Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,137cataloged exploits
35,961CVEs with public exploitation
24,695lab-tested
22,657 exploits
ReferênciaVexDay Proof
Joomla! Component ds-syndicate - 'feed_id' SQL Injection
CVE-2008-4623webappsphp
SQL injection vulnerability in the DS-Syndicate (com_ds-syndicate) component 1.1.1 for Joomla allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
newsReporter 1.1 - 'index.php' Remote File Inclusion
CVE-2006-3988webappsphp
PHP remote file inclusion vulnerability in index.php in Knusperleicht newsReporter 1.1 and earlier allows remote attacke
23RISK
open
ReferênciaVexDay Proof
XOOPS Module makale 0.26 - SQL Injection
CVE-2008-4653webappsphp
SQL injection vulnerability in makale.php in Makale 0.26 and possibly other versions, a module for XOOPS, allows remote
23RISK
open
Referência
CVE-2017-17575
FS Groupon Clone 1.0 has SQL Injection via the item_details.php id parameter or the vendor_details.php id parameter.
23RISK
open
Referência
CVE-2026-12823
Browserbase Skills Autobrowse Trace Artifact default permission
33RISK
open
Referência
CVE-2017-20261
Joomla! Component Bargain Product VM3 1.0 SQL Injection
41RISK
open
Referência
CVE-2017-20260
Joomla! Component Price Alert 3.0.2 SQL Injection
41RISK
open
Referência
CVE-2017-20259
Joomla OSDownloads 1.7.4 SQL Injection via item view
41RISK
open
Referência
CVE-2017-20258
Joomla! Component RPC Responsive Portfolio 1.6.1 SQL Injection
41RISK
open
Referência
CVE-2026-8981
Lazy Blocks < 4.3.0 - Admin+ Stored XSS via Custom Block Frontend HTML
28RISK
open
Referência
CVE-2016-2386
CVE-2016-2386CRITICALunder attack
SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbi
100RISK
open
Referência
CVE-2016-2386
CVE-2016-2386CRITICALunder attack
SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbi
100RISK
open
Referência
CVE-2026-11585
CodeAstro Student Attendance Management System createClassArms.php sql injection
33RISK
open
Referência
CVE-2016-2386
CVE-2016-2386CRITICALunder attack
SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbi
100RISK
open
ReferênciaVexDay Proof
Libera CMS 1.12 - 'cookie' SQL Injection
CVE-2008-4700webappsphp
SQL injection vulnerability in admin.php in Libera CMS 1.12 and earlier, when magic_quotes_gpc is disabled, allows remot
23RISK
open
ReferênciaVexDay Proof
Top Auction 1.0 - 'viewcat.php' SQL Injection
CVE-2005-3952webappsphp
SQL injection vulnerability in PHP Labs Top Auction allows remote attackers to execute arbitrary SQL commands via the (1
23RISK
open
Referência
CVE-2026-8777
Edimax BR-6428NS POST Request formStaDrvSetup command injection
33RISK
open
Referência
CVE-2026-8776
Edimax BR-6428NS POST Request formPPTPSetup buffer overflow
41RISK
open
Referência
CVE-2026-7315
eiceblue spire-pdf-mcp-server PDF File server.py get_pdf_path path traversal
33RISK
open
Referência
CVE-2026-16979
SmartCrawl < 3.16.3 - Subscriber+ Private/Draft Post Title Disclosure and Post Meta Key Enumeration
33RISK
open
ReferênciaVexDay Proof
BosNews 4.0 - 'article' SQL Injection
CVE-2008-4703webappsphp
SQL injection vulnerability in news.php in BosDev BosNews 4.0 allows remote attackers to execute arbitrary SQL commands
23RISK
open
ReferênciaVexDay Proof
My PHP Dating - 'id' SQL Injection
CVE-2008-4705webappsphp
SQL injection vulnerability in success_story.php in php Online Dating Software MyPHPDating allows remote attackers to ex
23RISK
open
Referência
CVE-2026-18395
Child Pages Card < 1.09 - Contributor+ Stored XSS via Shortcode Attributes
33RISK
open
Referência
CVE-2026-16065
Welcart e-Commerce < 2.11.32 - Editor+ SQL Injection via CSV Import
33RISK
open
Referência
CVE-2010-3404
Multiple SQL injection vulnerabilities in eshtery CMS (aka eshtery.com) allow remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
1st News - SQL Injection
CVE-2008-4890webappsphp
SQL injection vulnerability in products.php in 1st News 4 Professional (PR 1) allows remote attackers to execute arbitra
23RISK
open
Referência
CVE-2016-3081
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, a
60RISK
open
Referência
CVE-2026-14829
Checkimate <= 1.0.13 - Unauthenticated License Deactivation via Hardcoded Secret
41RISK
open
Referência
CVE-2026-75130
Context7 2.1.2 Prompt Injection via Custom AI Instructions
33RISK
open
Referência
CVE-2026-10875
projectworlds Online Art Gallery Shop Project adminHome.ph sql injection
33RISK
open
previouspage 656 / 756next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.