Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,137cataloged exploits
35,961CVEs with public exploitation
24,695lab-tested
22,657 exploits
ReferênciaVexDay Proof
Webace-Linkscript 1.3 SE - 'start.php' SQL Injection
CVE-2007-4846webappsphp
SQL injection vulnerability in start.php in Webace-Linkscript (wls) 1.3 Special Edition (SE) allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
YourFreeWorld Shopping Cart - Blind SQL Injection
CVE-2008-4886webappsphp
SQL injection vulnerability in index.php in YourFreeWorld Shopping Cart Script allows remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
sCssBoard (Multiple Versions) - 'pwnpack' Remote s
CVE-2008-5577webappsphp
PHP remote file inclusion vulnerability in index.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allows remote attackers to ex
23RISK
open
ReferênciaVexDay Proof
TorrentTrader Classic 1.09 - Multiple Vulnerabilities
CVE-2009-2161webappsphp
Directory traversal vulnerability in backend/admin-functions.php in TorrentTrader Classic 1.09, when used on a case-inse
23RISK
open
Referência
CVE-2013-0928
The NetWorker command processor in rrobotd.exe in the Device Manager in EMC AlphaStor 4.0 before build 800 allows remote
50RISK
open
Referência
CVE-2017-16807
A cross-site Scripting (XSS) vulnerability in Kirby Panel before 2.3.3, 2.4.x before 2.4.2, and 2.5.x before 2.5.7 exist
23RISK
open
Referência
CVE-2009-2642
index.php in Desi Short URL Script 1.0 allows remote attackers to bypass authentication by setting the logged cookie to
23RISK
open
ReferênciaVexDay Proof
Postfix 2.6-20080814 - 'symlink' Local Privilege Escalation
CVE-2008-2936locallinux
Postfix before 2.3.15, 2.4 before 2.4.8, 2.5 before 2.5.4, and 2.6 before 2.6-20080814, when the operating system suppor
23RISK
open
Referência
CVE-2012-5912
Multiple SQL injection vulnerabilities in PicoPublisher 2.0 allow remote attackers to execute arbitrary SQL commands via
23RISK
open
Referência
CVE-2012-5912
Multiple SQL injection vulnerabilities in PicoPublisher 2.0 allow remote attackers to execute arbitrary SQL commands via
23RISK
open
Referência
CVE-2026-5316
Nothings stb stb_vorbis.c setup_free allocation of resources
33RISK
open
Referência
CVE-2019-10847
Computrols CBAS 18.0.0 allows Cross-Site Request Forgery.
23RISK
open
Referência
CVE-2009-2558
system/message.php in Admin News Tools 2.5 does not properly restrict access, which allows remote attackers to post news
23RISK
open
Referência
CVE-2009-4106
Unrestricted file upload vulnerability in admintools/editpage-2.php in Agoko CMS 0.4 and earlier allows remote attackers
23RISK
open
Referência
CVE-2010-2850
Directory traversal vulnerability in productionnu2/fileuploader.php in nuBuilder 10.04.20, and possibly other versions b
23RISK
open
Referência
CVE-2009-4674
admin/admin.php in Mole Group Sky Hunter Airline Ticket Sale Script and Bus Ticket Script allows remote attackers to cha
23RISK
open
Referência
CVE-2015-3897
Directory traversal vulnerability in Bonita BPM Portal before 6.5.3 allows remote attackers to read arbitrary files via
43RISK
open
Referência
CVE-2010-3437
Integer signedness error in the pkt_find_dev_from_minor function in drivers/block/pktcdvd.c in the Linux kernel before 2
23RISK
open
Referência
CVE-2010-4980
SQL injection vulnerability in packagedetails.php in iScripts ReserveLogic 1.0 allows remote attackers to execute arbitr
23RISK
open
Referência
CVE-2010-4980
SQL injection vulnerability in packagedetails.php in iScripts ReserveLogic 1.0 allows remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
iyzi Forum 1.0b3 - Database Disclosure
CVE-2008-5901webappsphp
iyzi Forum 1.0 beta 3 stores sensitive information under the web root with insufficient access control, which allows rem
23RISK
open
ReferênciaVexDay Proof
GGCMS 1.1.0 RC1 - Remote Code Execution
CVE-2007-0804webappsphp
Directory traversal vulnerability in admin/subpages.php in GGCMS 1.1.0 RC1 and earlier allows remote attackers to inject
23RISK
open
ReferênciaVexDay Proof
Garennes 0.6.1 - 'repertoire_config' Remote File Inclusion
CVE-2007-2298webappsphp
Multiple PHP remote file inclusion vulnerabilities in Garennes 0.6.1 and earlier allow remote attackers to execute arbit
23RISK
open
ReferênciaVexDay Proof
GoSamba 1.0.1 - 'INCLUDE_PATH' Multiple Remote File Inclusions
CVE-2007-5786webappsphp
Multiple PHP remote file inclusion vulnerabilities in GoSamba 1.0.1 allow remote attackers to execute arbitrary PHP code
23RISK
open
Referência
CVE-2012-4871
Cross-site scripting (XSS) vulnerability in service/graph_html.php in the administrator panel in LiteSpeed Web Server 4.
23RISK
open
Referência
CVE-2010-2906
SQL injection vulnerability in articlesdetails.php in ScriptsFeed and BrotherScripts (BS) Scripts Directory allows remot
23RISK
open
Referência
CVE-2018-6563
Multiple cross-site request forgery (CSRF) vulnerabilities in totemomail Encryption Gateway before 6.0.0_Build_371 allow
23RISK
open
Referência
CVE-2018-6563
Multiple cross-site request forgery (CSRF) vulnerabilities in totemomail Encryption Gateway before 6.0.0_Build_371 allow
23RISK
open
Referência
CVE-2010-4918
PHP remote file inclusion vulnerability in iJoomla Magazine (com_magazine) component 3.0.1 for Joomla! allows remote att
23RISK
open
Referência
CVE-2010-4918
PHP remote file inclusion vulnerability in iJoomla Magazine (com_magazine) component 3.0.1 for Joomla! allows remote att
23RISK
open
previouspage 633 / 756next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.