Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,837cataloged exploits
35,811CVEs with public exploitation
24,695lab-tested
22,549 exploits
Referência
CVE-2011-5165
Stack-based buffer overflow in Free MP3 CD Ripper 1.1, 2.6 and earlier, when converting a file, allows user-assisted rem
50RISK
open
Referência
CVE-2010-4283
PHP remote file inclusion vulnerability in extras/pandora_diag.php in Pandora FMS before 3.1.1 allows remote attackers t
23RISK
open
Referência
CVE-2018-1002005
These vulnerabilities require administrative privileges to exploit. There is an XSS vulnerability in bft_list.html.php:4
23RISK
open
Referência
CVE-2014-2587
SQL injection vulnerability in jsp/reports/ReportsAudit.jsp in McAfee Asset Manager 6.6 allows remote authenticated user
23RISK
open
Referência
CVE-2014-2587
SQL injection vulnerability in jsp/reports/ReportsAudit.jsp in McAfee Asset Manager 6.6 allows remote authenticated user
23RISK
open
Referência
CVE-2017-11309
Buffer overflow in the SoftConsole client in Avaya IP Office before 10.1.1 allows remote servers to execute arbitrary co
23RISK
open
Referência
CVE-2017-11309
Buffer overflow in the SoftConsole client in Avaya IP Office before 10.1.1 allows remote servers to execute arbitrary co
23RISK
open
Referência
CVE-2009-4206
SQL injection vulnerability in admin.link.modify.php in Million Dollar Text Links 1.0 and earlier allows remote attacker
23RISK
open
Referência
CVE-2020-8495
In Kronos Web Time and Attendance (webTA) 3.8.x and later 3.x versions before 4.0, the com.threeis.webta.H491delegate se
41RISK
open
Referência
CVE-2014-3848
The iMember360 plugin before 3.9.001 for WordPress does not properly restrict access, which allows remote attackers to o
23RISK
open
Referência
CVE-2014-3848
The iMember360 plugin before 3.9.001 for WordPress does not properly restrict access, which allows remote attackers to o
23RISK
open
Referência
CVE-2006-5521
PHP remote file inclusion vulnerability in DNS/RR.php in Net_DNS 0.03 and earlier allows remote attackers to execute arb
23RISK
open
Referência
CVE-2009-4208
SQL injection vulnerability in the os_news module in Open-school (OS) 1.0 allows remote attackers to execute arbitrary S
23RISK
open
ReferênciaVexDay Proof
wbstreet 1.0 - SQL Injection / File Disclosure
CVE-2008-5956webappsphp
Wbstreet (aka PHPSTREET Webboard) 1.0 stores sensitive information under the web root with insufficient access control,
23RISK
open
Referência
CVE-2013-4865
Cross-site request forgery (CSRF) vulnerability in upgrade_step2.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows
23RISK
open
ReferênciaVexDay Proof
Anthologia 0.5.2 - 'index.php?ads_file' Remote File Inclusion
CVE-2007-2094webappsphp
PHP remote file inclusion vulnerability in index.php in Anthologia 0.5.2 allows remote attackers to execute arbitrary PH
23RISK
open
ReferênciaVexDay Proof
PHP-Generics 1.0.0 Beta - Multiple Remote File Inclusions
CVE-2007-2346webappsphp
Multiple PHP remote file inclusion vulnerabilities in PHP-Generics 1.0 beta allow remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
Glossword 1.8.1 - 'custom_vars.php' Remote File Inclusion
CVE-2007-2743webappsphp
PHP remote file inclusion vulnerability in custom_vars.php in GlossWord 1.8.1 allows remote attackers to execute arbitra
23RISK
open
ReferênciaVexDay Proof
PHP Real Estate Classifieds - Remote File Inclusion
CVE-2007-3160webappsphp
PHP remote file inclusion vulnerability in admin/header.php in PHP Real Estate Classifieds Premium Plus allows remote at
23RISK
open
ReferênciaVexDay Proof
CounterPath X-Lite 3.x - SIP phone Remote Denial of Service
CVE-2007-4382doswindows
CounterPath X-Lite 3.0 34025, and possibly eyeBeam, allows remote attackers to cause a denial of service (device crash)
23RISK
open
ReferênciaVexDay Proof
Joomla! 1.5.x - 'Token' Remote Admin Change Password
CVE-2008-3681webappsphp
components/com_user/models/reset.php in Joomla! 1.5 through 1.5.5 does not properly validate reset tokens, which allows
23RISK
open
ReferênciaVexDay Proof
addalink 4 - 'category_id' SQL Injection
CVE-2008-4145webappsphp
SQL injection vulnerability in user_read_links.php in Addalink 1.0 beta 4 and earlier, when magic_quotes_gpc is disabled
23RISK
open
Referência
CVE-2012-6644
Multiple cross-site scripting (XSS) vulnerabilities in ClipBucket 2.6 allow remote attackers to inject arbitrary web scr
23RISK
open
Referência
CVE-2018-0715
Cross-site scripting vulnerability in QNAP Photo Station versions 5.7.0 and earlier could allow remote attackers to inje
23RISK
open
Referência
CVE-2026-17530
AstrBotDevs AstrBot Subagent astr_agent_tool_exec.py _build_handoff_toolset authorization
33RISK
open
Referência
CVE-2019-3474
Path traversal vulnerability in Filr web application
33RISK
open
Referência
CVE-2026-17529
AstrBotDevs AstrBot astr_main_agent.py authorization
33RISK
open
ReferênciaVexDay Proof
webid 0.5.4 - Multiple Vulnerabilities
CVE-2008-7117webappsphp
eledicss.php in WeBid auction script 0.5.4 allows remote attackers to modify arbitrary cascading style sheets (CSS) file
23RISK
open
Referência
CVE-2016-4004
Directory traversal vulnerability in Dell OpenManage Server Administrator (OMSA) 8.2 allows remote authenticated adminis
23RISK
open
Referência
CVE-2026-5813
PHPGurukul Online Course Registration check_availability.php sql injection
33RISK
open
previouspage 583 / 752next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.