Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,056cataloged exploits
35,925CVEs with public exploitation
24,695lab-tested
22,640 exploits
Referência
CVE-2010-4987
SQL injection vulnerability in default.asp in KMSoft Guestbook (aka GBook) allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
MiniBB 2.0.5 - 'Language' Local File Inclusion
CVE-2007-3272webappsphp
Directory traversal vulnerability in index.php in MiniBB 2.0.5 allows remote attackers to read arbitrary files via a ..
23RISK
open
Referência
CVE-2017-8479
The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2,
23RISK
open
Referência
CVE-2026-3326
XStore < 9.7.3 - Unauthenticated SQLi
56RISK
open
Referência
CVE-2026-14843
Events Made Easy < 3.1.4 - Unauthenticated Person Data Modification via IDOR
33RISK
open
Referência
CVE-2006-1747
PHP remote file inclusion vulnerability in Virtual War (VWar) 1.5.0 allows remote attackers to execute arbitrary PHP cod
23RISK
open
Referência
CVE-2005-4696
The Microsoft Wireless Zero Configuration system (WZCS) stores WEP keys and pair-wise Master Keys (PMK) of the WPA pre-s
23RISK
open
ReferênciaVexDay Proof
rgboard 3.0.12 - Remote File Inclusioni / Cross-Site Scripting
CVE-2008-2295webappsphp
Cross-site scripting (XSS) vulnerability in rg_search.php in Rgboard 3.0.12, and possibly earlier versions, allows remot
23RISK
open
Referência
CVE-2018-10310
A persistent cross-site scripting vulnerability has been identified in the web interface of the Catapult UK Cookie Conse
23RISK
open
Referência
CVE-2018-10310
A persistent cross-site scripting vulnerability has been identified in the web interface of the Catapult UK Cookie Conse
23RISK
open
Referência
CVE-2014-9311
Cross-site scripting (XSS) vulnerability in admin.php in the Shareaholic plugin before 7.6.1.0 for WordPress allows remo
23RISK
open
Referência
CVE-2018-17428
An issue was discovered in OPAC EasyWeb Five 5.7. There is SQL injection via the w2001/index.php?scelta=campi biblio par
23RISK
open
Referência
CVE-2019-11416
A CSRF issue was discovered on Intelbras IWR 3000N 1.5.0 devices, leading to complete control of the router, as demonstr
23RISK
open
Referência
CVE-2019-11416
A CSRF issue was discovered on Intelbras IWR 3000N 1.5.0 devices, leading to complete control of the router, as demonstr
23RISK
open
Referência
CVE-2013-4950
Cross-site scripting (XSS) vulnerability in view.php in Machform 2 allows remote attackers to inject arbitrary web scrip
23RISK
open
Referência
CVE-2010-1270
SQL injection vulnerability in auktion.php in Multi Auktions Komplett System 2 allows remote attackers to execute arbitr
23RISK
open
Referência
CVE-2011-5228
Cross-site scripting (XSS) vulnerability in the Search module (quickstart/search) in appRain CMF 0.1.5 allows remote att
23RISK
open
Referência
CVE-2012-2939
Multiple unrestricted file upload vulnerabilities in Travelon Express 6.2.2 allow remote authenticated users to execute
23RISK
open
Referência
CVE-2026-11530
imvks786 student_management_system Login index.ph sql injection
33RISK
open
ReferênciaVexDay Proof
SoftBB 0.1 - 'cmd' Remote Command Execution
CVE-2006-4632webappsphp
Multiple SQL injection vulnerabilities in SoftBB 0.1, and possibly earlier, allow remote attackers to execute arbitrary
23RISK
open
Referência
CVE-2015-1422
Multiple cross-site scripting (XSS) vulnerabilities in Gecko CMS 2.2 and 2.3 allow remote attackers to inject arbitrary
23RISK
open
ReferênciaVexDay Proof
W3Filer 2.1.3 - Remote Stack Overflow (PoC)
CVE-2007-3548doswindows
Stack-based buffer overflow in W3Filer 2.1.3 allows remote FTP servers to cause a denial of service (application hang or
23RISK
open
ReferênciaVexDay Proof
Live for Speed S1/S2/Demo - '.mpr replay' Local Buffer Overflow
CVE-2007-4140localwindows
Buffer overflow in Live for Speed (LFS) S2 ALPHA PATCH 0.5x allows user-assisted remote attackers to execute arbitrary c
23RISK
open
Referência
CVE-2010-5001
SQL injection vulnerability in view.php in esoftpro Online Contact Manager 3.0 allows remote attackers to execute arbitr
23RISK
open
Referência
CVE-2010-5008
SQL injection vulnerability in pages/contact_list_mail_form.asp in BrightSuite Groupware 5.4 allows remote attackers to
23RISK
open
Referência
CVE-2010-5009
SQL injection vulnerability in index.php in UTStats Beta 4 and earlier allows remote attackers to execute arbitrary SQL
23RISK
open
Referência
CVE-2010-3134
Untrusted search path vulnerability in Google Earth 5.1.3535.3218 allows local users, and possibly remote attackers, to
23RISK
open
ReferênciaVexDay Proof
68 Classifieds 4.0 - 'category.php' SQL Injection
CVE-2008-2336webappsphp
SQL injection vulnerability in category.php in 68 Classifieds 4.0.1 allows remote attackers to execute arbitrary SQL com
23RISK
open
Referência
CVE-2025-34024
Edimax EW-7438RPn Mini OS Command Injection via mp.asp
48RISK
open
Referência
CVE-2018-9844
The Iptanus WordPress File Upload plugin before 4.3.4 for WordPress mishandles Settings attributes, leading to XSS.
23RISK
open
previouspage 616 / 755next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.