Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,765cataloged exploits
35,760CVEs with public exploitation
24,695lab-tested
22,492 exploits
Referência
CVE-2009-3343
SQL injection vulnerability in details.asp in HotWeb Rentals allows remote attackers to execute arbitrary SQL commands v
23RISK
open
Referência
CVE-2023-41425
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RISK
open
Referência
CVE-2009-2400
SQL injection vulnerability in the PHP (com_php) component for Joomla! allows remote attackers to execute arbitrary SQL
23RISK
open
Referência
CVE-2009-2402
SQL injection vulnerability in index.php in the forum module in PHPEcho CMS 2.0-rc3 allows remote attackers to execute a
23RISK
open
Referência
CVE-2009-2423
SQL injection vulnerability in category.php in Ebay Clone 2009 allows remote attackers to execute arbitrary SQL commands
23RISK
open
Referência
CVE-2019-19609
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RISK
open
ReferênciaVexDay Proof
Ajax File Browser 3b - 'settings.inc.php?approot' Remote File Inclusion
CVE-2007-4921webappsphp
PHP remote file inclusion vulnerability in _includes/settings.inc.php in Ajax File Browser 3 Beta allows remote attacker
35RISK
open
ReferênciaVexDay Proof
KwsPHP Module jeuxflash 1.0 - 'id' SQL Injection
CVE-2007-4922webappsphp
SQL injection vulnerability in play.php in the jeuxflash 1.0 module for KwsPHP allows remote authenticated users to exec
23RISK
open
ReferênciaVexDay Proof
Joomla! Component Joomlaradio 5.0 - Remote File Inclusion
CVE-2007-4923webappsphp
PHP remote file inclusion vulnerability in admin.joomlaradiov5.php in the Joomla Radio 5 (com_joomlaradiov5) component f
35RISK
open
ReferênciaVexDay Proof
phpFFL 1.24 - 'PHPFFL_FILE_ROOT' Remote File Inclusion
CVE-2007-4934webappsphp
Multiple PHP remote file inclusion vulnerabilities in phpFFL 1.24 allow remote attackers to execute arbitrary PHP code v
28RISK
open
Referência
CVE-2026-16083
Sipeed PicoClaw LINE Webhook line.go webhook.ParseRequest authentication replay
33RISK
open
Referência
CVE-2026-16082
Sipeed PicoClaw pipeline_execute.go ExecTool.executeRun toctou
33RISK
open
Referência
CVE-2026-16081
Sipeed PicoClaw auth.go cross-site request forgery
33RISK
open
Referência
CVE-2026-16077
AstrBotDevs AstrBot Filesystem Computer-Use Tool fs.py _normalize_rw_path link following
33RISK
open
Referência
CVE-2026-16076
AstrBotDevs AstrBot API open_api.py OpenApiRoute.chat_send authentication spoofing
33RISK
open
Referência
CVE-2026-16075
AstrBotDevs AstrBot session-listing Endpoint open_api.py OpenApiRoute.get_chat_sessions authorization
33RISK
open
Referência
CVE-2016-0710
Multiple SQL injection vulnerabilities in the User Manager service in Apache Jetspeed before 2.3.1 allow remote attacker
50RISK
open
Referência
CVE-2019-8953
The HAProxy package before 0.59_16 for pfSense has XSS via the desc (aka Description) or table_actionsaclN parameter, re
35RISK
open
Referência
CVE-2019-13272
CVE-2019-13272HIGHunder attack
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISK
open
Referência
CVE-2017-1000486
CVE-2017-1000486CRITICALunder attack
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
100RISK
open
Referência
CVE-2022-31470
An XSS vulnerability in the index_mobile_changepass.hsp reset-password section of Axigen Mobile WebMail before 10.2.3.12
50RISK
open
Referência
CVE-2009-3446
SQL injection vulnerability in the MyRemote Video Gallery (com_mytube) component 1.0 Beta for Joomla! allows remote atta
23RISK
open
Referência
CVE-2010-1622
SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote at
35RISK
open
Referência
CVE-2019-13068
public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the
35RISK
open
Referência
CVE-2011-4075
The masort function in lib/functions.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to execute arbitrary
50RISK
open
Referência
CVE-2025-40552
SolarWinds Web Help Desk Authentication Bypass Vulnerability
75RISK
open
Referência
CVE-2011-0522
The StripTags function in (1) the USF decoder (modules/codec/subtitles/subsdec.c) and (2) the Text decoder (modules/code
35RISK
open
Referência
CVE-2014-9308
Unrestricted file upload vulnerability in inc/amfphp/administration/banneruploaderscript.php in the WP EasyCart (aka Wor
50RISK
open
Referência
CVE-2014-9308
Unrestricted file upload vulnerability in inc/amfphp/administration/banneruploaderscript.php in the WP EasyCart (aka Wor
50RISK
open
Referência
CVE-2013-1408
Multiple SQL injection vulnerabilities in the Wysija Newsletters plugin before 2.2.1 for WordPress allow remote authenti
23RISK
open
previouspage 536 / 750next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.