Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,801cataloged exploits
35,788CVEs with public exploitation
24,695lab-tested
22,523 exploits
Referência
CVE-2015-4073
Multiple SQL injection vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote attackers to exe
23RISK
open
ReferênciaVexDay Proof
Winamp GEN_MSN Plugin - Heap Buffer Overflow (PoC)
CVE-2009-0833doswindows
Heap-based buffer overflow in gen_msn.dll in the gen_msn plugin 0.31 for Winamp 5.541 allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
ablespace 1.0 - Cross-Site Scripting / Blind SQL Injection
CVE-2009-1315webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in AbleSpace 1.0 allow remote attackers to inject arbitrary web scri
23RISK
open
ReferênciaVexDay Proof
Cyberfolio 2.0 RC1 - 'av' Remote File Inclusion
CVE-2006-5768webappsphp
Multiple PHP remote file inclusion vulnerabilities in Cyberfolio 2.0 RC1 and earlier, when register_globals is enabled,
23RISK
open
ReferênciaVexDay Proof
IP3 NetAccess < 4.1.9.6 - Arbitrary File Disclosure
CVE-2007-0883remotehardware
Directory traversal vulnerability in portalgroups/portalgroups/getfile.cgi in IP3 NetAccess before firmware 4.1.9.6 allo
23RISK
open
ReferênciaVexDay Proof
muvee autoProducer 6.1 - 'TextOut.dll' ActiveX Remote Buffer Overflow
CVE-2008-2910remotewindows
Buffer overflow in the DXTTextOutEffect ActiveX control (aka the Text-Effect DXT Filter), as distributed in TextOut.dll
23RISK
open
Referência
CVE-2020-8615
A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves a
38RISK
open
Referência
CVE-2024-51978
Authentication bypass via default password generation affecting multiple models from Brother Industries, Ltd, Toshiba Tec, and Konica Minolta, Inc.
68RISK
open
Referência
CVE-2024-51978
Authentication bypass via default password generation affecting multiple models from Brother Industries, Ltd, Toshiba Tec, and Konica Minolta, Inc.
68RISK
open
Referência
CVE-2024-51978
Authentication bypass via default password generation affecting multiple models from Brother Industries, Ltd, Toshiba Tec, and Konica Minolta, Inc.
68RISK
open
Referência
CVE-2016-4656
CVE-2016-4656HIGHunder attack
The kernel in Apple iOS before 9.3.5 allows attackers to execute arbitrary code in a privileged context or cause a denia
91RISK
open
Referência
CVE-2009-2534
RealNetworks Helix Server and Helix Mobile Server before 13.0.0 allow remote attackers to cause a denial of service (dae
23RISK
open
Referência
CVE-2006-3144
PHP remote file inclusion vulnerability in micro_cms_files/microcms-include.php in Implied By Design (IBD) Micro CMS 3.5
23RISK
open
Referência
CVE-2018-7737
In Z-BlogPHP 1.5.1.1740, there is Web Site physical path leakage, as demonstrated by admin_footer.php or admin_footer.ph
23RISK
open
Referência
CVE-2009-4992
SQL injection vulnerability in paidbanner.php in LM Starmail Paidmail 2.0 allows remote attackers to execute arbitrary S
23RISK
open
Referência
CVE-2018-7737
In Z-BlogPHP 1.5.1.1740, there is Web Site physical path leakage, as demonstrated by admin_footer.php or admin_footer.ph
23RISK
open
ReferênciaVexDay Proof
GeoVision LiveAudio - ActiveX Remote Freed-Memory Access
CVE-2009-1092remotewindows
Use-after-free vulnerability in the LIVEAUDIO.LiveAudioCtrl.1 ActiveX control in LIVEAU~1.OCX 7.0 for GeoVision DVR syst
23RISK
open
Referência
CVE-2014-3225
Absolute path traversal vulnerability in the web interface in Cobbler 2.4.x through 2.6.x allows remote authenticated us
23RISK
open
Referência
CVE-2017-17111
Posty Readymade Classifieds Script 1.0 allows an attacker to inject SQL commands via a listings.php?catid= or ads-detail
23RISK
open
Referência
CVE-2017-17111
Posty Readymade Classifieds Script 1.0 allows an attacker to inject SQL commands via a listings.php?catid= or ads-detail
23RISK
open
ReferênciaVexDay Proof
Joomla! Component JContentSubscription 1.5.8 - Multiple Remote File Inclusions
CVE-2007-5407webappsphp
Multiple PHP remote file inclusion vulnerabilities in the JContentSubscription (com_jcs) 1.5.8 component for Joomla! all
35RISK
open
Referência
CVE-2010-0718
Buffer overflow in Microsoft Windows Media Player 9 and 11.0.5721.5145 allows remote attackers to cause a denial of serv
23RISK
open
Referência
ScreenStream 3.0.15 - Denial of Service
CVE-2019-9833dosandroid
The Screen Stream application through 3.0.15 for Android allows remote attackers to cause a denial of service via many s
23RISK
open
Referência
CVE-2010-4170
The staprun runtime tool in SystemTap 1.3 does not properly clear the environment before executing modprobe, which allow
38RISK
open
ReferênciaVexDay Proof
Mms Gallery PHP 1.0 - 'id' Remote File Disclosure
CVE-2007-6323webappsphp
Multiple directory traversal vulnerabilities in MMS Gallery PHP 1.0 allow remote attackers to read arbitrary files via a
23RISK
open
ReferênciaVexDay Proof
MailEnable Professional/Enterprise 3.13 - 'Fetch' (Authenticated) Remote Buffer Overflow
CVE-2008-1276remotewindows
Multiple buffer overflows in the IMAP service (MEIMAPS.EXE) in MailEnable Professional Edition and Enterprise Edition 3.
23RISK
open
Referência
CVE-2016-5678
NUUO NVRmini 2 1.0.0 through 3.0.0 and NUUO NVRsolo 1.0.0 through 3.0.0 have hardcoded root credentials, which allows re
23RISK
open
Referência
CVE-2021-26828
CVE-2021-26828HIGHunder attack
OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and exe
83RISK
open
Referência
CVE-2020-25494
Xinuos (formerly SCO) Openserver v5 and v6 allows attackers to execute arbitrary commands via shell metacharacters in ou
35RISK
open
Referência
CVE-2012-6500
Directory traversal vulnerability in download.lib.php in Pragyan CMS 3.0 and earlier allows remote attackers to read arb
23RISK
open
previouspage 559 / 751next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.