Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,900cataloged exploits
35,840CVEs with public exploitation
24,695lab-tested
22,600 exploits
Referência
CVE-2009-4604
PHP remote file inclusion vulnerability in mamboleto.php in the Fernando Soares Mamboleto (com_mamboleto) component 2.0
23RISK
open
Referência
CVE-2009-4604
PHP remote file inclusion vulnerability in mamboleto.php in the Fernando Soares Mamboleto (com_mamboleto) component 2.0
23RISK
open
Referência
CVE-2023-32315
CVE-2023-32315HIGHunder attack
Openfire administration console authentication bypass
100RISK
open
Referência
CVE-2024-3273
CVE-2024-3273HIGHunder attack
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RISK
open
Referência
CVE-2014-6389
backup.php in PHPCompta/NOALYSS before 6.7.2 allows remote attackers to execute arbitrary commands via shell metacharact
23RISK
open
Referência
CVE-2022-22954
CVE-2022-22954CRITICALunder attackransomware
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISK
open
Referência
CVE-2011-2523
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open
Referência64
FortiWeb CVE-2025-25257 exploit
CVE-2025-25257CRITICALunder attack
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RISK
open
Referência
FortiWeb Fabric Connector 7.6.x - SQL Injection to Remote Code Execution
CVE-2025-25257CRITICALunder attackwebappsmultiple
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RISK
open
ReferênciaVexDay Proof
plxAutoReminder 3.7 - 'id' SQL Injection
CVE-2009-0593webappsphp
SQL injection vulnerability in members.php in plx Auto Reminder 3.7 allows remote authenticated users to execute arbitra
23RISK
open
ReferênciaVexDay Proof
phpskelsite 1.4 - Local File Inclusion / Remote File Inclusion / Cross-Site Scripting
CVE-2009-0594webappsphp
Cross-site scripting (XSS) vulnerability in index.php in phpSkelSite 1.4 allows remote attackers to inject arbitrary web
23RISK
open
Referência
CVE-2018-11776
CVE-2018-11776HIGHunder attack
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISK
open
Referência
CVE-2009-4624
SQL injection vulnerability in download.php in Nicecoder iDesk allows remote attackers to execute arbitrary SQL commands
23RISK
open
Referência
CVE-2020-8515
CVE-2020-8515CRITICALunder attack
DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow
100RISK
open
Referência
CVE-2018-7600
CVE-2018-7600CRITICALunder attackransomware
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
Referência
CVE-2018-7600
CVE-2018-7600CRITICALunder attackransomware
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
Referência
CVE-2013-2143
The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update
50RISK
open
ReferênciaVexDay Proof
Multiple Vendor - PF Null Pointer Dereference
CVE-2009-0687dosbsd
The pf_test_rule function in OpenBSD Packet Filter (PF), as used in OpenBSD 4.2 through 4.5, NetBSD 5.0 before RC3, MirO
23RISK
open
ReferênciaVexDay Proof
OpenBSD 4.5 - IP datagrams Remote Denial of Service
CVE-2009-0687dosopenbsd
The pf_test_rule function in OpenBSD Packet Filter (PF), as used in OpenBSD 4.2 through 4.5, NetBSD 5.0 before RC3, MirO
23RISK
open
Referência
CVE-2026-8214
Industrial Application Software IAS Canias ERP RMI doAction improper authentication
33RISK
open
Referência
CVE-2013-2294
Multiple cross-site scripting (XSS) vulnerabilities in ViewGit before 0.0.7 allow remote repository users to inject arbi
23RISK
open
Referência
CVE-2013-2423
CVE-2013-2423LOWunder attack
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and
95RISK
open
Referência
CVE-2014-9258
SQL injection vulnerability in ajax/getDropdownValue.php in GLPI before 0.85.1 allows remote authenticated users to exec
23RISK
open
Referência
CVE-2023-46805
CVE-2023-46805HIGHunder attackransomware
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a re
100RISK
open
Referência
CVE-2023-22527
CVE-2023-22527CRITICALunder attackransomware
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RISK
open
Referência
CVE-2026-10062
TRENDnet TEW-432BRP formSetRoute stack-based overflow
41RISK
open
Referência
CVE-2013-2684
Cross-site Scripting (XSS) in Cisco Linksys E4200 1.0.05 Build 7 devices allows remote attackers to inject arbitrary web
23RISK
open
Referência
CVE-2009-4721
Multiple SQL injection vulnerabilities in Admin/index.asp in Andrews-Web (A-W) BannerAd 1.0 allow remote attackers to ex
23RISK
open
Referência
CVE-2015-0313
CVE-2015-0313HIGHunder attack
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows
100RISK
open
Referência
CVE-2013-3529
Multiple cross-site scripting (XSS) vulnerabilities in user/obits.php in the WP FuneralPress plugin before 1.1.7 for Wor
23RISK
open
previouspage 606 / 754next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.