Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,772cataloged exploits
35,760CVEs with public exploitation
24,695lab-tested
22,523 exploits
ReferênciaVexDay Proof
KingSoft - 'UpdateOcx2.dll SetUninstallName()' Heap Overflow (PoC)
CVE-2008-1307doswindows
Heap-based buffer overflow in the KUpdateObj2 Class ActiveX control in UpdateOcx2.dll in Beijing KingSoft Antivirus Onli
28RISK
open
Referência
CVE-2017-13861
An issue was discovered in certain Apple products. iOS before 11.2 is affected. tvOS before 11.2 is affected. watchOS be
43RISK
open
Referência
CVE-2013-6987
Multiple directory traversal vulnerabilities in the FileBrowser components in Synology DiskStation Manager (DSM) before
28RISK
open
ReferênciaVexDay Proof
Pluck CMS 4.6.2 - 'langpref' Local File Inclusion
CVE-2009-1765webappsphp
Multiple directory traversal vulnerabilities in pluck 4.6.2, when register_globals is enabled, allow remote attackers to
28RISK
open
Referência
CVE-2017-14243
An authentication bypass vulnerability on UTStar WA3002G4 ADSL Broadband Modem WA3002G4-0021.01 devices allows attackers
28RISK
open
Referência
CVE-2014-9463
functions_vbseo_hook.php in the VBSEO module for vBulletin allows remote authenticated users to execute arbitrary code v
28RISK
open
Referência
CVE-2009-2635
PHP remote file inclusion vulnerability in toolbar_ext.php in the RealEstateManager (com_realestatemanager) component 1.
23RISK
open
Referência
CVE-2009-2637
PHP remote file inclusion vulnerability in toolbar_ext.php in the BookLibrary (com_booklibrary) component 1.5.2.4 Basic
23RISK
open
Referência
CVE-2017-8982
A Remote Authentication Restriction Bypass vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E05
28RISK
open
Referência
CVE-2014-8791
project/register.php in Tuleap before 7.7, when sys_create_project_in_one_step is disabled, allows remote authenticated
43RISK
open
Referência
CVE-2018-6409
An issue was discovered in Appnitro MachForm before 4.2.3. The module in charge of serving stored files gets the path fr
28RISK
open
Referência
CVE-2008-1160
ZyXEL ZyWALL 1050 has a hard-coded password for the Quagga and Zebra processes that is not changed when it is set by a u
28RISK
open
Referência
CVE-2017-3807
A vulnerability in Common Internet Filesystem (CIFS) code in the Clientless SSL VPN functionality of Cisco ASA Software,
28RISK
open
Referência
CVE-2018-5511
On F5 BIG-IP 13.1.0-13.1.0.3 or 13.0.0, when authenticated administrative users execute commands in the Traffic Manageme
28RISK
open
Referência
CVE-2018-5511
On F5 BIG-IP 13.1.0-13.1.0.3 or 13.0.0, when authenticated administrative users execute commands in the Traffic Manageme
28RISK
open
Referência
CVE-2016-10718
Brave Browser before 0.13.0 allows a tab to close itself even if the tab was not opened by a script, resulting in denial
28RISK
open
Referência
CVE-2018-0891
ChakraCore, and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT
28RISK
open
Referência
CVE-2025-8356
Path Traversal leading to RCE
53RISK
open
Referência
CVE-2018-7702
SecurEnvoy SecurMail before 9.2.501 allows remote attackers to spoof transmission of arbitrary e-mail messages, resend e
28RISK
open
Referência
CVE-2010-1300
SQL injection vulnerability in index.php in Yamamah (aka Dove Photo Album) 1.00 allows remote attackers to execute arbit
23RISK
open
Referência
CVE-2007-2586
The FTP Server in Cisco IOS 11.3 through 12.4 does not properly check user authorization, which allows remote attackers
28RISK
open
Referência
CVE-2013-5573
Cross-site scripting (XSS) vulnerability in the default markup formatter in Jenkins 1.523 allows remote attackers to inj
23RISK
open
Referência
CVE-2025-34040
Seeyon Zhiyuan OA System Path Traversal File Upload
68RISK
open
Referência
CVE-2019-7193
CVE-2019-7193CRITICALunder attackransomware
This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the
83RISK
open
Referência
CVE-2011-2443
Multiple buffer overflows in Adobe Photoshop Elements 8.0 and earlier allow remote attackers to cause a denial of servic
28RISK
open
Referência
CVE-2016-0165
CVE-2016-0165HIGHunder attack
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, W
76RISK
open
Referência
CVE-2017-2547
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The
28RISK
open
Referência
CVE-2017-16944
The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to cause a denial
35RISK
open
Referência
CVE-2024-11972
Hunk Companion < 1.9.0 - Unauthenticated Plugin Installation
75RISK
open
Referência
CVE-2018-11742
NEC Univerge Sv9100 WebPro 6.00.00 devices have Cleartext Password Storage in the Web UI.
28RISK
open
previouspage 548 / 751next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.