Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,724cataloged exploits
35,724CVEs with public exploitation
24,695lab-tested
22,492 exploits
Referência
CVE-2013-6225
LiveZilla 5.0.1.4 has a Remote Code Execution vulnerability
28RISK
open
Referência
CVE-2020-5515
Gila CMS 1.11.8 allows /admin/sql?query= SQL Injection.
28RISK
open
Referência
CVE-2020-5515
Gila CMS 1.11.8 allows /admin/sql?query= SQL Injection.
28RISK
open
Referência
CVE-2019-13359
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, a cwpsrv-xxx cookie allows a normal user to craft and uploa
28RISK
open
Referência
CVE-2009-4727
SQL injection vulnerability in x/login in JungleScripts Ajax Short Url Script allows remote attackers to execute arbitra
23RISK
open
Referência
CVE-2018-4935
Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds write vulnerability. Successful exp
28RISK
open
Referência
CVE-2018-4937
Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds write vulnerability. Successful exp
28RISK
open
Referência
CVE-2016-10036
Unrestricted file upload vulnerability in ui/artifact/upload in JFrog Artifactory before 4.16 allows remote attackers to
28RISK
open
Referência
CVE-2016-10036
Unrestricted file upload vulnerability in ui/artifact/upload in JFrog Artifactory before 4.16 allows remote attackers to
28RISK
open
ReferênciaVexDay Proof
HotScripts Clone Script - SQL Injection
CVE-2007-6084webappsphp
SQL injection vulnerability in software-description.php in HotScripts Clone Script allows remote attackers to execute ar
23RISK
open
Referência
CVE-2017-16642
In PHP before 5.6.32, 7.x before 7.0.25, and 7.1.x before 7.1.11, an error in the date extension's timelib_meridian hand
28RISK
open
Referência
CVE-2015-2998
SysAid Help Desk before 15.2 uses a hardcoded encryption key, which makes it easier for remote attackers to obtain sensi
43RISK
open
Referência
CVE-2020-8196
CVE-2020-8196MEDIUMunder attack
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14
68RISK
open
Referência
CVE-2018-0708
Command injection vulnerability in networking of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allo
28RISK
open
Referência
CVE-2018-0708
Command injection vulnerability in networking of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allo
28RISK
open
Referência
CVE-2013-3893
CVE-2013-3893HIGHunder attack
Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 throug
100RISK
open
Referência
CVE-2025-34036
Shenzhen TVT CCTV-DVR Command Injection
53RISK
open
Referência
CVE-2025-34036
Shenzhen TVT CCTV-DVR Command Injection
53RISK
open
Referência
CVE-2021-3278
Local Service Search Engine Management System 1.0 has a vulnerability through authentication bypass using SQL injection
28RISK
open
Referência
CVE-2017-11151
A vulnerability in synotheme_upload.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers
28RISK
open
Referência
CVE-2017-2930
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable memory corruption vulnerability due to a concurre
28RISK
open
Referência
CVE-2017-2930
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable memory corruption vulnerability due to a concurre
28RISK
open
Referência
CVE-2017-2930
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable memory corruption vulnerability due to a concurre
28RISK
open
Referência
CVE-2009-4792
SQL injection vulnerability in includes/content/member_content.php in BandSite CMS 1.1.4 allows remote attackers to exec
23RISK
open
Referência
CVE-2026-14654
SourceCodester Simple and Nice Shopping Cart Script girlsproductdeletequery.php sql injection
33RISK
open
Referência
CVE-2026-14653
SourceCodester Simple and Nice Shopping Cart Script mensproductdeletequery.php sql injection
33RISK
open
Referência
CVE-2018-11652
CSV Injection vulnerability in Nikto 2.1.6 and earlier allows remote attackers to inject arbitrary OS commands via the S
28RISK
open
Referência
CVE-2019-5893
Nelson Open Source ERP v6.3.1 allows SQL Injection via the db/utils/query/data.xml query parameter.
28RISK
open
Referência
CVE-2017-2885
An exploitable stack based buffer overflow vulnerability exists in the GNOME libsoup 2.58. A specially crafted HTTP requ
53RISK
open
Referência
CVE-2016-3645
Integer overflow in the TNEF unpacker in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); S
28RISK
open
previouspage 531 / 750next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.