Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,794cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
22,573 exploits
Referência
CVE-2008-6392
SQL injection vulnerability in showads.php in Z1Exchange allows remote attackers to execute arbitrary SQL commands via t
23RISK
open
Referência
CVE-2018-14933
CVE-2018-14933CRITICALunder attack
upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir par
100RISK
open
ReferênciaVexDay Proof
Catviz 0.4.0 beta1 - Multiple SQL Injections
CVE-2008-3129webappsphp
Multiple SQL injection vulnerabilities in index.php in Catviz 0.4 beta 1 allow remote attackers to execute arbitrary SQL
23RISK
open
Referência
CVE-2015-5122
CVE-2015-5122HIGHunder attack
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player
100RISK
open
ReferênciaVexDay Proof
pSys 0.7.0 Alpha - 'chatbox.php' SQL Injection
CVE-2008-3131webappsphp
SQL injection vulnerability in chatbox.php in pSys 0.7.0 Alpha, when magic_quotes_gpc is disabled, allows remote attacke
23RISK
open
Referência
CyberArk Viewfinity 5.5.10.95 - Local Privilege Escalation
CVE-2017-11197HIGHlocalwindows
In CyberArk Viewfinity 5.5.10.95 and 6.x before 6.1.1.220, a low privilege user can escalate to an administrative user v
41RISK
open
Referência
CVE-2017-1129
IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it coul
50RISK
open
ReferênciaVexDay Proof
AShop Deluxe 4.x - 'catalogue.php' SQL Injection
CVE-2008-3136webappsphp
SQL injection vulnerability in catalogue.php in AShop Deluxe 4.x allows remote attackers to execute arbitrary SQL comman
23RISK
open
ReferênciaVexDay Proof
Rae Media Contact MS - Authentication Bypass
CVE-2008-6389webappsphp
SQL injection vulnerability in asadmin/default.asp in Rae Media Contact Management Software SOHO, Standard, and Enterpri
23RISK
open
Referência
CVE-2008-6396
Cross-site scripting (XSS) vulnerability in account.php in Celerondude Uploader 6.1 allows remote attackers to inject ar
23RISK
open
Referência
CVE-2026-7219
Totolink N300RT formIpQoS buffer overflow
41RISK
open
Referência
CVE-2026-7218
Totolink N300RT libapmib.so formWsc is_cmd_string_valid buffer overflow
41RISK
open
Referência
CVE-2021-42013
CVE-2021-42013CRITICALunder attackransomware
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
Referência
CVE-2021-42013
CVE-2021-42013CRITICALunder attackransomware
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
Referência
CVE-2021-42013
CVE-2021-42013CRITICALunder attackransomware
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
ReferênciaVexDay Proof
CodeDB 1.1.1 - 'list.php' Local File Inclusion
CVE-2008-3190webappsphp
Directory traversal vulnerability in list.php in 1Scripts CodeDB 1.1.1 allows remote attackers to include and execute ar
23RISK
open
Referência
CVE-2018-10561
CVE-2018-10561CRITICALunder attack
An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images
100RISK
open
Referência
CVE-2019-1653
CVE-2019-1653HIGHunder attack
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RISK
open
ReferênciaVexDay Proof
jsite 1.0 oe - SQL Injection / Local File Inclusion
CVE-2008-3193webappsphp
SQL injection vulnerability in jSite 1.0 OE allows remote attackers to execute arbitrary SQL commands via the page param
23RISK
open
Referência
CVE-2019-16662
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to a
60RISK
open
Referência
CVE-2019-16662
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to a
60RISK
open
ReferênciaVexDay Proof
bilboblog 2.1 - Multiple Vulnerabilities
CVE-2008-3302webappsphp
SQL injection vulnerability in admin/delete.php in BilboBlog 0.2.1, when magic_quotes_gpc is disabled, allows remote aut
23RISK
open
ReferênciaVexDay Proof
bilboblog 2.1 - Multiple Vulnerabilities
CVE-2008-3304webappsphp
BilboBlog 0.2.1 allows remote attackers to obtain sensitive information via (1) an enable_cache=false query string to fo
23RISK
open
Referência
CVE-2022-33891
CVE-2022-33891HIGHunder attack
Apache Spark shell command injection vulnerability via Spark UI
100RISK
open
Referência
CVE-2023-41892
Craft CMS Remote Code Execution vulnerability
85RISK
open
ReferênciaVexDay Proof
Pre Survey Poll - 'catid' SQL Injection
CVE-2008-3310webappsasp
SQL injection vulnerability in default.asp in Pre Survey Poll allows remote attackers to execute arbitrary SQL commands
23RISK
open
Referência
CVE-2019-15976
Cisco Data Center Network Manager Authentication Bypass Vulnerabilities
70RISK
open
Referência
CVE-2022-21907
HTTP Protocol Stack Remote Code Execution Vulnerability
70RISK
open
Referência
CVE-2012-1297
Multiple cross-site request forgery (CSRF) vulnerabilities in main.php in Contao (formerly TYPOlight) 2.11.0 and earlier
23RISK
open
Referência
CVE-2012-1297
Multiple cross-site request forgery (CSRF) vulnerabilities in main.php in Contao (formerly TYPOlight) 2.11.0 and earlier
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.