Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,772cataloged exploits
35,760CVEs with public exploitation
24,695lab-tested
22,523 exploits
Referência
CVE-2010-3856
ld.so in the GNU C Library (aka glibc or libc6) before 2.11.3, and 2.12.x before 2.12.2, does not properly restrict use
43RISK
open
ReferênciaVexDay Proof
PNPHPBB2 < 1.2g - 'phpbb_root_path' Remote File Inclusion
CVE-2006-4968webappsphp
PHP remote file inclusion vulnerability in includes/functions_admin.php in PNphpBB 1.2g allows remote attackers to execu
23RISK
open
ReferênciaVexDay Proof
Linksys SPA941 - '\377' Character Remote Denial of Service
CVE-2007-2270doshardware
The Linksys SPA941 VoIP Phone allows remote attackers to cause a denial of service (device reboot) via a 0377 (0xff) cha
23RISK
open
ReferênciaVexDay Proof
PHP 5.2.3 'Tidy' Extension - Local Buffer Overflow
CVE-2007-3294localwindows
Multiple buffer overflows in libtidy, as used in the Tidy extension for PHP 5.2.3 and possibly other products, allow con
23RISK
open
ReferênciaVexDay Proof
Ultra Crypto Component - 'CryptoX.dll 2.0' Remote Buffer Overflow
CVE-2007-4903remotewindows
Multiple buffer overflows in a certain ActiveX control in CryptoX.dll 2.0 and earlier in the Ultra Crypto Component allo
23RISK
open
Referência
CVE-2021-41382
Plastic SCM before 10.0.16.5622 mishandles the WebAdmin server management interface.
23RISK
open
Referência
CVE-2019-2107
In ihevcd_parse_pps of ihevcd_parse_headers.c, there is a possible out of bounds write due to a missing bounds check. Th
23RISK
open
Referência
CVE-2018-1038
The Windows kernel in Windows 7 SP1 and Windows Server 2008 R2 SP1 allows an elevation of privilege vulnerability due to
23RISK
open
Referência
CVE-2019-11269
Open Redirector in spring-security-oauth2
33RISK
open
Referência
CVE-2016-8377
An issue was discovered in Fatek Automation PLC WinProladder Version 3.11 Build 14701. A stack-based buffer overflow vul
23RISK
open
Referência
CVE-2015-0097
Microsoft Excel 2007 SP3, PowerPoint 2007 SP3, Word 2007 SP3, Excel 2010 SP2, PowerPoint 2010 SP2, and Word 2010 SP2 all
35RISK
open
Referência
CVE-2021-25297
CVE-2021-25297HIGHunder attack
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi
98RISK
open
Referência
CVE-2026-32746
telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption
53RISK
open
Referência
CVE-2012-4750
A Code Execution vulnerability exists in the memcpy function when processing AMF requests in Ezhometech EzServer 7.0, wh
23RISK
open
Referência
CVE-2012-1563
Joomla! before 2.5.3 allows Admin Account Creation.
23RISK
open
Referência
CVE-2024-12342
TP-Link VN020 F3v(T) Incomplete SOAP Request WANIPConnection denial of service
41RISK
open
Referência
CVE-2017-7042
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISK
open
Referência
CVE-2015-1028
Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2730B router (rev C1) with firmware GE_1.01 allow remo
23RISK
open
Referência
CVE-2015-1028
Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2730B router (rev C1) with firmware GE_1.01 allow remo
23RISK
open
ReferênciaVexDay Proof
Mozilla Firefox 3.0.3 - User Interface Null Pointer Dereference Crash
CVE-2008-4324doswindows
The user interface event dispatcher in Mozilla Firefox 3.0.3 on Windows XP SP2 allows remote attackers to cause a denial
23RISK
open
Referência
CVE-2017-10309
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affecte
23RISK
open
ReferênciaVexDay Proof
PHPStore Car Dealers - Arbitrary File Upload
CVE-2008-6929webappsphp
Unrestricted file upload vulnerability in PHPStore Auto Classifieds allows remote authenticated users to execute arbitra
23RISK
open
Referência
CVE-2013-1606
Buffer overflow in the ubnt-streamer RTSP service on the Ubiquiti UBNT AirCam with airVision firmware before 1.1.6 allow
28RISK
open
ReferênciaVexDay Proof
WOW Web On Windows ActiveX Control 2 - Remote Code Execution
CVE-2009-0389remotewindows
Multiple insecure method vulnerabilities in the Web On Windows (WOW) ActiveX control in WOW ActiveX 2 allow remote attac
23RISK
open
Referência
CVE-2015-8357
Directory traversal vulnerability in the bitrix.xscan module before 1.0.4 for Bitrix allows remote authenticated users t
23RISK
open
Referência
CVE-2010-4051
The regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows c
35RISK
open
Referência
CVE-2015-8357
Directory traversal vulnerability in the bitrix.xscan module before 1.0.4 for Bitrix allows remote authenticated users t
23RISK
open
Referência
CVE-2012-5329
Buffer overflow in TYPSoft FTP Server 1.1 allows remote authenticated users to cause a denial of service (application cr
23RISK
open
Referência
CVE-2017-8311
Potential heap based buffer overflow in ParseJSS in VideoLAN VLC before 2.2.5 due to skipping NULL terminator in an inpu
23RISK
open
ReferênciaVexDay Proof
Mozilla Firefox 3.0.10 - 'KEYGEN' Remote Denial of Service
CVE-2009-1828dosmultiple
Mozilla Firefox 3.0.10 allows remote attackers to cause a denial of service (infinite loop, application hang, and memory
23RISK
open
previouspage 554 / 751next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.