Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,056cataloged exploits
35,925CVEs with public exploitation
24,695lab-tested
22,640 exploits
ReferênciaVexDay Proof
PHP Dir Submit - Authentication Bypass
CVE-2009-1787webappsphp
Multiple SQL injection vulnerabilities in PHP Dir Submit (aka WebsiteSubmitter and Submitter Script) allow remote attack
23RISK
open
Referência
CVE-2020-7247
CVE-2020-7247CRITICALunder attack
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISK
open
Referência
CVE-2020-7247
CVE-2020-7247CRITICALunder attack
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISK
open
Referência
CVE-2010-4866
SQL injection vulnerability in index.php in Chipmunk Board 1.3 allows remote attackers to execute arbitrary SQL commands
23RISK
open
Referência
CVE-2015-1100
The kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 allows attackers to cause a denia
23RISK
open
Referência
CVE-2013-1773
Buffer overflow in the VFAT filesystem implementation in the Linux kernel before 3.3 allows local users to gain privileg
23RISK
open
Referência
CVE-2012-0906
SQL injection vulnerability in the Moviebase addon for deV!L'z Clanportal (DZCP) 1.5.5 allows remote attackers to execut
23RISK
open
Referência
CVE-2012-5323
Cross-site request forgery (CSRF) vulnerability in webconfig/admin_passwd/passwd.html/admin_passwd in Xavi X7968 allows
23RISK
open
Referência
CVE-2022-3241
Build App Online < 1.0.19 - Unauthenticated SQL Injection
48RISK
open
Referência
CVE-2022-4383
CBX Petition for WordPress <= 1.0.3 - Unauthenticated SQLi
48RISK
open
Referência
CVE-2017-14956
AlienVault USM v5.4.2 and earlier offers authenticated users the functionality of exporting generated reports via the "/
23RISK
open
Referência
CVE-2022-4099
Joy Of Text Lite < 2.3.1 - Unauthenticated SQLi
48RISK
open
ReferênciaVexDay Proof
DigiLeave 1.2 - 'book_id' Blind SQL Injection
CVE-2008-3309webappsasp
SQL injection vulnerability in info_book.asp in DigiLeave 1.2 and earlier allows remote attackers to execute arbitrary S
23RISK
open
Referência
CVE-2014-7872
Comodo GeekBuddy before 4.18.121 does not restrict access to the VNC server, which allows local users to gain privileges
23RISK
open
Referência
CVE-2014-7872
Comodo GeekBuddy before 4.18.121 does not restrict access to the VNC server, which allows local users to gain privileges
23RISK
open
ReferênciaVexDay Proof
ZEELYRICS 2.0 - 'bannerclick.php' SQL Injection
CVE-2008-4717webappsphp
SQL injection vulnerability in bannerclick.php in ZEELYRICS 2.0 allows remote attackers to execute arbitrary SQL command
23RISK
open
ReferênciaVexDay Proof
Woltlab Burning Board 1.0.2/2.3.6 - 'search.php' SQL Injection (1)
CVE-2007-0388webappsphp
SQL injection vulnerability in search.php in Woltlab Burning Board (wBB) 1.0.2 and earlier, and 2.3.6 and earlier in the
23RISK
open
ReferênciaVexDay Proof
BluSky CMS - 'news_id' SQL Injection
CVE-2009-1548webappsphp
SQL injection vulnerability in index.php in BluSky CMS allows remote attackers to execute arbitrary SQL commands via the
23RISK
open
ReferênciaVexDay Proof
NukeSentinel 2.5.05 - 'nukesentinel.php' File Disclosure
CVE-2007-1172webappsphp
SQL injection vulnerability in nukesentinel.php in NukeSentinel 2.5.05, and possibly earlier, allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
Crea-Book 1.0 - Admin Access Bypass / Database Disclosure / Code Execution
CVE-2007-2000webappsphp
Multiple SQL injection vulnerabilities in admin/admin.php in Crea-Book 1.0 and earlier allow remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
XOOPS module Articles 1.02 - 'print.php?id' SQL Injection
CVE-2007-3311webappsphp
SQL injection vulnerability in print.php in the Articles 1.02 and earlier module for Xoops allows remote attackers to ex
23RISK
open
ReferênciaVexDay Proof
phpFullAnnu (PFA) 6.0 - SQL Injection
CVE-2007-5068webappsphp
SQL injection vulnerability in index.php in phpFullAnnu (PFA) 6.0 allows remote attackers to execute arbitrary SQL comma
23RISK
open
Referência
CVE-2008-4344
SQL injection vulnerability in cat.php in 6rbScript allows remote attackers to execute arbitrary SQL commands via the Ca
23RISK
open
ReferênciaVexDay Proof
JobSite Professional 2.0 - 'file.php' SQL Injection
CVE-2007-5785webappsphp
SQL injection vulnerability in file.php in JobSite Professional 2.0 allows remote attackers to execute arbitrary SQL com
23RISK
open
ReferênciaVexDay Proof
Content Injector 1.53 - 'index.php' SQL Injection
CVE-2007-6394webappsphp
SQL injection vulnerability in index.php in Content Injector 1.53 allows remote attackers to execute arbitrary SQL comma
23RISK
open
Referência
CVE-2019-25750
Joomla J-MultipleHotelReservation 6.0.7 SQL Injection
41RISK
open
ReferênciaVexDay Proof
phpsmartcom 0.2 - Local File Inclusion / SQL Injection
CVE-2008-4351webappsphp
Directory traversal vulnerability in index.php in phpSmartCom 0.2 allows remote attackers to include and execute arbitra
23RISK
open
Referência
CVE-2010-4915
SQL injection vulnerability in index.cfm in ColdGen ColdBookmarks 1.22 allows remote attackers to execute arbitrary SQL
23RISK
open
Referência
CVE-2017-20277
Joomla JoomRecipe 1.0.4 Component Blind SQL Injection via search_author
41RISK
open
Referência
CVE-2009-4057
SQL injection vulnerability in the inertialFATE iF Portfolio Nexus (com_if_nexus) component 1.1 for Joomla! allows remot
23RISK
open
previouspage 624 / 755next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.