Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,056cataloged exploits
35,925CVEs with public exploitation
24,695lab-tested
22,640 exploits
Referência
CVE-2010-1364
SQL injection vulnerability in index.php in Uiga Personal Portal, as downloaded on 20100301, allows remote attackers to
23RISK
open
Referência
CVE-2010-1364
SQL injection vulnerability in index.php in Uiga Personal Portal, as downloaded on 20100301, allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
Joomla! Component JooBB 0.5.9 - Blind SQL Injection
CVE-2008-2651webappsphp
SQL injection vulnerability in the Joomla! Bulletin Board (aka Joo!BB or com_joobb) component 0.5.9 for Joomla! allows r
23RISK
open
ReferênciaVexDay Proof
LightNEasy sqlite / no database 1.2.2 - Multiple Vulnerabilities
CVE-2008-6593webappsphp
SQL injection vulnerability in LightNEasy/lightneasy.php in LightNEasy SQLite 1.2.2 and earlier allows remote attackers
23RISK
open
ReferênciaVexDay Proof
CJG EXPLORER PRO 3.2 - 'g_pcltar_lib_dir' Remote File Inclusion
CVE-2007-2660webappsphp
PHP remote file inclusion vulnerability in pcltrace.lib.php in the PclTar module in Vincent Blavet PhpConcept Library, a
23RISK
open
ReferênciaVexDay Proof
MemHT Portal 4.0.1 - Remote Code Execution
CVE-2009-0372webappsphp
Unrestricted file upload vulnerability in index.php in Miltenovik Manojlo MemHT Portal 4.0.1 and earlier allows remote a
23RISK
open
Referência
CVE-2009-4194
Directory traversal vulnerability in Golden FTP Server 4.30 Free and Professional, 4.50, and possibly other versions all
23RISK
open
Referência
CVE-2019-13658
CA Network Flow Analysis 9.x and 10.0.x have a default credential vulnerability that can allow a remote attacker to exec
48RISK
open
Referência
CVE-2026-12723
Kirki < 6.0.12 - Unauthenticated Arbitrary Comment Modification and Moderation Bypass via Component Library
33RISK
open
ReferênciaVexDay Proof
Telephone Directory 2008 - SQL Injection / Cross-Site Scripting
CVE-2008-2678webappsphp
Multiple SQL injection vulnerabilities in Telephone Directory 2008, when magic_quotes_gpc is disabled, allow remote atta
23RISK
open
Referência
CVE-2013-6164
SQL injection vulnerability in view/objectDetail.php in Project'Or RIA 3.4.0 allows remote attackers to execute arbitrar
23RISK
open
Referência
CVE-2013-6164
SQL injection vulnerability in view/objectDetail.php in Project'Or RIA 3.4.0 allows remote attackers to execute arbitrar
23RISK
open
Referência
CVE-2017-6528
An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is affected by plaintext password storage (the /home/dna/
23RISK
open
Referência
CVE-2012-1199
Multiple PHP remote file inclusion vulnerabilities in Basic Analysis and Security Engine (BASE) 1.4.5 allow remote attac
23RISK
open
Referência
CVE-2026-16214
geex-arts django-jet Dashboard views.py authorization
33RISK
open
Referência
CVE-2026-16212
awesto django-shop Purchase Stock inventory.py race condition
28RISK
open
ReferênciaVexDay Proof
realm CMS 2.3 - Multiple Vulnerabilities
CVE-2008-2679webappsphp
SQL injection vulnerability in the KeyWordsList function in _includes/inc_routines.asp in Realm CMS 2.3 and earlier allo
23RISK
open
Referência
CVE-2012-5322
Multiple cross-site scripting (XSS) vulnerabilities in Xavi X7968 allow remote attackers to inject arbitrary web script
23RISK
open
Referência
CVE-2018-6372
SQL Injection exists in the JB Bus 2.3 component for Joomla! via the order_number parameter.
23RISK
open
Referência
CVE-2010-3266
Multiple cross-site scripting (XSS) vulnerabilities in BugTracker.NET before 3.4.5 allow remote authenticated users to i
23RISK
open
Referência
CVE-2014-5090
admin/options/logs.php in Status2k allows remote authenticated administrators to execute arbitrary commands via shell me
23RISK
open
Referência
CVE-2017-6547
Cross-site scripting (XSS) vulnerability in httpd on ASUS RT-N56U, RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC
23RISK
open
Referência
CVE-2010-4858
Directory traversal vulnerability in team.rc5-72.php in DNET Live-Stats 0.8 allows remote attackers to read arbitrary fi
23RISK
open
Referência
CVE-2010-4858
Directory traversal vulnerability in team.rc5-72.php in DNET Live-Stats 0.8 allows remote attackers to read arbitrary fi
23RISK
open
ReferênciaVexDay Proof
Cyberfolio 7.12 - 'rep' Remote File Inclusion
CVE-2008-2228webappsphp
PHP remote file inclusion vulnerability in portfolio/commentaires/derniers_commentaires.php in Cyberfolio 7.12, when reg
23RISK
open
Referência
CVE-2016-6772
An elevation of privilege vulnerability in Wi-Fi could enable a local malicious application to execute arbitrary code wi
23RISK
open
Referência
CVE-2009-4424
SQL injection vulnerability in results.php in the Pyrmont plugin 2 for WordPress allows remote attackers to execute arbi
23RISK
open
Referência
CVE-2009-4424
SQL injection vulnerability in results.php in the Pyrmont plugin 2 for WordPress allows remote attackers to execute arbi
23RISK
open
ReferênciaVexDay Proof
IntelliTamper 2.07 - '.map' Local Arbitrary Code Execution (1)
CVE-2006-2494localwindows
Stack-based buffer overflow in IntelliTamper 2.07 allows remote attackers to execute arbitrary code via a crafted .map f
23RISK
open
ReferênciaVexDay Proof
Million Dollar Text Links 1.0 - Arbitrary Authentication Bypass
CVE-2009-1582webappsphp
Million Dollar Text Links 1.0 does not properly restrict administrator access to admin.home.php, which allows remote att
23RISK
open
previouspage 620 / 755next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.