Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,813cataloged exploits
35,788CVEs with public exploitation
24,695lab-tested
22,523 exploits
Referência
CVE-2015-0555
Buffer overflow in the XnsSdkDeviceIpInstaller.ocx ActiveX control in Samsung iPOLiS Device Manager 1.12.2 allows remote
23RISK
open
Referência
CVE-2025-15501
Sangfor Operation and Maintenance Management System getCmd WriterHandle.getCmd os command injection
48RISK
open
Referência
CVE-2023-0744
Improper Access Control in answerdev/answer
48RISK
open
Referência
CVE-2010-5022
SQL injection vulnerability in the JExtensions JE Story Submit (com_jesubmit) component 1.4 for Joomla! allows remote at
23RISK
open
ReferênciaVexDay Proof
phpChess Community Edition 2.0 - Multiple Remote File Inclusions
CVE-2007-2677webappsphp
Multiple PHP remote file inclusion vulnerabilities in phpChess Community Edition 2.0 allow remote attackers to execute a
23RISK
open
ReferênciaVexDay Proof
LightBlog 9.5 - 'cp_upload_image.php' Arbitrary File Upload
CVE-2008-0632webappsphp
Unrestricted file upload vulnerability in cp_upload_image.php in LightBlog 9.5 allows remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
VBA32 Personal AntiVirus 3.12.8.x - Malformed Archive Denial of Service
CVE-2008-5667doswindows
The scanning engine in VirusBlokAda VBA32 Personal Antivirus 3.12.8.x allows remote attackers to cause a denial of servi
23RISK
open
Referência
CVE-2010-5023
SQL injection vulnerability in index.asp in Digital Interchange Calendar 5.8.5 allows remote attackers to execute arbitr
23RISK
open
Referência
CVE-2012-2919
Directory traversal vulnerability in Upload/engine.php in Chevereto 1.9.1 allows remote attackers to determine the exist
23RISK
open
Referência
CVE-2010-0759
Directory traversal vulnerability in plugins/system/cdscriptegrator/libraries/highslide/js/jsloader.php in the Core Desi
43RISK
open
Referência
CVE-2019-6192
A potential vulnerability has been reported in Lenovo Power Management Driver versions prior to 1.67.17.48 leading to a
33RISK
open
Referência
CVE-2018-7705
Directory traversal vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote authenticated users to read e-mai
23RISK
open
Referência
CVE-2022-39195
A cross-site scripting (XSS) vulnerability in the LISTSERV 17 web interface allows remote attackers to inject arbitrary
48RISK
open
Referência
CVE-2013-1636
Cross-site scripting (XSS) vulnerability in open-flash-chart.swf in Open Flash Chart (aka Open-Flash Chart), as used in
23RISK
open
Referência
CVE-2013-1636
Cross-site scripting (XSS) vulnerability in open-flash-chart.swf in Open Flash Chart (aka Open-Flash Chart), as used in
23RISK
open
ReferênciaVexDay Proof
WebSVN 2.0 - Cross-Site Scripting / File Handling / Code Execution
CVE-2008-5919webappsphp
Directory traversal vulnerability in rss.php in WebSVN 2.0 and earlier, when magic_quotes_gpc is disabled, allows remote
23RISK
open
Referência
CVE-2017-7043
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISK
open
Referência
CVE-2017-7039
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISK
open
Referência
CVE-2017-7040
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISK
open
ReferênciaVexDay Proof
Flexcustomer 0.0.6 - Admin Authentication Bypass / Possible PHP Code Writing
CVE-2008-6761webappsphp
Static code injection vulnerability in admin/install.php in Flexcustomer 0.0.6 might allow remote attackers to inject ar
23RISK
open
Referência
CVE-2018-1185
An issue was discovered in EMC RecoverPoint for Virtual Machines versions prior to 5.1.1, EMC RecoverPoint version 5.1.0
23RISK
open
ReferênciaVexDay Proof
Envolution 1.1.0 - 'PNSVlang' Remote Code Execution
CVE-2006-6445webappsphp
Directory traversal vulnerability in error.php in Envolution 1.1.0 and earlier allows remote attackers to include and ex
23RISK
open
ReferênciaVexDay Proof
E-GADS! 2.2.6 - 'common.php?locale' Remote File Inclusion
CVE-2007-2521webappsphp
PHP remote file inclusion vulnerability in common.php in E-GADS! before 2.2.7 allows remote attackers to execute arbitra
23RISK
open
ReferênciaVexDay Proof
samPHPweb 4.2.2 - 'db.php' Remote File Inclusion
CVE-2008-0143webappsphp
PHP remote file inclusion vulnerability in common/db.php in samPHPweb, possibly 4.2.2 and others, as provided with SAM B
23RISK
open
Referência
CVE-2010-5033
SQL injection vulnerability in ProductList.cfm in Fusebox 5.5.1 allows remote attackers to execute arbitrary SQL command
23RISK
open
ReferênciaVexDay Proof
PHP-Fusion 7.0.2 - Blind SQL Injection
CVE-2008-1918webappsphp
SQL injection vulnerability in submit.php in PHP-Fusion 6.01.14 and 6.00.307, when magic_quotes_gpc is disabled and the
23RISK
open
Referência
CVE-2010-5034
SQL injection vulnerability in viewhistorydetail.php in iScripts EasyBiller 1.1 allows remote attackers to execute arbit
23RISK
open
Referência
CVE-2009-4451
Unrestricted file upload vulnerability in upper.php in kandalf upper 0.1 allows remote attackers to execute arbitrary co
23RISK
open
Referência
CVE-2009-4819
Multiple unrestricted file upload vulnerabilities in upload.php in PHPhotoalbum allow remote attackers to execute arbitr
23RISK
open
Referência
CVE-2023-4173
mooSocial mooStore index cross site scripting
43RISK
open
previouspage 569 / 751next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.