Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,772cataloged exploits
35,760CVEs with public exploitation
24,695lab-tested
22,523 exploits
Referência
CVE-2019-9650
An XSS issue was discovered in upcoming_events.php in the Upcoming Events plugin before 1.33 for MyBB via a crafted name
23RISK
open
Referência
CVE-2019-9650
An XSS issue was discovered in upcoming_events.php in the Upcoming Events plugin before 1.33 for MyBB via a crafted name
23RISK
open
ReferênciaVexDay Proof
V-Webmail 1.6.4 - 'pear_dir' Remote File Inclusion
CVE-2006-2665webappsphp
PHP remote file inclusion vulnerability in includes/mailaccess/pop3/core.php in V-Webmail 1.3 allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
AGTC MyShop 3.2 - Insecure Cookie Handling
CVE-2009-1549webappsphp
AGTC MyShop 3.2b allows remote attackers to bypass authentication and obtain administrative access setting the log_accep
23RISK
open
Referência
CVE-2016-3963
Siemens SCALANCE S613 allows remote attackers to cause a denial of service (web-server outage) via traffic to TCP port 4
23RISK
open
ReferênciaVexDay Proof
asg-sentry 7.0.0 - Multiple Vulnerabilities
CVE-2008-1322dosmultiple
The File Check Utility (fcheck.exe) in ASG-Sentry Network Manager 7.0.0 and earlier allows remote attackers to cause a d
23RISK
open
Referência
CVE-2016-6896
Directory traversal vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPre
35RISK
open
Referência
CVE-2010-4617
Directory traversal vulnerability in the JotLoader (com_jotloader) component 2.2.1 for Joomla! allows remote attackers t
38RISK
open
Referência
CVE-2016-10034
The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.
35RISK
open
Referência
CVE-2010-4617
Directory traversal vulnerability in the JotLoader (com_jotloader) component 2.2.1 for Joomla! allows remote attackers t
38RISK
open
Referência
CVE-2012-4253
Multiple directory traversal vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to read arbitrary files via a
38RISK
open
Referência
CVE-2017-1000499
phpMyAdmin versions 4.7.x (prior to 4.7.6.1/4.7.7) are vulnerable to a CSRF weakness. By deceiving a user to click on a
23RISK
open
Referência
CVE-2018-8002
In PoDoFo 0.9.5, there exists an infinite loop vulnerability in PdfParserObject::ParseFileComplete() in PdfParserObject.
23RISK
open
Referência
CVE-2017-9640
A Path Traversal issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web prior to 6.5;
23RISK
open
Referência
CVE-2006-4131
Multiple buffer overflows in ArcSoft MMS Composer 1.5.5.6, and possibly earlier, and 2.0.0.13, and possibly earlier, all
23RISK
open
Referência
CVE-2010-4056
solid.exe in IBM solidDB 6.5.0.3 and earlier does not properly perform a recursive call to a certain function upon recei
23RISK
open
Referência
CVE-2017-11664
The _WM_SetupMidiEvent function in internal_midi.c:2122 in WildMIDI 0.4.2 can cause a denial of service (invalid memory
23RISK
open
Referência
CVE-2015-3313
SQL injection vulnerability in WordPress Community Events plugin before 1.4.
23RISK
open
Referência
CVE-2006-2152
PHP remote file inclusion vulnerability in admin/addentry.php in phpBB Advanced Guestbook 2.4.0 and earlier, when regist
23RISK
open
Referência
CVE-2017-13262
In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing length decrement operation. Th
23RISK
open
Referência
CVE-2017-13262
In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing length decrement operation. Th
23RISK
open
Referência
CVE-2018-8532
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious
28RISK
open
Referência
CVE-2012-0276
Multiple heap-based buffer overflows in XnView before 1.99 allow remote attackers to cause a denial of service (applicat
23RISK
open
Referência
CVE-2012-0276
Multiple heap-based buffer overflows in XnView before 1.99 allow remote attackers to cause a denial of service (applicat
23RISK
open
ReferênciaVexDay Proof
SysInfo 1.21 - 'sysinfo.cgi' Remote Command Execution
CVE-2006-1831webappscgi
Direct static code injection vulnerability in sysinfo.cgi in sysinfo 1.21 and possibly other versions before 2.25 allows
23RISK
open
ReferênciaVexDay Proof
Nokia N95-8 browser - 'setAttributeNode' Method Crash
CVE-2009-0649doshardware
The web browser in Symbian OS on the Nokia N95 cell phone allows remote attackers to cause a denial of service (crash) v
23RISK
open
Referência
CVE-2010-1930
Off-by-one error in Novell iManager 2.7, 2.7.3, and 2.7.3 FTF2 allows remote attackers to cause a denial of service (dae
23RISK
open
Referência
CVE-2010-4300
Heap-based buffer overflow in the dissect_ldss_transfer function (epan/dissectors/packet-ldss.c) in the LDSS dissector i
28RISK
open
ReferênciaVexDay Proof
Simple Web Content Management System - SQL Injection
CVE-2007-0093webappsphp
SQL injection vulnerability in page.php in Simple Web Content Management System allows remote attackers to execute arbit
23RISK
open
ReferênciaVexDay Proof
ASPapp Knowledge Base - 'CatId' SQL Injection (1)
CVE-2008-1430webappsasp
SQL injection vulnerability in links.asp in ASPapp allows remote attackers to execute arbitrary SQL commands via the Cat
23RISK
open
previouspage 552 / 751next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.