 and earlier allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
Camera Life 2.6.2b4 - SQL Injection / Cross-Site Scripting
CVE-2008-6086webappsphp
SQL injection vulnerability in album.php in Camera Life 2.6.2b4 allows remote attackers to execute arbitrary SQL command
23RISK
open
previouspage 502 / 748next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.