Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,131cataloged exploits
35,957CVEs with public exploitation
24,695lab-tested
22,640 exploits
Referência
CVE-2013-2094
CVE-2013-2094HIGHunder attack
The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data t
83RISK
open
ReferênciaVexDay Proof
Minerva 2.0.8a Build 237 - 'phpbb_root_path' File Inclusion
CVE-2006-3028webappsphp
PHP remote file inclusion vulnerability in stat_modules/users_age/module.php in Minerva 2.0.8a Build 237 and earlier all
23RISK
open
ReferênciaVexDay Proof
PHP-Update 2.7 - '/admin/uploads.php' Remote Code Execution
CVE-2006-6878webappsphp
admin/uploads.php in PHP-Update 2.7 and earlier allows remote attackers to gain privileges by setting the rights[7] para
23RISK
open
ReferênciaVexDay Proof
Joomla! Component module autostand 1.0 - Remote File Inclusion
CVE-2007-2319webappsphp
PHP remote file inclusion vulnerability in the AutoStand 1.1 and earlier module for Joomla! allows remote attackers to e
23RISK
open
ReferênciaVexDay Proof
Blakord Portal Beta 1.3.A (All Modules) - SQL Injection
CVE-2007-6565webappsphp
Multiple SQL injection vulnerabilities in Blakord Portal 1.3.A Beta and earlier allow remote attackers to execute arbitr
23RISK
open
Referência
CVE-2015-4624
Hak5 WiFi Pineapple 2.0 through 2.3 uses predictable CSRF tokens.
50RISK
open
Referência
CVE-2013-7192
Multiple SQL injection vulnerabilities in Dynamic Biz Website Builder (QuickWeb) allow remote attackers to execute arbit
23RISK
open
Referência
CVE-2010-2925
SQL injection vulnerability in index.php in Freeway CMS 1.4.3.210 allows remote attackers to execute arbitrary SQL comma
23RISK
open
Referência
CVE-2010-2925
SQL injection vulnerability in index.php in Freeway CMS 1.4.3.210 allows remote attackers to execute arbitrary SQL comma
23RISK
open
Referência
CVE-2010-1710
Directory traversal vulnerability in login.php in Siestta 2.0, when register_globals is enabled, allows remote attackers
23RISK
open
Referência
CVE-2010-1710
Directory traversal vulnerability in login.php in Siestta 2.0, when register_globals is enabled, allows remote attackers
23RISK
open
ReferênciaVexDay Proof
phpBB Module XS-Mod 2.3.1 - Local File Inclusion
CVE-2008-1512webappsphp
Directory traversal vulnerability in admin/admin_xs.php in eXtreme Styles module (XS-Mod) 2.3.1 and 2.4.0 for phpBB allo
23RISK
open
ReferênciaVexDay Proof
Gelato - 'index.php?post' SQL Injection
CVE-2007-4918webappsphp
SQL injection vulnerability in classes/gelato.class.php in Gelato allows remote attackers to execute arbitrary SQL comma
23RISK
open
ReferênciaVexDay Proof
Uebimiau Web-Mail 2.7.10/2.7.2 - Remote File Disclosure
CVE-2008-0140webappsphp
Directory traversal vulnerability in error.php in Uebimiau Webmail 2.7.10 and 2.7.2 allows remote authenticated users to
23RISK
open
ReferênciaVexDay Proof
Aprox CMS Engine 5.1.0.4 - Local File Inclusion
CVE-2008-2895webappsphp
Directory traversal vulnerability in index.php in AproxEngine 5.1.0.4 allows remote attackers to include and execute arb
23RISK
open
Referência
CVE-2010-1268
Directory traversal vulnerability in index.php in justVisual CMS 2.0, when magic_quotes_gpc is disabled, allows remote a
23RISK
open
Referência
CVE-2010-1268
Directory traversal vulnerability in index.php in justVisual CMS 2.0, when magic_quotes_gpc is disabled, allows remote a
23RISK
open
ReferênciaVexDay Proof
PHP weather 2.2.2 - Local File Inclusion / Cross-Site Scripting
CVE-2008-5771webappsphp
Directory traversal vulnerability in test.php in PHP Weather 2.2.2 allows remote attackers to include and execute arbitr
23RISK
open
Referência
CVE-2009-4628
SQL injection vulnerability in the TemplatePlaza.com TPDugg (com_tpdugg) component 1.1 for Joomla! allows remote attacke
23RISK
open
Referência
CVE-2010-1058
Directory traversal vulnerability in codelib/cfg/common.inc.php in Phpkobo Address Book Script 1.09, when magic_quotes_g
23RISK
open
Referência
CVE-2010-1058
Directory traversal vulnerability in codelib/cfg/common.inc.php in Phpkobo Address Book Script 1.09, when magic_quotes_g
23RISK
open
Referência
CVE-2020-15046
The web interface on Supermicro X10DRH-iT motherboards with BIOS 2.0a and IPMI firmware 03.40 allows remote attackers to
23RISK
open
Referência
CVE-2015-4624
Hak5 WiFi Pineapple 2.0 through 2.3 uses predictable CSRF tokens.
50RISK
open
ReferênciaVexDay Proof
BNCwi 1.04 - Local File Inclusion
CVE-2008-5948webappsphp
Directory traversal vulnerability in index.php in BNCwi 1.04 and earlier allows remote attackers to include and execute
23RISK
open
ReferênciaVexDay Proof
wotw 5.0 - Local/Remote File Inclusion
CVE-2008-6224webappsphp
Directory traversal vulnerability in visualizza.php in Way Of The Warrior (WOTW) 5.0 and earlier allows remote attackers
23RISK
open
ReferênciaVexDay Proof
Telephone Directory 2008 - Arbitrary Delete Contact
CVE-2008-7180webappsphp
del_query1.php in Telephone Directory 2008 allows remote attackers to delete arbitrary contacts via a direct request wit
23RISK
open
ReferênciaVexDay Proof
ClipShare 2.6 - Remote User Password Change
CVE-2008-7188webappsphp
ClipShare 2.6 does not properly restrict access to certain functionality, which allows remote attackers to change the pr
23RISK
open
Referência
CVE-2012-4993
torrent_functions.php in RivetTracker 1.03 and earlier does not properly restrict access, which allows remote attackers
23RISK
open
Referência
CVE-2010-1945
Multiple PHP remote file inclusion vulnerabilities in openMairie Openfoncier 2.00, when register_globals is enabled, all
23RISK
open
Referência
CVE-2010-2926
SQL injection vulnerability in index.php in sNews 1.7 allows remote attackers to execute arbitrary SQL commands via the
23RISK
open
previouspage 630 / 755next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.