Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,900cataloged exploits
35,840CVEs with public exploitation
24,695lab-tested
22,600 exploits
Referência
CVE-2016-1914
Multiple SQL injection vulnerabilities in the com.rim.mdm.ui.server.ImageServlet servlet in BlackBerry Enterprise Server
23RISK
open
Referência
CVE-2010-4942
SQL injection vulnerability in location.php in the eCal module in E-Xoopport Samsara 3.1 and earlier allows remote attac
23RISK
open
Referência
CVE-2010-2018
Directory traversal vulnerability in downlot.php in Lokomedia CMS 1.4.1 and 2.0 allows remote attackers to read arbitrar
38RISK
open
ReferênciaVexDay Proof
PHP-Fusion Mod Classifieds - 'lid' SQL Injection
CVE-2008-5197webappsphp
SQL injection vulnerability in classifieds.php in PHP-Fusion allows remote attackers to execute arbitrary SQL commands v
23RISK
open
Referência
CVE-2010-1186
Cross-site scripting (XSS) vulnerability in xml/media-rss.php in the NextGEN Gallery plugin before 1.5.2 for WordPress a
23RISK
open
Referência
CVE-2018-2892
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Availability Suite Service).
23RISK
open
ReferênciaVexDay Proof
TurnkeyForms Web Hosting Directory - Multiple Vulnerabilities
CVE-2008-6940webappsphp
TurnkeyForms Web Hosting Directory stores sensitive information under the web root with insufficient access control, whi
23RISK
open
Referência
CVE-2010-1199
Integer overflow in the XSLT node sorting implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4,
28RISK
open
ReferênciaVexDay Proof
Discuz! - Remote Reset User Password
CVE-2008-6957webappsphp
member.php in Crossday Discuz! Board allows remote attackers to reset passwords of arbitrary users via crafted (1) lostp
23RISK
open
Referência
CVE-2015-0936
Ceragon FibeAir IP-10 have a default SSH public key in the authorized_keys file for the mateidu user, which allows remot
60RISK
open
ReferênciaVexDay Proof
pivot 1.40.4-7 - Multiple Vulnerabilities
CVE-2009-2133webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in Pivot 1.40.4 and 1.40.7 allow remote attackers to inject arbitrar
23RISK
open
Referência
CVE-2010-4943
Multiple PHP remote file inclusion vulnerabilities in Saurus CMS 4.7.0 allow remote attackers to execute arbitrary PHP c
23RISK
open
Referência
CVE-2018-16061
Mitsubishi Electric Europe B.V. SmartRTU devices allow XSS via the username parameter or PATH_INFO to login.php.
23RISK
open
ReferênciaVexDay Proof
DeluxeBB 1.2 - Multiple Vulnerabilities
CVE-2008-2194webappsphp
SQL injection vulnerability in forums.php in DeluxeBB 1.2 and earlier allows remote attackers to execute arbitrary SQL c
23RISK
open
Referência
CVE-2026-3301
Totolink N300RH Web Management cstecgi.cgi setWebWlanIdx os command injection
48RISK
open
Referência
CVE-2017-15284
Cross-Site Scripting exists in OctoberCMS 1.0.425 (aka Build 425), allowing a least privileged user to upload an SVG fil
23RISK
open
Referência
CVE-2026-9278
Form Builder CP < 1.2.47 - Editor+ Stored XSS via form_structure
33RISK
open
Referência
CVE-2026-21876 PoC: WAF charset bypass (Flask, ASP.NET and Spring Boot stands)
OWASP CRS has multipart bypass using multiple content-type parts
53RISK
open
Referência
CVE-2019-11419
vcodec2_hls_filter in libvoipCodec_v7a.so in the WeChat application through 7.0.3 for Android allows attackers to cause
23RISK
open
Referência
CVE-2009-4834
lib.php in Zeroboard 4.1 pl7 allows remote attackers to execute arbitrary PHP code via a crafted parameter name, possibl
23RISK
open
ReferênciaVexDay Proof
phpDatingClub 3.7 - 'website.php' Local File Inclusion
CVE-2008-3179webappsphp
Directory traversal vulnerability in website.php in Web 2 Business (W2B) phpDatingClub (aka Dating Club) 3.7 allows remo
23RISK
open
Referência
CVE-2026-8385
WP Go Maps < 10.0.10 - Unauthenticated Sensitive Information Disclosure via Datatables AJAX Fallback
48RISK
open
Referência
CVE-2019-17220
Rocket.Chat before 2.1.0 allows XSS via a URL on a ![title] line.
23RISK
open
ReferênciaVexDay Proof
Jinzora 2.1 - 'media.php' Remote File Inclusion
CVE-2006-7130webappsphp
PHP remote file inclusion vulnerability in backend/primitives/cache/media.php in Jinzora 2.1 and earlier allows remote a
23RISK
open
ReferênciaVexDay Proof
PHP-Nuke Module PostGuestbook 0.6.1 - 'tpl_pgb_moddir' Remote File Inclusion
CVE-2007-1372webappsphp
PHP remote file inclusion vulnerability in styles/internal/header.php in the PostGuestbook 0.6.1 module for PHP-Nuke all
23RISK
open
ReferênciaVexDay Proof
cPanel 11.x - Cross-Site Scripting / Local File Inclusion
CVE-2008-6926webappsphp
Directory traversal vulnerability in autoinstall4imagesgalleryupgrade.php in the Fantastico De Luxe Module for cPanel al
23RISK
open
ReferênciaVexDay Proof
mxBB Module FAQ & RULES 2.0.0 - Remote File Inclusion
CVE-2007-2493webappsphp
PHP remote file inclusion vulnerability in faq.php in the FAQ & RULES 2.0.0 and earlier module for mxBB allows remote at
23RISK
open
Referência
WeChat for Android 7.0.4 - 'vcodec2_hls_filter' Denial of Service
CVE-2019-11419dosandroid
vcodec2_hls_filter in libvoipCodec_v7a.so in the WeChat application through 7.0.3 for Android allows attackers to cause
23RISK
open
Referência
CVE-2010-4969
SQL injection vulnerability in articlesdetails.php in BrotherScripts (BS) Business Directory allows remote attackers to
23RISK
open
Referência
CVE-2018-11339
An XSS issue was discovered in Frappe ERPNext v11.x.x-develop b1036e5 via a comment.
23RISK
open
previouspage 611 / 754next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.