Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,620cataloged exploits
35,647CVEs with public exploitation
24,695lab-tested
22,429 exploits
ReferênciaVexDay Proof
Natterchat 1.1 - Authentication Bypass
CVE-2008-7049webappsphp
Multiple SQL injection vulnerabilities in login.asp in NatterChat 1.1 and 1.12 allow remote attackers to execute arbitra
23RISK
open
ReferênciaVexDay Proof
Natterchat 1.12 - Authentication Bypass
CVE-2008-7049webappsphp
Multiple SQL injection vulnerabilities in login.asp in NatterChat 1.1 and 1.12 allow remote attackers to execute arbitra
23RISK
open
Referência
CVE-2009-2310
SQL injection vulnerability in include/get_read.php in Extensible-BioLawCom CMS (X-BLC) 0.2.0 and earlier allows remote
23RISK
open
Referência
CVE-2017-16894
In Laravel framework through 5.5.21, remote attackers can obtain sensitive information (such as externally usable passwo
60RISK
open
Referência
CVE-2018-1002105
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg
70RISK
open
Referência
CVE-2018-1002105
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg
70RISK
open
Referência
CVE-2023-4278
MasterStudy LMS < 3.0.18 - Unauthenticated Instructor Account Creation
41RISK
open
Referência
CVE-2018-9276
CVE-2018-9276HIGHunder attack
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administra
100RISK
open
Referência
CVE-2018-9276
CVE-2018-9276HIGHunder attack
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administra
100RISK
open
Referência
CVE-2018-9276
CVE-2018-9276HIGHunder attack
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administra
100RISK
open
Referência
CVE-2023-4278
MasterStudy LMS < 3.0.18 - Unauthenticated Instructor Account Creation
41RISK
open
Referência
CVE-2010-1743
SQL injection vulnerability in projects.php in Scratcher allows remote attackers to execute arbitrary SQL commands via t
23RISK
open
Referência
CVE-2022-2992
A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows
85RISK
open
Referência
CVE-2009-2331
Multiple static code injection vulnerabilities in CMS Chainuk 1.2 and earlier allow remote attackers to inject arbitrary
23RISK
open
Referência
CVE-2021-1675
CVE-2021-1675HIGHunder attackransomware
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
Referência
CVE-2021-1675
CVE-2021-1675HIGHunder attackransomware
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
Referência
CVE-2021-1675
CVE-2021-1675HIGHunder attackransomware
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
ReferênciaVexDay Proof
Facil-CMS 0.1RC - Multiple Local File Inclusions
CVE-2008-7176webappsphp
Multiple directory traversal vulnerabilities in Facil CMS 0.1RC allow remote attackers to read arbitrary files via a ..
23RISK
open
Referência
CVE-2026-1731
CVE-2026-1731CRITICALunder attackransomware
Remote code execution vulnerability in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)
100RISK
open
ReferênciaVexDay Proof
OTManager CMS 2.4 - Insecure Cookie Handling
CVE-2008-7179webappsphp
OTManager CMS 2.4 allows remote attackers to bypass authentication and gain administrator privileges by setting the ADMI
23RISK
open
Referência
CVE-2020-11652
CVE-2020-11652MEDIUMunder attack
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISK
open
Referência
CVE-2017-5255
In version 3.5 and prior of Cambium Networks ePMP firmware, a lack of input sanitation for certain parameters on the web
60RISK
open
ReferênciaVexDay Proof
Adobe Photoshop CS2 / CS3 - '.bmp' Local Buffer Overflow
CVE-2007-2244localwindows
Multiple buffer overflows in Adobe Photoshop CS2 and CS3, Illustrator CS3, and GoLive 9 allow user-assisted remote attac
35RISK
open
Referência
CVE-2018-25415
AiOPMSD Final 1.0.0 SQL Injection via director Parameter
41RISK
open
Referência
CVE-2018-25414
AiOPMSD Final 1.0.0 SQL Injection via actor.php
41RISK
open
ReferênciaVexDay Proof
Mozilla Firefox 3.0.6 - BODY onload Remote Crash
CVE-2009-0071dosmultiple
Mozilla Firefox 3.0.5 and earlier 3.0.x versions, when designMode is enabled, allows remote attackers to cause a denial
23RISK
open
Referência
CVE-2012-2590
Multiple cross-site scripting (XSS) vulnerabilities in ESCON SupportPortal Professional Edition 3.0 allow remote attacke
23RISK
open
Referência
CVE-2012-2591
Multiple cross-site scripting (XSS) vulnerabilities in EmailArchitect Email Server 10.0 and 10.0.0.3 allow remote attack
23RISK
open
Referência
CVE-2020-8654
An issue was discovered in EyesOfNetwork 5.3. An authenticated web user with sufficient privileges could abuse the AutoD
60RISK
open
Referência
CVE-2020-8654
An issue was discovered in EyesOfNetwork 5.3. An authenticated web user with sufficient privileges could abuse the AutoD
60RISK
open
previouspage 510 / 748next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.