Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,813cataloged exploits
35,788CVEs with public exploitation
24,695lab-tested
22,523 exploits
Referência
CVE-2017-2464
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RISK
open
Referência
CVE-2021-22204
CVE-2021-22204MEDIUMunder attack
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISK
open
Referência
CVE-2010-2932
Buffer overflow in BarCodeWiz BarCode 3.29 ActiveX control (BarcodeWiz.dll) allows remote attackers to execute arbitrary
23RISK
open
Referência
CVE-2021-22204
CVE-2021-22204MEDIUMunder attack
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISK
open
Referência
CVE-2021-22204
CVE-2021-22204MEDIUMunder attack
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISK
open
Referência
CVE-2009-0812
Stack-based buffer overflow in BreakPoint Software Hex Workshop 4.23, 6.0.1.4603, and other 6.x and earlier versions all
23RISK
open
Referência
CVE-2009-3812
Heap-based buffer overflow in OtsAV DJ trial version 1.85.64.0, Radio trial version 1.85.64.0, TV trial version 1.85.64.
23RISK
open
Referência
CVE-2009-3812
Heap-based buffer overflow in OtsAV DJ trial version 1.85.64.0, Radio trial version 1.85.64.0, TV trial version 1.85.64.
23RISK
open
Referência
CVE-2018-6064
Type Confusion in the implementation of __defineGetter__ in V8 in Google Chrome prior to 65.0.3325.146 allowed a remote
23RISK
open
Referência
CVE-2023-5204
AI ChatBot <= 4.8.9 - Unauthenticated SQL Injection via qc_wpbo_search_response
63RISK
open
Referência
CVE-2013-4093
The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote attackers to o
23RISK
open
Referência
CVE-2016-0075
The kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 160
23RISK
open
Referência
CVE-2010-4978
Cross-site scripting (XSS) vulnerability in image/view.php in CANDID allows remote attackers to inject arbitrary web scr
23RISK
open
ReferênciaVexDay Proof
Links Directory 1.1 - 'cat_id' SQL Injection
CVE-2008-1871webappsphp
SQL injection vulnerability in links.php in Scriptsagent.com Links Directory 1.1 allows remote authenticated users to ex
23RISK
open
Referência
CVE-2017-0119
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers
28RISK
open
Referência
CVE-2010-0690
SQL injection vulnerability in index.php in CommodityRentals Video Games Rentals allows remote attackers to execute arbi
23RISK
open
Referência
CVE-2021-31673
A Dom-based Cross-site scripting (XSS) vulnerability at registration account in Cyclos 4 PRO.14.7 and before allows remo
23RISK
open
Referência
CVE-2020-11457
pfSense before 2.4.5 has stored XSS in system_usermanager_addprivs.php in the WebGUI via the descr parameter (aka full n
23RISK
open
Referência
CVE-2012-6509
Unrestricted file upload vulnerability in NetArt Media Car Portal 3.0 allows remote attackers to execute arbitrary PHP c
23RISK
open
Referência
CVE-2015-1389
Cross-site scripting (XSS) vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allows remote at
23RISK
open
Referência
CVE-2015-1389
Cross-site scripting (XSS) vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allows remote at
23RISK
open
Referência
CVE-2023-2437
UserPro <= 5.1.1 - Authentication Bypass to Administrator
63RISK
open
Referência
CVE-2018-10653
There is an XML External Entity (XXE) Processing Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 befor
23RISK
open
Referência
CVE-2009-2557
Directory traversal vulnerability in system/download.php in Admin News Tools 2.5 allows remote attackers to read arbitra
23RISK
open
Referência
CVE-2017-15639
tasks/feed/readRSS.cfm in Mura CMS before 6.2 allows attackers to bypass intended access restrictions by leveraging the
23RISK
open
Referência
CVE-2018-8718
Cross-site request forgery (CSRF) vulnerability in the Mailer Plugin 1.20 for Jenkins 2.111 allows remote authenticated
23RISK
open
ReferênciaVexDay Proof
PassWiki 0.9.16 RC3 - 'site_id' Local File Inclusion
CVE-2008-6423webappsphp
Directory traversal vulnerability in passwiki.php in PassWiki 0.9.16 RC3 and earlier allows remote attackers to read arb
23RISK
open
ReferênciaVexDay Proof
XPOZE Pro 3.05 - 'reed' SQL Injection
CVE-2008-1874webappsphp
SQL injection vulnerability in account/user/mail.html in Xpoze Pro 3.05 and earlier allows remote authenticated users to
23RISK
open
Referência
CVE-2010-4985
Cross-site scripting (XSS) vulnerability in notes.php in My Kazaam Notes Management System allows remote attackers to in
23RISK
open
Referência
CVE-2010-4986
SQL injection vulnerability in detail.php in Simple Document Management System (SDMS) allows remote attackers to execute
23RISK
open
previouspage 562 / 751next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.