Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,866cataloged exploits
35,812CVEs with public exploitation
24,695lab-tested
22,549 exploits
ReferênciaVexDay Proof
EasyNews 40tr - SQL Injection / Cross-Site Scripting / Local File Inclusion
CVE-2008-1651webappsphp
Directory traversal vulnerability in admin/login.php in EasyNews 4.0 allows remote attackers to include and execute arbi
23RISK
open
Referência
CVE-2018-14592
The CWJoomla CW Article Attachments PRO extension before 2.0.7 and CW Article Attachments FREE extension before 1.0.6 fo
23RISK
open
ReferênciaVexDay Proof
DBGuestbook 1.1 - 'dbs_base_path' Remote File Inclusion
CVE-2007-1165webappsphp
Multiple PHP remote file inclusion vulnerabilities in DBGuestbook 1.1 allow remote attackers to execute arbitrary PHP co
23RISK
open
ReferênciaVexDay Proof
phpTrafficA 1.4.2 - 'pageid' SQL Injection
CVE-2007-3425webappsphp
Directory traversal vulnerability in index.php in phpTrafficA 1.4.2 and earlier allows remote attackers to include arbit
23RISK
open
ReferênciaVexDay Proof
gapicms 9.0.2 - 'dirDepth' Remote File Inclusion
CVE-2008-3183webappsphp
PHP remote file inclusion vulnerability in ktmlpro/includes/ktedit/toolbar.php in gapicms 9.0.2 allows remote attackers
23RISK
open
ReferênciaVexDay Proof
HIOX Random Ad 1.3 - Remote File Inclusion
CVE-2008-3401webappsphp
PHP remote file inclusion vulnerability in hioxRandomAd.php in HIOX Random Ad (HRA) 1.3 allows remote attackers to execu
23RISK
open
ReferênciaVexDay Proof
Hotel Reservation System - 'city.asp' Blind SQL Injection
CVE-2008-4204webappsasp
SQL injection vulnerability in city.asp in SoftAcid Hotel Reservation System (HRS) allows remote attackers to execute ar
23RISK
open
Referência
CVE-2006-5192
PHP remote file inclusion vulnerability in includes/footer.php in phpGreetz 0.99 and earlier allows remote attackers to
23RISK
open
Referência
CVE-2020-25015
A specific router allows changing the Wi-Fi password remotely. Genexis Platinum 4410 V2-1.28, a compact router generally
23RISK
open
Referência
CVE-2021-31762
Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to create a privileged user through Webmin's add users fea
23RISK
open
Referência
CVE-2009-4224
Multiple PHP remote file inclusion vulnerabilities in SweetRice 0.5.4, 0.5.3, and earlier allow remote attackers to exec
23RISK
open
Referência
CVE-2013-5954
Multiple cross-site request forgery (CSRF) vulnerabilities in OpenX 2.8.11 and earlier allow remote attackers to hijack
23RISK
open
Referência
CVE-2018-18755
K-iwi Framework 1775 has SQL Injection via the admin/user/group/update user_group_id parameter or the admin/user/user/up
23RISK
open
Referência
CVE-2018-18755
K-iwi Framework 1775 has SQL Injection via the admin/user/group/update user_group_id parameter or the admin/user/user/up
23RISK
open
ReferênciaVexDay Proof
KDPics 1.11 - 'exif.php?lib_path' Remote File Inclusion
CVE-2006-6516webappsphp
Multiple PHP remote file inclusion vulnerabilities in KDPics 1.16 and earlier allow remote attackers to execute arbitrar
23RISK
open
ReferênciaVexDay Proof
CzarNews 1.14 - 'tpath' Remote File Inclusion
CVE-2005-0859webappsphp
PHP remote file inclusion vulnerability in CzarNews 1.13b allows remote attackers to execute arbitrary PHP code via the
28RISK
open
ReferênciaVexDay Proof
FlashFXP 3.4.0 build 1145 - Remote Buffer Overflow (Denial of Service) (PoC)
CVE-2007-0825doswindows
FlashFXP 3.4.0 build 1145 allows remote servers to cause a denial of service (CPU consumption) via a response to a PWD c
23RISK
open
ReferênciaVexDay Proof
TorrentTrader Classic 1.07 - Multiple Vulnerabilities
CVE-2007-5311webappsphp
Directory traversal vulnerability in backend/admin-functions.php in TorrentTrader Classic Edition 1.07 allows remote att
23RISK
open
Referência
CVE-2010-1875
Directory traversal vulnerability in the Real Estate Property (com_properties) component 3.1.22-03 for Joomla! allows re
43RISK
open
Referência
CVE-2020-13228
An issue was discovered in Sysax Multi Server 6.90. There is reflected XSS via the /scgi sid parameter.
23RISK
open
Referência
CVE-2023-0916
SourceCodester Auto Dealer Management System Users.php access control
33RISK
open
Referência
CVE-2014-3704
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RISK
open
Referência
CVE-2023-31902
RPA Technology Mobile Mouse 3.6.0.4 is vulnerable to Remote Code Execution (RCE).
63RISK
open
Referência
CVE-2018-25115
D-Link DIR-110/412/600/615/645/815 RCE via service.cgi
48RISK
open
Referência
CVE-2018-25115
D-Link DIR-110/412/600/615/645/815 RCE via service.cgi
48RISK
open
Referência
CVE-2016-8024
Improper neutralization of CRLF sequences in HTTP headers vulnerability in Intel Security VirusScan Enterprise Linux (VS
23RISK
open
Referência
CVE-2018-10575
An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15. Hardcoded credentia
23RISK
open
Referência
CVE-2014-3704
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RISK
open
ReferênciaVexDay Proof
evilboard 0.1a - SQL Injection / Cross-Site Scripting
CVE-2008-0155webappsphp
Cross-site scripting (XSS) vulnerability in index.php in EvilBoard 0.1a (Alpha) allows remote attackers to inject arbitr
23RISK
open
ReferênciaVexDay Proof
PGOSD - '/misc/function.php3' Remote File Inclusion
CVE-2006-5543webappsphp
PHP remote file inclusion vulnerability in misc/function.php3 in PHP Generator of Object SQL Database (PGOSD), when regi
23RISK
open
previouspage 588 / 752next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.