Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,866cataloged exploits
35,812CVEs with public exploitation
24,695lab-tested
22,549 exploits
Referência
CVE-2023-39115
install/aiz-uploader/upload in Campcodes Online Matrimonial Website System Script 3.3 allows XSS via a crafted SVG docum
23RISK
open
ReferênciaVexDay Proof
Pre Real Estate Listings - Arbitrary File Upload
CVE-2008-6798webappsphp
Multiple SQL injection vulnerabilities in login.php in Pre Projects Pre Real Estate Listings allow remote attackers to e
23RISK
open
ReferênciaVexDay Proof
Tribiq CMS 5.0.9a (Beta) - Insecure Cookie Handling
CVE-2008-6804webappsphp
Tribiq CMS 5.0.9a beta allows remote attackers to bypass authentication and gain administrative access by setting the CO
23RISK
open
ReferênciaVexDay Proof
XOOPS Module Tutoriais - 'viewcat.php' SQL Injection
CVE-2007-1816webappsphp
SQL injection vulnerability in viewcat.php in the Tutoriais module for Xoops allows remote attackers to execute arbitrar
23RISK
open
ReferênciaVexDay Proof
7Shop 1.1 - Arbitrary File Upload
CVE-2008-6806webappsphp
Unrestricted file upload vulnerability in includes/imageupload.php in 7Shop 1.1 and earlier allows remote attackers to e
23RISK
open
Referência
CVE-2021-34523
CVE-2021-34523CRITICALunder attackransomware
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RISK
open
ReferênciaVexDay Proof
SFS EZ Link Directory - 'cat_id' SQL Injection
CVE-2008-6808webappsphp
SQL injection vulnerability in links.php in Scripts for Sites (SFS) EZ Link Directory allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
Booking Centre 2.01 - 'HotelID' SQL Injection
CVE-2008-6809webappsphp
SQL injection vulnerability in hotel_habitaciones.php in Venalsur Booking Centre Booking System for Hotels Group 2.01 al
23RISK
open
ReferênciaVexDay Proof
Booking Centre 2.01 - Authentication Bypass
CVE-2008-6810webappsphp
Multiple SQL injection vulnerabilities in admin/checklogin.php in Venalsur Booking Centre Booking System for Hotels Grou
23RISK
open
ReferênciaVexDay Proof
Joomla! Component Ice Gallery 0.5b2 - 'catid' Blind SQL Injection
CVE-2008-6852webappsphp
SQL injection vulnerability in the Ice Gallery (com_ice) component 0.5 beta 2 for Joomla! allows remote attackers to exe
23RISK
open
Referência
CVE-2012-1921
Cross-site request forgery (CSRF) vulnerability in goform/admin/formWlEncrypt in Sitecom WLM-2501 allows remote attacker
23RISK
open
ReferênciaVexDay Proof
CMS NetCat 3.0/3.12 - Blind SQL Injection
CVE-2008-6853webappsphp
SQL injection vulnerability in modules/poll/index.php in AIST NetCat 3.0 and 3.12 allows remote attackers to execute arb
23RISK
open
Referência
CVE-2021-43798
CVE-2021-43798HIGHunder attack
Grafana path traversal
100RISK
open
ReferênciaVexDay Proof
Absolute News Feed 1.0 - Remote Insecure Cookie Handling
CVE-2008-6855webappsphp
Xigla Software Absolute News Feed 1.0 and possibly 1.5 allows remote attackers to bypass authentication and gain adminis
23RISK
open
ReferênciaVexDay Proof
Absolute News Manager 5.1 - Insecure Cookie Handling
CVE-2008-6856webappsphp
Xigla Software Absolute News Manager.NET 5.1 allows remote attackers to bypass authentication and gain administrative ac
23RISK
open
ReferênciaVexDay Proof
Absolute Podcast 1.0 - Remote Insecure Cookie Handling
CVE-2008-6857webappsphp
Absolute Podcast .NET 1.0 allows remote attackers to bypass authentication and gain administrative access by setting a c
23RISK
open
ReferênciaVexDay Proof
Absolute Poll Manager XE 4.1 - Insecure Cookie Handling
CVE-2008-6860webappsphp
Xigla Software Absolute Poll Manager XE 4.1 allows remote attackers to bypass authentication and gain administrative acc
23RISK
open
ReferênciaVexDay Proof
Absolute NewsLetter 6.1 - Insecure Cookie Handling
CVE-2008-6861webappsphp
Xigla Software Absolute Newsletter 6.0 and 6.1 allows remote attackers to bypass authentication and gain administrative
23RISK
open
ReferênciaVexDay Proof
Absolute Content Rotator 6.0 - Insecure Cookie Handling
CVE-2008-6862webappsphp
Absolute Content Rotator 6.0 allows remote attackers to bypass authentication and gain administrative access by setting
23RISK
open
ReferênciaVexDay Proof
Active Web Mail 4 - Blind SQL Injection
CVE-2008-6873webappsasp
SQL injection vulnerability in Active Web Mail 4.0 allows remote attackers to execute arbitrary SQL commands via the Tab
23RISK
open
ReferênciaVexDay Proof
ASPSiteWare Automotive Dealer 1.0/2.0 - SQL Injection
CVE-2008-6874webappsphp
Multiple SQL injection vulnerabilities in ASP SiteWare autoDealer 1 and 2 allow remote attackers to execute arbitrary SQ
23RISK
open
Referência
CVE-2023-4119
Academy LMS courses cross site scripting
33RISK
open
Referência
CVE-2018-1000115
Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vuln
60RISK
open
Referência
CVE-2018-1000115
Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vuln
60RISK
open
Referência
CVE-2012-2109
SQL injection vulnerability in wp-load.php in the BuddyPress plugin 1.5.x before 1.5.5 of WordPress allows remote attack
23RISK
open
Referência
CVE-2024-13161
CVE-2024-13161CRITICALunder attack
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up
100RISK
open
Referência
CVE-2020-8193
CVE-2020-8193MEDIUMunder attack
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14
100RISK
open
Referência
CVE-2020-3243
Multiple Vulnerabilities in Cisco UCS Director and Cisco UCS Director Express for Big Data
85RISK
open
ReferênciaVexDay Proof
Joomla! Component mosmedia 1.0.8 - Remote File Inclusion
CVE-2007-2043webappsphp
Multiple PHP remote file inclusion vulnerabilities in the Avant-Garde Solutions MOSMedia (com_mosmedia) 1.08 and earlier
23RISK
open
Referência
CVE-2018-7251
An issue was discovered in config/error.php in Anchor 0.12.3. The error log is exposed at an errors.log URI, and contain
60RISK
open
previouspage 590 / 752next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.