Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,137cataloged exploits
35,961CVEs with public exploitation
24,695lab-tested
22,657 exploits
Referência
CVE-2014-7176
SQL injection vulnerability in Enalean Tuleap before 7.5.99.4 allows remote authenticated users to execute arbitrary SQL
23RISK
open
Referência
CVE-2009-3949
cp/profile.php in VivaPrograms Infinity 2.0.5 and earlier does not require administrative authentication for the donewau
23RISK
open
Referência
CVE-2020-28092
PESCMS Team 2.3.2 has multiple reflected XSS via the id parameter:?g=Team&m=Task&a=my&status=3&id=,?g=Team&m=Task&a=my&s
23RISK
open
Referência
CVE-2018-10109
Monstra CMS 3.0.4 has a stored XSS vulnerability when an attacker has access to the editor role, and enters the payload
23RISK
open
Referência
CVE-2025-13188
D-Link DIR-816L authentication.cgi authenticationcgi_main stack-based overflow
48RISK
open
Referência
CVE-2015-5285
CRLF injection vulnerability in Kallithea before 0.3 allows remote attackers to inject arbitrary HTTP headers and conduc
23RISK
open
Referência
CVE-2009-3065
PHP remote file inclusion vulnerability in editor/edit_htmlarea.php in Ve-EDIT 0.1.4 allows remote attackers to execute
23RISK
open
Referência
CVE-2018-1203
In Dell EMC Isilon OneFS, the compadmin is able to run tcpdump binary with root privileges. In versions between 8.1.0.0
23RISK
open
Referência
CVE-2006-5209
PHP remote file inclusion vulnerability in admin/admin_topic_action_logging.php in Admin Topic Action Logging Mod 0.95 a
23RISK
open
Referência
CVE-2010-2005
Multiple PHP remote file inclusion vulnerabilities in DataLife Engine (DLE) 8.3 allow remote attackers to execute arbitr
23RISK
open
Referência
CVE-2016-7385
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 3
23RISK
open
ReferênciaVexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
CVE-2007-6504webappsasp
Unspecified vulnerability in IIS/iibind.asp in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticate
23RISK
open
Referência
CVE-2014-3857
Multiple SQL injection vulnerabilities in Kerio Control Statistics in Kerio Control (formerly WinRoute Firewall) before
23RISK
open
Referência
CVE-2014-3857
Multiple SQL injection vulnerabilities in Kerio Control Statistics in Kerio Control (formerly WinRoute Firewall) before
23RISK
open
Referência
CVE-2018-5976
Cross Site Request Forgery (CSRF) exists in RSVP Invitation Online 1.0 via function/account.php, as demonstrated by modi
23RISK
open
Referência
CVE-2017-1000474
Soyket Chowdhury Vehicle Sales Management System version 2017-07-30 is vulnerable to multiple SQL Injecting in login/veh
23RISK
open
Referência
CVE-2010-1498
Multiple SQL injection vulnerabilities in dl_stats before 2.0 allow remote attackers to execute arbitrary SQL commands v
23RISK
open
Referência
CVE-2010-1498
Multiple SQL injection vulnerabilities in dl_stats before 2.0 allow remote attackers to execute arbitrary SQL commands v
23RISK
open
Referência
CVE-2013-10054
LibrettoCMS File Manager Arbitrary File Upload
63RISK
open
Referência
CVE-2013-10054
LibrettoCMS File Manager Arbitrary File Upload
63RISK
open
Referência
CVE-2013-10054
LibrettoCMS File Manager Arbitrary File Upload
63RISK
open
ReferênciaVexDay Proof
Dokeos 1.6.5 - 'courseLog.php?scormcontopen' SQL Injection
CVE-2007-2889webappsphp
SQL injection vulnerability in tracking/courseLog.php in Dokeos 1.6.5 and earlier allows remote attackers to execute arb
23RISK
open
Referência
CVE-2012-4281
Multiple SQL injection vulnerabilities in Travelon Express 6.2.2 allow remote attackers to execute arbitrary SQL command
23RISK
open
ReferênciaVexDay Proof
PHPizabi 0.848b C1 HFP3 - Database Information Disclosure
CVE-2008-2018webappsphp
The AssignUser function in template.class.php in PHPizabi 0.848b C1 HFP3 performs unsafe macro expansions on strings del
23RISK
open
ReferênciaVexDay Proof
DreamNews Manager - 'id' SQL Injection
CVE-2008-3189webappsphp
SQL injection vulnerability in dreamnews-rss.php in DreamNews Manager allows remote attackers to execute arbitrary SQL c
23RISK
open
ReferênciaVexDay Proof
Joomla! Component Pony Gallery 1.5 - SQL Injection
CVE-2007-4046webappsphp
SQL injection vulnerability in index.php in the Pony Gallery (com_ponygallery) 1.5 and earlier component for Joomla! all
23RISK
open
ReferênciaVexDay Proof
P2P Foxy - Out of Memory Denial of Service
CVE-2008-6742doswindows
Foxy P2P software allows remote attackers to cause a denial of service (memory consumption) via a foxy URI with a downlo
23RISK
open
Referência
CVE-2015-5452
SQL injection vulnerability in Watchguard XCS 9.2 and 10.0 before build 150522 allows remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
xGB 2.0 - 'xGB.php' Remote Security Bypass
CVE-2007-4637webappsphp
xGB.php in xGB 2.0 does not require authentication for an admin edit action, which allows remote attackers to make unspe
23RISK
open
Referência
CVE-2016-0400
CRLF injection vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3, 7.1.1 before 7.1.1.1, 8.5 before 8.5.0
23RISK
open
previouspage 640 / 756next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.