Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,724cataloged exploits
35,724CVEs with public exploitation
24,695lab-tested
22,429 exploits
Referência
CVE-2023-1730
SupportCandy < 3.1.5 - Unauthenticated SQLi
75RISK
open
Referência
CVE-2018-1000094
CMS Made Simple version 2.2.5 contains a Remote Code Execution vulnerability in File Manager that can result in Allows a
50RISK
open
ReferênciaVexDay Proof
Winamp 5.551 - MAKI Parsing Integer Overflow
CVE-2009-1831localwindows
The Nullsoft Modern Skins Support module (gen_ff.dll) in Nullsoft Winamp before 5.552 allows remote attackers to execute
50RISK
open
Referência
CVE-2012-5223
The proc_deutf function in includes/functions_vbseocp_abstract.php in vBSEO 3.5.0, 3.5.1, 3.5.2, 3.6.0, and earlier allo
50RISK
open
Referência
CVE-2021-25156
A remote arbitrary directory create vulnerability was discovered in some Aruba Instant Access Point (IAP) products in ve
35RISK
open
Referência
CVE-2022-29548
A reflected XSS issue exists in the Management Console of several WSO2 products. This affects API Manager 2.2.0, 2.5.0,
60RISK
open
Referência
CVE-2012-4924
Buffer overflow in the CxDbgPrint function in the ipswcom.dll ActiveX component 1.0.0.1 for ASUS Net4Switch 1.0.0020 all
50RISK
open
ReferênciaVexDay Proof
Cisco Phone 7940 - Remote Denial of Service
CVE-2007-5583doshardware
Cisco IP Phone 7940 with firmware P0S3-08-7-00 allows remote attackers to cause a denial of service ("486 Busy" response
23RISK
open
ReferênciaVexDay Proof
Chilkat Crypt - ActiveX Arbitrary File Creation/Execution
CVE-2008-5002remotewindows
Insecure method vulnerability in the ChilkatCrypt2.ChilkatCrypt2.1 ActiveX control (ChilkatCrypt2.dll 4.3.2.1) in Chilka
50RISK
open
Referência
CVE-2016-1096
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsof
35RISK
open
Referência
CVE-2016-1096
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsof
35RISK
open
Referência
CVE-2016-6816
The code in Apache Tomcat 9.0.0.M1 to 9.0.0.M11, 8.5.0 to 8.5.6, 8.0.0.RC1 to 8.0.38, 7.0.0 to 7.0.72, and 6.0.0 to 6.0.
35RISK
open
Referência
CVE-2023-2068
File Manager Advanced Shortcode <= 2.3.2 - Unauthenticated Remote Code Execution through shortcode
50RISK
open
Referência
CVE-2023-2068
File Manager Advanced Shortcode <= 2.3.2 - Unauthenticated Remote Code Execution through shortcode
50RISK
open
Referência
CVE-2016-3087
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, a
60RISK
open
Referência
CVE-2009-3857
Buffer overflow in Softonic International SciTE 1.72 allows user-assisted remote attackers to cause a denial of service
23RISK
open
Referência
CVE-2019-17240
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many
40RISK
open
Referência
CVE-2019-17240
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many
40RISK
open
Referência
CVE-2009-3863
Buffer overflow in the gxmim1.dll ActiveX control in Novell Groupwise Client 7.0.3.1294 allows remote attackers to cause
23RISK
open
Referência
CVE-2013-3660
CVE-2013-3660HIGHunder attack
The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windo
98RISK
open
Referência
CVE-2023-4521
Import XML and RSS Feeds < 2.1.5 - Unauthenticated RCE
75RISK
open
Referência
CVE-2018-7286
An issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asteris
35RISK
open
Referência
CVE-2018-2791
Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). Supported
50RISK
open
Referência
CVE-2009-3970
SQL injection vulnerability in index.php in PHP Dir Submit (aka WebsiteSubmitter or Submitter Script) allows remote auth
23RISK
open
ReferênciaVexDay Proof
Discloser 0.0.4 - 'fileloc' Remote File Inclusion
CVE-2006-4207webappsphp
Multiple PHP remote file inclusion vulnerabilities in Bob Jewell Discloser 0.0.4 and earlier allow remote attackers to e
23RISK
open
Referência
CVE-2009-3975
SQL injection vulnerability in index.php in Moa Gallery 1.1.0 and 1.2.0 allows remote attackers to execute arbitrary SQL
23RISK
open
Referência
CVE-2008-0610
Stack-based buffer overflow in the ClientConnection::NegotiateProtocolVersion function in vncviewer/ClientConnection.cpp
50RISK
open
Referência
CVE-2013-2683
Cisco Linksys E4200 1.0.05 Build 7 devices contain an Information Disclosure Vulnerability which allows remote attackers
28RISK
open
Referência
CVE-2009-3973
SQL injection vulnerability in index.php in Turnkey Arcade Script allows remote attackers to execute arbitrary SQL comma
23RISK
open
Referência
CVE-2023-26609
ABUS TVIP 20000-21150 devices allows remote attackers to execute arbitrary code via shell metacharacters in the /cgi-bin
53RISK
open
previouspage 514 / 748next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.