Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,056cataloged exploits
35,925CVEs with public exploitation
24,695lab-tested
22,640 exploits
Referência
CVE-2014-10031
Buffer overflow in the IMAPd service in Qualcomm Eudora WorldMail 9.0.333.0 allows remote attackers to execute arbitrary
23RISK
open
Referência
CVE-2017-14960
xDashboard in OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 has SQL I
23RISK
open
ReferênciaVexDay Proof
PHP Jokesite 2.0 - 'cat_id' SQL Injection
CVE-2008-2457webappsphp
SQL injection vulnerability in jokes_category.php in PHP-Jokesite 2.0 allows remote attackers to execute arbitrary SQL c
23RISK
open
Referência
CVE-2010-1299
Multiple PHP remote file inclusion vulnerabilities in DynPG CMS 4.1.0, and possibly earlier, when magic_quotes_gpc is di
28RISK
open
Referência
CVE-2009-4578
Cross-site scripting (XSS) vulnerability in the Facileforms (com_facileforms) component for Joomla! and Mambo allows rem
23RISK
open
Referência
CVE-2014-3738
Cross-site scripting (XSS) vulnerability in Zenoss 4.2.5 allows remote attackers to inject arbitrary web script or HTML
23RISK
open
Referência
CVE-2014-9610
Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication an
23RISK
open
Referência
CVE-2014-9610
Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication an
23RISK
open
ReferênciaVexDay Proof
Samsung DVR SHR2040 - HTTPd Remote Denial of Service Denial of Service (PoC)
CVE-2008-4380doshardware
The web interface in Samsung DVR SHR2040 allows remote attackers to cause a denial of service (crash) via a malformed HT
23RISK
open
ReferênciaVexDay Proof
Google Chrome - 'ChromeHTML://' Remote Parameter Injection
CVE-2008-5749remotewindows
Argument injection vulnerability in Google Chrome 1.0.154.36 on Windows XP SP3 allows remote attackers to execute arbitr
23RISK
open
Referência
CVE-2015-1578
Multiple open redirect vulnerabilities in u5CMS before 3.9.4 allow remote attackers to redirect users to arbitrary web s
23RISK
open
ReferênciaVexDay Proof
acFTP FTP Server 1.4 - 'USER' Remote Buffer Overflow (PoC)
CVE-2006-2242doswindows
acFTP 1.4 allows remote attackers to cause a denial of service (application crash) via a long string with "{" (brace) ch
23RISK
open
ReferênciaVexDay Proof
SimpCMS 04.10.2007 - 'site' Remote File Inclusion
CVE-2007-2009webappsphp
PHP remote file inclusion vulnerability in index.php in SimpCMS Light 04.10.2007 and earlier allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
Siemens C450IP/C475IP - Remote Denial of Service
CVE-2008-7065doshardware
Siemens C450 IP and C475 IP VoIP devices allow remote attackers to cause a denial of service (disconnected calls and dev
23RISK
open
ReferênciaVexDay Proof
maGAZIn 2.0 - 'PHPThumb.php?src' Remote File Disclosure
CVE-2007-2643webappsphp
Directory traversal vulnerability in phpThumb.php in PinkCrow Designs Gallery or maGAZIn 2.0 allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
SunLight CMS 5.3 - 'root' Remote File Inclusion
CVE-2007-2774webappsphp
Multiple PHP remote file inclusion vulnerabilities in SunLight CMS 5.3 allow remote attackers to execute arbitrary PHP c
23RISK
open
ReferênciaVexDay Proof
Bitweaver R2 CMS - Arbitrary File Upload / Disclosure
CVE-2007-6651webappsphp
Directory traversal vulnerability in wiki/edit.php in Bitweaver R2 CMS allows remote attackers to obtain sensitive infor
23RISK
open
Referência
CVE-2010-5239
Untrusted search path vulnerability in DAEMON Tools Lite 4.35.6.0091 and Pro Standard 4.36.0309.0160 allows local users
23RISK
open
Referência
CVE-2011-0049
Directory traversal vulnerability in the _list_file_get function in lib/Majordomo.pm in Majordomo 2 before 20110131 allo
60RISK
open
Referência
CVE-2018-25126
TVT NVMS-9000 Hard-coded API Credentials & Command Injection
48RISK
open
Referência
CVE-2018-25126
TVT NVMS-9000 Hard-coded API Credentials & Command Injection
48RISK
open
Referência
CVE-2017-15974
tPanel 2009 allows SQL injection for Authentication Bypass via 'or 1=1 or ''=' to login.php.
23RISK
open
Referência
CVE-2017-15974
tPanel 2009 allows SQL injection for Authentication Bypass via 'or 1=1 or ''=' to login.php.
23RISK
open
Referência
CVE-2019-17624
"" In X.Org X Server 1.20.4, there is a stack-based buffer overflow in the function XQueryKeymap. For example, by sendin
23RISK
open
Referência
CVE-2018-0968
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISK
open
Referência
Authenticated low-privileged RCE in Coolify via unsanitized shell commands in the Git Repository field.
Coolify Git Repository Field Command Injection in Project Deployment Workflow
48RISK
open
Referência
CVE-2022-39285
Stored Cross-Site Scripting Vulnerability In File Parameter in zoneminder
41RISK
open
Referência
CVE-2015-1028
Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2730B router (rev C1) with firmware GE_1.01 allow remo
23RISK
open
Referência
CVE-2026-4567
Tenda A15 UploadCfg stack-based overflow
48RISK
open
Referência
CVE-2022-3481
WooCommerce Dropshipping < 4.4 - Unauthenticated SQLi
63RISK
open
previouspage 618 / 755next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.