Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,137cataloged exploits
35,961CVEs with public exploitation
24,695lab-tested
22,657 exploits
Referência
CVE-2017-16928
The arq_updater binary in Arq 5.10 and earlier for Mac allows local users to write to arbitrary files and consequently g
23RISK
open
ReferênciaVexDay Proof
Live Music Plus 1.1.0 - 'id' SQL Injection
CVE-2008-3352webappsphp
SQL injection vulnerability in index.php in Live Music Plus 1.1.0 allows remote attackers to execute arbitrary SQL comma
23RISK
open
Referência
CVE-2014-8727
Multiple directory traversal vulnerabilities in F5 BIG-IP before 10.2.2 allow local users with the "Resource Administrat
23RISK
open
Referência
CVE-2014-8727
Multiple directory traversal vulnerabilities in F5 BIG-IP before 10.2.2 allow local users with the "Resource Administrat
23RISK
open
Referência
CVE-2009-4617
Multiple SQL injection vulnerabilities in Tourism Script Accommodation Hotel Booking Portal Script allow remote attacker
23RISK
open
Referência
CVE-2010-3131
Untrusted search path vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 an
28RISK
open
ReferênciaVexDay Proof
Portail PHP 1.7 - 'chemin' Remote File Inclusion
CVE-2006-3922webappsphp
PHP remote file inclusion vulnerability in mod_membre/inscription.php in PortailPHP 1.7 allows remote attackers to execu
23RISK
open
ReferênciaVexDay Proof
Pligg CMS 9.9.0 - 'story.php' SQL Injection
CVE-2008-3366webappsphp
SQL injection vulnerability in story.php in Pligg CMS Beta 9.9.0 allows remote attackers to execute arbitrary SQL comman
23RISK
open
Referência
CVE-2015-3202
fusermount in FUSE before 2.9.3-15 does not properly clear the environment before invoking (1) mount or (2) umount as ro
23RISK
open
Referência
CVE-2015-3202
fusermount in FUSE before 2.9.3-15 does not properly clear the environment before invoking (1) mount or (2) umount as ro
23RISK
open
Referência
CVE-2016-1719
The IOHIDFamily API in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain pri
23RISK
open
Referência
CVE-2016-1719
The IOHIDFamily API in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain pri
23RISK
open
Referência
CVE-2016-1719
The IOHIDFamily API in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain pri
23RISK
open
Referência
CVE-2016-1719
The IOHIDFamily API in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain pri
23RISK
open
Referência
CVE-2016-1719
The IOHIDFamily API in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain pri
23RISK
open
ReferênciaVexDay Proof
Joomla! Component astatsPRO 1.0 - 'refer.php' SQL Injection
CVE-2008-0839webappsphp
SQL injection vulnerability in refer.php in the astatsPRO (com_astatspro) 1.0 component for Joomla! allows remote attack
23RISK
open
ReferênciaVexDay Proof
deeemm CMS (dmcms) 0.7.4 - Multiple Vulnerabilities
CVE-2008-3720webappsphp
SQL injection vulnerability in index.php in DeeEmm CMS (DMCMS) 0.7.4 allows remote attackers to execute arbitrary SQL co
23RISK
open
ReferênciaVexDay Proof
ASPSiteWare Home Builder 1.0/2.0 - SQL Injection
CVE-2008-5774webappsasp
Multiple SQL injection vulnerabilities in ASPSiteWare HomeBuilder 1.0 and 2.0 allow remote attackers to execute arbitrar
23RISK
open
ReferênciaVexDay Proof
MyCard 1.0.2 - 'id' SQL Injection
CVE-2008-4738webappsphp
SQL injection vulnerability in gallery.php in MyCard 1.0.2 allows remote attackers to execute arbitrary SQL commands via
23RISK
open
ReferênciaVexDay Proof
AIOCP 1.4 - 'poll_id' SQL Injection
CVE-2008-4782webappsphp
SQL injection vulnerability in public/code/cp_polls_results.php in All In One Control Panel (AIOCP) 1.4 allows remote at
23RISK
open
ReferênciaVexDay Proof
Mediatheka 4.2 - Blind SQL Injection
CVE-2008-5895webappsphp
SQL injection vulnerability in connection.php in Mediatheka 4.2 and earlier allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
AJSquare Free Polling Script - 'DB' Multiple Vulnerabilities
CVE-2008-7044webappsphp
SQL injection vulnerability in admin/include/newpoll.php in AJ Square Free Polling Script (AJPoll) Database version allo
23RISK
open
Referência
CVE-2012-2760
mod_auth_openid before 0.7 for Apache uses world-readable permissions for /tmp/mod_auth_openid.db, which allows local us
23RISK
open
Referência
CVE-2012-2760
mod_auth_openid before 0.7 for Apache uses world-readable permissions for /tmp/mod_auth_openid.db, which allows local us
23RISK
open
Referência
CVE-2009-5088
SQL injection vulnerability in secure/index.php in IdeaCart 0.02 allows remote attackers to execute arbitrary SQL comman
23RISK
open
Referência
CVE-2025-4318
Input validation issue in AWS Amplify Studio UI component properties
48RISK
open
Referência
CVE-2010-0795
SQL injection vulnerability in the JE Event Calendars (com_jeeventcalendar) component 1.0 for Joomla! allows remote atta
23RISK
open
Referência
CVE-2017-15962
iStock Management System 1.0 allows Arbitrary File Upload via user/profile.
23RISK
open
Referência
CVE-2008-3719
SQL injection vulnerability in directory.php in SFS Affiliate Directory allows remote attackers to execute arbitrary SQL
23RISK
open
Referência
CVE-2017-15962
iStock Management System 1.0 allows Arbitrary File Upload via user/profile.
23RISK
open
previouspage 635 / 756next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.