Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,724cataloged exploits
35,724CVEs with public exploitation
24,695lab-tested
22,492 exploits
Referência
CVE-2023-4547
SPA-Cart eCommerce CMS search cross site scripting
55RISK
open
Referência
CVE-2017-9232
Juju before 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3 uses a UNIX domain socket without setting appropriate pe
50RISK
open
Referência
CVE-2021-40875
Improper Access Control in Gurock TestRail versions < 7.2.0.3014 resulted in sensitive information exposure. A threat ac
50RISK
open
Referência
CVE-2009-0182
Buffer overflow in VUPlayer 2.49 and earlier allows user-assisted attackers to execute arbitrary code via a long URL in
50RISK
open
Referência
CVE-2025-48828
Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the t
75RISK
open
ReferênciaVexDay Proof
Bitweaver 2.6 - 'saveFeed()' Remote Code Execution
CVE-2009-1669webappsphp
The smarty_function_math function in libs/plugins/function.math.php in Smarty 2.6.22 allows context-dependent attackers
28RISK
open
Referência
CVE-2013-3563
Stack-based buffer overflow in db_netserver in Lianja SQL Server before 1.0.0RC5.2 allows remote attackers to cause a de
50RISK
open
ReferênciaVexDay Proof
Xitami Web Server 2.5 - 'If-Modified-Since' Remote Buffer Overflow
CVE-2007-5067remotewindows
Multiple buffer overflows in iMatix Xitami Web Server 2.5c2 allow remote attackers to execute arbitrary code via a long
60RISK
open
ReferênciaVexDay Proof
DM FileManager 3.9.2 - Authentication Bypass
CVE-2009-1741webappsphp
Multiple SQL injection vulnerabilities in login.php in DM FileManager 3.9.2, when magic_quotes_gpc is disabled, allow re
23RISK
open
ReferênciaVexDay Proof
DGNews 3.0 Beta - 'id' SQL Injection
CVE-2009-1746webappsphp
SQL injection vulnerability in berita.php in Dian Gemilang DGNews 3.0 Beta allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
Softbiz Classifieds PLUS - 'id' SQL Injection
CVE-2007-5122webappsphp
SQL injection vulnerability in store_info.php in SoftBiz Classifieds PLUS allows remote attackers to execute arbitrary S
23RISK
open
Referência
CVE-2009-3054
SQL injection vulnerability in the Artetics.com Art Portal (com_artportal) component 1.0 for Joomla! allows remote attac
23RISK
open
Referência
CVE-2009-3062
SQL injection vulnerability in message_box.php in OSI Codes PHP Live! 3.3 allows remote attackers to execute arbitrary S
23RISK
open
Referência
CVE-2009-3063
SQL injection vulnerability in the Game Server (com_gameserver) component 1.0 for Joomla! allows remote attackers to exe
23RISK
open
Referência
CVE-2009-3115
SolarWinds TFTP Server 9.2.0.111 and earlier allows remote attackers to cause a denial of service (service stop) via a c
28RISK
open
Referência
CVE-2009-3150
SQL injection vulnerability in index.php in Multi Website 1.5 allows remote attackers to execute arbitrary SQL commands
23RISK
open
Referência
CVE-2016-3976
CVE-2016-3976HIGHunder attack
Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary fil
83RISK
open
Referência
CVE-2019-17026
CVE-2019-17026HIGHunder attack
Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are
83RISK
open
ReferênciaVexDay Proof
MaxCMS 2.0 - '/inc/ajax.asp' SQL Injection
CVE-2009-1764webappsasp
SQL injection vulnerability in inc/ajax.asp in MaxCMS 2.0 allows remote attackers to execute arbitrary SQL commands via
23RISK
open
Referência
CVE-2018-15812
DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expect
50RISK
open
Referência
CVE-2019-9692
class.showtime2_image.php in CMS Made Simple (CMSMS) before 2.2.10 does not ensure that a watermark file has a standard
50RISK
open
Referência
CVE-2019-9692
class.showtime2_image.php in CMS Made Simple (CMSMS) before 2.2.10 does not ensure that a watermark file has a standard
50RISK
open
Referência
CVE-2009-3320
Cross-site scripting (XSS) vulnerability in scrivi.php in Zenas PaoLink (aka Pao-Link) 1.0 allows remote attackers to in
23RISK
open
Referência
CVE-2009-3331
Multiple PHP remote file inclusion vulnerabilities in DDL CMS 1.0 allow remote attackers to execute arbitrary PHP code v
23RISK
open
Referência
CVE-2009-3336
SQL injection vulnerability in auction_details.php in PHP Pro Bid allows remote attackers to execute arbitrary SQL comma
23RISK
open
ReferênciaVexDay Proof
Vortex Portal 1.0.42 - Remote File Inclusion
CVE-2007-5842webappsphp
Multiple PHP remote file inclusion vulnerabilities in Vortex Portal 1.0.42 allow remote attackers to execute arbitrary P
35RISK
open
Referência
CVE-2021-29003
Genexis PLATINUM 4410 2.1 P4410-V2-1.28 devices allow remote attackers to execute arbitrary code via shell metacharacter
35RISK
open
Referência
CVE-2014-9312
Unrestricted File Upload vulnerability in Photo Gallery 1.2.5.
50RISK
open
Referência
CVE-2020-1147
CVE-2020-1147HIGHunder attack
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the softwar
100RISK
open
Referência
CVE-2020-1147
CVE-2020-1147HIGHunder attack
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the softwar
100RISK
open
previouspage 526 / 750next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.