Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,900cataloged exploits
35,840CVEs with public exploitation
24,695lab-tested
22,600 exploits
ReferênciaVexDay Proof
0irc-client 1345 build20060823 - Denial of Service
CVE-2007-1648doswindows
0irc 1345 build 20060823 allows remote attackers to cause a denial of service (application crash) by operating an IRC se
23RISK
open
Referência
CVE-2017-8917
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RISK
open
Referência
CVE-2009-3593
Multiple cross-site scripting (XSS) vulnerabilities in Freelancers 1.0 allow remote attackers to inject arbitrary web sc
23RISK
open
Referência
CVE-2009-3599
Cross-site scripting (XSS) vulnerability in single_winner1.php in HUBScript 1.0 allows remote attackers to inject arbitr
23RISK
open
Referência
CVE-2025-34103
WePresent WiPG-1000 Unauthenticated Command Injection in via rdfs.cgi
63RISK
open
Referência
CVE-2009-3661
Multiple SQL injection vulnerabilities in the DJ-Catalog (com_djcatalog) component for Joomla! allow remote attackers to
23RISK
open
Referência
CVE-2014-2623
Unspecified vulnerability in HP Storage Data Protector 8.x allows remote attackers to execute arbitrary code via unknown
60RISK
open
Referência
CVE-2014-2671
Microsoft Windows Media Player (WMP) 11.0.5721.5230 allows remote attackers to cause a denial of service (memory corrupt
35RISK
open
Referência
CVE-2009-3669
SQL injection vulnerability in the foobla Suggestions (com_foobla_suggestions) component 1.5.11 for Joomla! allows remot
23RISK
open
Referência
CVE-2011-5116
SQL injection vulnerability in setseed-hub in SetSeed CMS 5.8.20, 5.11.2, and earlier allows remote attackers to execute
23RISK
open
Referência
CVE-2011-5135
Multiple SQL injection vulnerabilities in the save_connection function in lib/lib.iotask.php in the iotask module in Doc
23RISK
open
Referência
CVE-2011-5165
Stack-based buffer overflow in Free MP3 CD Ripper 1.1, 2.6 and earlier, when converting a file, allows user-assisted rem
50RISK
open
Referência
CVE-2024-13159
CVE-2024-13159CRITICALunder attack
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up
100RISK
open
Referência
CVE-2021-34527
CVE-2021-34527HIGHunder attackransomware
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
Referência
CVE-2011-5170
Stack-based buffer overflow in Castillo Bueno Systems CCMPlayer 1.5 allows remote attackers to execute arbitrary code vi
50RISK
open
Referência
CVE-2016-10033
CVE-2016-10033CRITICALunder attack
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISK
open
Referência
CVE-2021-47981
Quick.CMS 6.7 Cross-Site Scripting via CSRF to Sliders Form
33RISK
open
Referência
CVE-2026-1184
Deserialization of Untrusted Data in GitLab
33RISK
open
Referência
CVE-2026-1322
Business Logic Errors in GitLab
33RISK
open
Referência
CVE-2026-1338
Authorization Bypass Through User-Controlled Key in GitLab
33RISK
open
Referência
CVE-2026-3074
Authorization Bypass Through User-Controlled Key in GitLab
33RISK
open
Referência
CVE-2026-3160
Unintended Proxy or Intermediary ('Confused Deputy') in GitLab
33RISK
open
Referência
CVE-2024-9465
CVE-2024-9465CRITICALunder attack
Expedition: SQL Injection Leads to Firewall Admin Credential Disclosure
100RISK
open
Referência
CVE-2009-4221
SQL injection vulnerability in classified.php in phpBazar 2.1.1fix and earlier allows remote attackers to execute arbitr
23RISK
open
Referência
CVE-2020-16846
CVE-2020-16846CRITICALunder attack
An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH clien
100RISK
open
Referência
CVE-2009-4223
PHP remote file inclusion vulnerability in adm/krgourl.php in KR-Web 1.1b2 and earlier allows remote attackers to execut
50RISK
open
Referência
CVE-2015-3313
SQL injection vulnerability in WordPress Community Events plugin before 1.4.
23RISK
open
Referência
CVE-2009-4989
Cross-site scripting (XSS) vulnerability in index.php in AJ Auction Pro OOPD 3.0 allows remote attackers to inject arbit
23RISK
open
Referência
CVE-2012-0698
tcsd in TrouSerS before 0.3.10 allows remote attackers to cause a denial of service (daemon crash) via a crafted type_of
28RISK
open
Referência
CVE-2026-19934
itsourcecode Hospital Management System vieworder.php sql injection
33RISK
open
previouspage 610 / 754next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.