Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,836cataloged exploits
35,811CVEs with public exploitation
24,695lab-tested
22,549 exploits
ReferênciaVexDay Proof
PHP JOBWEBSITE PRO - 'JobSearch3.php' SQL Injection
CVE-2008-2914webappsphp
SQL injection vulnerability in jobseekers/JobSearch3.php (aka the search module) in PHP JOBWEBSITE PRO allows remote att
23RISK
open
Referência
CVE-2019-6275
Command injection vulnerability in firmware_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attac
28RISK
open
Referência
CVE-2019-6275
Command injection vulnerability in firmware_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attac
28RISK
open
Referência
CVE-2019-6272
Command injection vulnerability in login_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attacker
28RISK
open
Referência
CVE-2010-1174
Cisco TFTP Server 1.1 allows remote attackers to cause a denial of service (daemon crash) via a crafted (1) read (aka RR
23RISK
open
Referência
CVE-2015-10141
Xdebug Remote Debugger Unauthenticated OS Command Execution
63RISK
open
Referência
CVE-2017-13847
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. The is
23RISK
open
Referência
CVE-2012-6622
Multiple cross-site scripting (XSS) vulnerabilities in fs-admin/fs-admin.php in the ForumPress WP Forum Server plugin be
23RISK
open
Referência
CVE-2017-7402
Pixie 1.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via the POST data in an admin/ind
23RISK
open
Referência
CVE-2014-8358
Huawei EC156, EC176, and EC177 USB Modem products with software before UTPS-V200R003B015D02SP07C1014 (23.015.02.07.1014)
23RISK
open
Referência
CVE-2004-1719
Multiple cross-site scripting (XSS) vulnerabilities in Merak Webmail Server 5.2.7 allow remote attackers to inject arbit
23RISK
open
Referência
CVE-2022-28598
Frappe ERPNext 12.29.0 is vulnerable to XSS where the software does not neutralize or incorrectly neutralize user-contro
23RISK
open
ReferênciaVexDay Proof
Extcalendar 2 - 'profile.php' Remote User Pass Change
CVE-2007-0681webappsphp
profile.php in ExtCalendar 2 and earlier allows remote attackers to change the passwords of arbitrary users without prov
23RISK
open
Referência
CVE-2019-11448
An issue was discovered in Zoho ManageEngine Applications Manager 11.0 through 14.0. An unauthenticated user can gain th
28RISK
open
Referência
CVE-2015-7241
XML External Entity (XXE) vulnerability in SAP Netweaver before 7.01.
28RISK
open
Referência
CVE-2011-2523
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open
ReferênciaVexDay Proof
study planner (studiewijzer) 0.15 - Remote File Inclusion
CVE-2007-1628webappsphp
Multiple PHP remote file inclusion vulnerabilities in Study planner (Studiewijzer) 0.15 and earlier, when register_globa
23RISK
open
ReferênciaVexDay Proof
PHPRaider 1.0.7 - 'PHPbb3.functions.php' Remote File Inclusion
CVE-2008-2481webappsphp
PHP remote file inclusion vulnerability in authentication/phpbb3/phpbb3.functions.php in phpRaider 1.0.7 and 1.0.7a, whe
23RISK
open
ReferênciaVexDay Proof
Dana IRC 1.3 - Remote Buffer Overflow (PoC)
CVE-2008-2922doswindows
Stack-based buffer overflow in artegic Dana IRC client 1.3 and earlier allows remote attackers to cause a denial of serv
23RISK
open
Referência
CVE-2023-54335
eXtplorer<= 2.1.14 - Authentication Bypass & Remote Code Execution (RCE)
48RISK
open
Referência
CVE-2021-28242
SQL Injection in the "evoadm.php" component of b2evolution v7.2.2-stable allows remote attackers to obtain sensitive dat
23RISK
open
Referência
CVE-2017-0300
The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2,
23RISK
open
Referência
CVE-2019-13623
In NSA Ghidra before 9.1, path traversal can occur in RestoreTask.java (from the package ghidra.app.plugin.core.archive)
23RISK
open
Referência
CVE-2013-4868
Karotz API 12.07.19.00: Session Token Information Disclosure
23RISK
open
Referência
CVE-2018-10188
phpMyAdmin 4.8.0 before 4.8.0-1 has CSRF, allowing an attacker to execute arbitrary SQL statements, related to js/db_ope
23RISK
open
Referência
CVE-2017-0100
A DCOM object in Helppane.exe in Microsoft Windows 7 SP1; Windows Server 2008 R2; Windows 8.1; Windows Server 2012 Gold
23RISK
open
Referência
CVE-2022-4117
IWS - Geo Form Fields <= 1.0 - Unauthenticated SQLi
63RISK
open
Referência
CVE-2017-4916
VMware Workstation Pro/Player contains a NULL pointer dereference vulnerability that exists in the vstor2 driver. Succes
23RISK
open
Referência
CVE-2014-9261
The sanitize function in Codoforum 2.5.1 does not properly implement filtering for directory traversal sequences, which
23RISK
open
Referência
CVE-2014-9261
The sanitize function in Codoforum 2.5.1 does not properly implement filtering for directory traversal sequences, which
23RISK
open
previouspage 581 / 752next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.