Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,900cataloged exploits
35,840CVEs with public exploitation
24,695lab-tested
22,600 exploits
ReferênciaVexDay Proof
bloofox 0.3 - SQL Injection / File Disclosure
CVE-2008-0427webappsphp
Directory traversal vulnerability in file.php in bloofoxCMS 0.3 allows remote attackers to read arbitrary files via a ..
23RISK
open
Referência
CVE-2015-2528
Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 do not proper
23RISK
open
Referência
CVE-2015-2528
Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 do not proper
23RISK
open
Referência
CVE-2017-14266
tcprewrite in Tcpreplay 3.4.4 has a Heap-Based Buffer Overflow vulnerability triggered by a crafted PCAP file, a related
23RISK
open
Referência
CVE-2014-9581
Directory traversal vulnerability in components/filemanager/download.php in Codiad 2.4.3 allows remote attackers to read
23RISK
open
Referência
CVE-2014-6070
Multiple cross-site scripting (XSS) vulnerabilities in Adiscon LogAnalyzer before 3.6.6 allow remote attackers to inject
23RISK
open
Referência
CVE-2010-1335
Multiple PHP remote file inclusion vulnerabilities in Insky CMS 006-0111, when register_globals is enabled, allow remote
23RISK
open
Referência
CVE-2018-17997
LayerBB 1.1.1 allows XSS via the titles of conversations (PMs).
23RISK
open
Referência
CVE-2018-17997
LayerBB 1.1.1 allows XSS via the titles of conversations (PMs).
23RISK
open
Referência
CVE-2018-0969
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISK
open
Referência
CVE-2026-9583
SourceCodester CET Automated Grading System with AI Predictive Analytics SQL index.php information exposure
33RISK
open
Referência
CVE-2008-7008
HyperStop Web Host Directory 1.2 allows remote attackers to bypass authentication and download a database backup via a d
23RISK
open
Referência
CVE-2012-3435
SQL injection vulnerability in frontends/php/popup_bitem.php in Zabbix 1.8.15rc1 and earlier, and 2.x before 2.0.2rc1, a
23RISK
open
ReferênciaVexDay Proof
phpEventMan 1.0.2 - 'level' Remote File Inclusion
CVE-2007-0702webappsphp
Multiple PHP remote file inclusion vulnerabilities in phpEventMan 1.0.2 allow remote attackers to execute arbitrary PHP
23RISK
open
Referência
CVE-2014-2995
Multiple cross-site scripting (XSS) vulnerabilities in twitget.php in the Twitget plugin before 3.3.3 for WordPress allo
23RISK
open
ReferênciaVexDay Proof
e107 module 123 flash chat 6.8.0 - Remote File Inclusion
CVE-2008-1989webappsphp
PHP remote file inclusion vulnerability in 123flashchat.php in the 123 Flash Chat 6.8.0 module for e107, when register_g
23RISK
open
Referência
CVE-2009-3716
Unrestricted file upload vulnerability in admin.php in MCshoutbox 1.1 allows remote authenticated users to execute arbit
23RISK
open
Referência
CVE-2017-8840
Debug information disclosure exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before f
23RISK
open
Referência
CVE-2012-0699
Multiple cross-site request forgery (CSRF) vulnerabilities in Family Connections CMS (aka FCMS) 2.9 and earlier allow re
23RISK
open
Referência
CVE-2023-37759
Incorrect access control in the User Registration page of Crypto Currency Tracker (CCT) before v9.5 allows unauthenticat
23RISK
open
ReferênciaVexDay Proof
Joomla! Component Jotloader 1.2.1.a - Blind SQL Injection
CVE-2008-2564webappsphp
SQL injection vulnerability in the JotLoader (com_jotloader) component 1.2.1.a and earlier for Joomla! allows remote att
23RISK
open
Referência
CVE-2021-33570
Postbird 0.8.4 allows stored XSS via the onerror attribute of an IMG element in any PostgreSQL database table. This can
23RISK
open
Referência
CVE-2021-33570
Postbird 0.8.4 allows stored XSS via the onerror attribute of an IMG element in any PostgreSQL database table. This can
23RISK
open
Referência
CVE-2010-1340
Directory traversal vulnerability in jresearch.php in the J!Research (com_jresearch) component for Joomla! allows remote
43RISK
open
ReferênciaVexDay Proof
PhpHostBot 1.06 - 'svr_rootscript' Remote File Inclusion
CVE-2007-4231webappsphp
PHP remote file inclusion vulnerability in order/login.php in IDevSpot PhpHostBot 1.06 and earlier allows remote attacke
23RISK
open
Referência
CVE-2017-5473
Cross-site request forgery (CSRF) vulnerability in ntopng through 2.4 allows remote attackers to hijack the authenticati
23RISK
open
Referência
CVE-2005-0853
betaparticle blog (bp blog) stores the database under the web root, which allows remote attackers to obtain sensitive in
23RISK
open
Referência
CVE-2014-5308
Multiple SQL injection vulnerabilities in TestLink 1.9.11 allow remote authenticated users to execute arbitrary SQL comm
23RISK
open
Referência
CVE-2014-5308
Multiple SQL injection vulnerabilities in TestLink 1.9.11 allow remote authenticated users to execute arbitrary SQL comm
23RISK
open
Referência
CVE-2026-9436
Totolink A8000RU Web Management cstecgi.cgi setL2tpServerCfg os command injection
48RISK
open
previouspage 614 / 754next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.