Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,866cataloged exploits
35,812CVEs with public exploitation
24,695lab-tested
22,572 exploits
Referência
CVE-2016-15044
Kaltura < 11.1.0-2 PHP Object Injection RCE
63RISK
open
Referência
CVE-2016-15044
Kaltura < 11.1.0-2 PHP Object Injection RCE
63RISK
open
Referência
CVE-2016-15044
Kaltura < 11.1.0-2 PHP Object Injection RCE
63RISK
open
Referência
CVE-2017-9644
An Unquoted Search Path or Element issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan
23RISK
open
Referência
CVE-2016-7386
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 3
23RISK
open
Referência
CVE-2018-8815
Cross-site scripting (XSS) vulnerability in the gallery function in Alkacon OpenCMS 10.5.3 allows remote attackers to in
23RISK
open
ReferênciaVexDay Proof
Alstrasoft e-Friends 4.98 - 'seid' Multiple SQL Injections
CVE-2007-6106webappsphp
SQL injection vulnerability in index.php in AlstraSoft E-Friends 4.98 and earlier allows remote attackers to execute arb
23RISK
open
Referência
CVE-2017-5671
Honeywell Intermec PM23, PM42, PM43, PC23, PC43, PD43, and PC42 industrial printers before 10.11.013310 and 10.12.x befo
23RISK
open
Referência
CVE-2010-2462
SQL injection vulnerability in withdraw_money.php in Toma Cero OroHYIP allows remote attackers to execute arbitrary SQL
23RISK
open
Referência
CVE-2013-5321
Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.1 allow remot
23RISK
open
Referência
CVE-2020-26887
FRITZ!OS before 7.21 on FRITZ!Box devices allows a bypass of a DNS Rebinding protection mechanism.
23RISK
open
Referência
CVE-2010-2462
SQL injection vulnerability in withdraw_money.php in Toma Cero OroHYIP allows remote attackers to execute arbitrary SQL
23RISK
open
Referência
CVE-2026-19967
Open Asset Import Library Assimp File Compression.cpp decompressBlock heap-based overflow
33RISK
open
Referência
CVE-2005-3043
SQL injection vulnerability in AddItem.asp in Mall23 eCommerce allows remote attackers to execute arbitrary SQL commands
23RISK
open
Referência
CVE-2017-1000366
glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causin
23RISK
open
ReferênciaVexDay Proof
Joomla! Component Restaurante 1.0 - 'id' SQL Injection
CVE-2008-1465webappsphp
SQL injection vulnerability in the Detodas Restaurante (com_restaurante) 1.0 component for Mambo and Joomla! allows remo
23RISK
open
Referência
CVE-2014-0981
VBox/GuestHost/OpenGL/util/net.c in Oracle VirtualBox before 3.2.22, 4.0.x before 4.0.24, 4.1.x before 4.1.32, 4.2.x bef
23RISK
open
Referência
CVE-2015-5996
Cross-site request forgery (CSRF) vulnerability on Mediabridge Medialink MWN-WAPR300N devices with firmware 5.07.50 allo
23RISK
open
Referência
CVE-2012-3872
Multiple cross-site scripting (XSS) vulnerabilities in Open Constructor 3.12.0 allow remote attackers to inject arbitrar
23RISK
open
ReferênciaVexDay Proof
Dew-NewPHPLinks 2.0 - Local File Inclusion / Cross-Site Scripting
CVE-2009-1623webappsphp
Cross-site scripting (XSS) vulnerability in index.php in Dew-NewPHPLinks 2.0 allows remote attackers to inject arbitrary
23RISK
open
Referência
CVE-2022-48079
Monnai aaPanel host system v1.5 contains an access control issue which allows attackers to escalate privileges and execu
48RISK
open
Referência
CVE-2018-18435
KioWare Server version 4.9.6 and older installs by default to "C:\kioware_com" with weak folder permissions granting any
23RISK
open
Referência
CVE-2018-18435
KioWare Server version 4.9.6 and older installs by default to "C:\kioware_com" with weak folder permissions granting any
23RISK
open
Referência
CVE-2012-6585
Cross-site scripting (XSS) vulnerability in search.php in MYRE Realty Manager allows remote attackers to inject arbitrar
23RISK
open
Referência
CVE-2012-6589
Cross-site scripting (XSS) vulnerability in search.php in MYRE Business Directory allows remote attackers to inject arbi
23RISK
open
Referência
CVE-2009-3805
gpg2.exe in Gpg4win 2.0.1, as used in KDE Kleopatra 2.0.11, allows remote attackers to cause a denial of service (applic
23RISK
open
Referência
CVE-2018-0438
Cisco Umbrella Enterprise Roaming Client Privilege Escalation Vulnerability
23RISK
open
Referência
CVE-2021-31650
A SQL injection vulnerability in Sourcecodester Online Grading System 1.0 allows remote attackers to execute arbitrary S
48RISK
open
Referência
CVE-2010-2505
Soft SaschArt SasCAM Webcam Server 2.6.5, 2.7, and earlier allows remote attackers to cause a denial of service (crash)
23RISK
open
Referência
WonderCMS 3.1.3 - 'Menu' Persistent Cross-Site Scripting
CVE-2020-29469webappsphp
WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Menu component. This vulnerability can allow an attacke
23RISK
open
previouspage 591 / 753next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.