Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,137cataloged exploits
35,961CVEs with public exploitation
24,695lab-tested
22,657 exploits
Referência
CVE-2009-4626
Directory traversal vulnerability in menu.php in phpNagios 1.2.0 allows remote attackers to include and execute arbitrar
23RISK
open
Referência
CVE-2021-3186
A Stored Cross-site scripting (XSS) vulnerability in /main.html Wifi Settings in Tenda AC5 AC1200 version V15.03.06.47_m
23RISK
open
Referência
CVE-2017-17649
Readymade Video Sharing Script 3.2 has HTML Injection via the single-video-detail.php comment parameter.
23RISK
open
Referência
CVE-2018-15884
RICOH MP C4504ex devices allow HTML Injection via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn parameter.
23RISK
open
Referência
CVE-2018-15884
RICOH MP C4504ex devices allow HTML Injection via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn parameter.
23RISK
open
Referência
CVE-2009-4118
The StartServiceCtrlDispatcher function in the cvpnd service (cvpnd.exe) in Cisco VPN client for Windows before 5.0.06.0
23RISK
open
Referência
CVE-2026-19036
Shibby Tomato wanoptions sub_40F88C os command injection
41RISK
open
Referência
CVE-2018-16252
FsPro Labs Event Log Explorer 4.6.1.2115 has ".elx" FileType XML External Entity Injection.
23RISK
open
Referência
CVE-2019-13657
CA Performance Management 3.5.x, 3.6.x before 3.6.9, and 3.7.x before 3.7.4 have a default credential vulnerability that
48RISK
open
Referência
CVE-2019-13657
CA Performance Management 3.5.x, 3.6.x before 3.6.9, and 3.7.x before 3.7.4 have a default credential vulnerability that
48RISK
open
Referência
CVE-2013-7193
Multiple SQL injection vulnerabilities in C2C Forward Auction Creator 2.0 allow remote attackers to execute arbitrary SQ
23RISK
open
ReferênciaVexDay Proof
ASP.NET w3wp - COM Components Remote Crash
CVE-2006-1364doswindows
Microsoft w3wp (aka w3wp.exe) does not properly handle when the AspCompat directive is not used when referencing COM com
35RISK
open
ReferênciaVexDay Proof
Mini Blog 1.0.1 - 'index.php' Multiple Local File Inclusions
CVE-2008-5594webappsphp
Multiple directory traversal vulnerabilities in index.php in Mini Blog 1.0.1 allow remote attackers to include and execu
23RISK
open
ReferênciaVexDay Proof
AJ Auction - Authentication Bypass
CVE-2008-6966webappsphp
AJ Square AJ Auction Pro Platinum Skin #1 sends a redirect but does not exit when it is called directly, which allows re
23RISK
open
Referência
CVE-2026-40521
FrontAccounting < 2.4.20 Path Traversal RCE via attachment upload
41RISK
open
ReferênciaVexDay Proof
Enthrallweb eClassifieds 1.0 - Remote User Pass Change
CVE-2006-6822webappsasp
myprofile.asp in Enthrallweb eClassifieds does not properly validate the MM_recordId parameter during profile updates, w
23RISK
open
ReferênciaVexDay Proof
Tuned Studios Templates - Local File Inclusion
CVE-2008-0231webappsphp
Multiple directory traversal vulnerabilities in index.php in Tuned Studios (1) Subwoofer, (2) Freeze Theme, (3) Orange C
23RISK
open
Referência
CVE-2012-4266
Cross-site scripting (XSS) vulnerability in client_details.php in Proman Xpress 5.0.1 allows remote attackers to inject
23RISK
open
Referência
CVE-2011-5209
Cross-site scripting (XSS) vulnerability in search/ in GraphicsClone Script, possibly 1.11, allows remote attackers to i
23RISK
open
Referência
CVE-2012-4278
Multiple cross-site scripting (XSS) vulnerabilities in Free Realty 3.1-0.6 allow remote attackers to inject arbitrary we
23RISK
open
Referência
CVE-2017-1000432
Vanilla Forums below 2.1.5 are affected by CSRF leading to Deleting topics and comments from forums Admin access
23RISK
open
Referência
CVE-2010-4608
Habari 0.6.5 allows remote attackers to obtain sensitive information via a direct request to (1) header.php and (2) comm
23RISK
open
Referência
CVE-2010-4611
Html-edit CMS 3.1.8 allows remote attackers to obtain sensitive information via a direct request to (1) pages.php and (2
23RISK
open
Referência
CVE-2009-2293
Optimum Web Design Tutorial Share 3.5.0 and earlier allows remote attackers to bypass authentication and obtain administ
23RISK
open
Referência
CVE-2024-6159
Push Notification for Post and BuddyPress <=1.93 - Multiple Unauthenticated SQLi
63RISK
open
Referência
CVE-2010-1708
Multiple SQL injection vulnerabilities in agentadmin.php in Free Realty allow remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
ProManager 0.73 - 'config.php' Local File Inclusion
CVE-2008-2687webappsphp
Directory traversal vulnerability in inc/config.php in ProManager 0.73 allows remote attackers to include and execute ar
23RISK
open
Referência
CVE-2010-1922
Multiple PHP remote file inclusion vulnerabilities in 29o3 CMS 0.1 allow remote attackers to execute arbitrary PHP code
23RISK
open
Referência
CVE-2010-1922
Multiple PHP remote file inclusion vulnerabilities in 29o3 CMS 0.1 allow remote attackers to execute arbitrary PHP code
23RISK
open
Referência
CVE-2016-5195
CVE-2016-5195HIGHunder attack
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
previouspage 653 / 756next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.