Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,214cataloged exploits
36,016CVEs with public exploitation
24,695lab-tested
22,657 exploits
ReferênciaVexDay Proof
Alstrasoft Article Manager Pro 1.6 - Authentication Bypass
CVE-2008-5649webappsphp
SQL injection vulnerability in admin/admin.php in AlstraSoft Article Manager Pro 1.6 allows remote attackers to execute
23RISK
open
Referência
CVE-2016-9111
Incorrect access control mechanisms in Citrix Receiver Desktop Lock 4.5 allow an attacker to bypass the authentication r
23RISK
open
Referência
CVE-2016-9111
Incorrect access control mechanisms in Citrix Receiver Desktop Lock 4.5 allow an attacker to bypass the authentication r
23RISK
open
Referência7
CVE-2025-0364: BigAnt Server RCE Exploit
BigAntSoft BigAnt Server Account Registration Bypass to File Upload RCE
48RISK
open
Referência
CVE-2010-2143
Directory traversal vulnerability in index.php in Symphony CMS 2.0.7 allows remote attackers to read arbitrary files and
23RISK
open
Referência
CVE-2018-25371
mooSocial Store Plugin 2.6 SQL Injection via product parameter
41RISK
open
Referência
CVE-2018-25370
Admidio 3.3.5 Cross-Site Request Forgery via roles_function.php
33RISK
open
Referência
CVE-2018-25369
Visual Ping 0.8.0.0 Buffer Overflow Denial of Service
33RISK
open
ReferênciaVexDay Proof
Click N Print Coupons 2006.01 - 'key' SQL Injection
CVE-2006-6859webappsasp
SQL injection vulnerability in coupon_detail.asp in Website Designs For Less Click N' Print Coupons 2005.01 and earlier
23RISK
open
ReferênciaVexDay Proof
otscms 2.1.5 - SQL Injection / Cross-Site Scripting
CVE-2007-0846webappsphp
Cross-site scripting (XSS) vulnerability in forum.php in Open Tibia Server CMS (OTSCMS) 2.1.5 and earlier allows remote
23RISK
open
ReferênciaVexDay Proof
creative Guestbook 1.0 - Multiple Vulnerabilities
CVE-2007-1479webappsphp
Cross-site scripting (XSS) vulnerability in Guestbook.php in Creative Guestbook 1.0 allows remote attackers to inject ar
23RISK
open
Referência
CVE-2009-3368
Cross-site scripting (XSS) vulnerability in the Hotel Booking Reservation System (aka HBS or com_hbssearch) component fo
23RISK
open
Referência
CVE-2026-9295
Edimax BR-6428NS POST Request formWirelessTbl buffer overflow
41RISK
open
Referência
CVE-2014-6420
Cross-site scripting (XSS) vulnerability in Livefyre LiveComments 3.0 allows remote attackers to inject arbitrary web sc
23RISK
open
ReferênciaVexDay Proof
dnGuestbook 2.0 - SQL Injection
CVE-2006-1710webappsphp
SQL injection vulnerability in admin.php in Design Nation DNGuestbook 2.0 allows remote attackers to execute arbitrary S
23RISK
open
Referência
CVE-2005-4415
Cross-site scripting (XSS) vulnerability in index.php in TML CMS 0.5 allows remote attackers to inject arbitrary web scr
23RISK
open
Referência
CVE-2025-34042
Beward N100 IP Camera Remote Command Execution
48RISK
open
Referência
CVE-2025-34042
Beward N100 IP Camera Remote Command Execution
48RISK
open
Referência
CVE-2025-34042
Beward N100 IP Camera Remote Command Execution
48RISK
open
Referência
CVE-2019-9701
DLP 15.5 MP1 and all prior versions may be susceptible to a cross-site scripting (XSS) vulnerability, a type of issue th
23RISK
open
Referência
CVE-2024-53586
An issue in the relPath parameter of WebFileSys version 2.31.0 allows attackers to perform directory traversal via a cra
33RISK
open
Referência
CVE-2015-7358
The IsDriveLetterAvailable method in Driver/Ntdriver.c in TrueCrypt 7.0, VeraCrypt before 1.15, and CipherShed, when run
23RISK
open
Referência
CVE-2015-7358
The IsDriveLetterAvailable method in Driver/Ntdriver.c in TrueCrypt 7.0, VeraCrypt before 1.15, and CipherShed, when run
23RISK
open
Referência
CVE-2026-9294
Edimax BR-6428NS POST Request formWanTcpipSetup buffer overflow
41RISK
open
Referência
CVE-2020-13927
CVE-2020-13927CRITICALunder attack
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but th
100RISK
open
Referência
CVE-2018-10711
The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Str
23RISK
open
Referência
CVE-2009-3222
Cross-site scripting (XSS) vulnerability in index.php in FreeWebScriptz Honest Traffic (FWSHT) 1.x allows remote attacke
23RISK
open
Referência
CVE-2009-4403
Cross-site scripting (XSS) vulnerability in index.php in Rumba XML 1.8 allows remote attackers to inject arbitrary web s
23RISK
open
ReferênciaVexDay Proof
A-Link WL54AP3 / WL54AP2 - Cross-Site Request Forgery / Cross-Site Scripting
CVE-2008-6823remotehardware
Multiple cross-site request forgery (CSRF) vulnerabilities in the management interface on the A-LINK WL54AP3 and WL54AP2
23RISK
open
Referência
CVE-2014-9226
The management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center Security:
23RISK
open
previouspage 659 / 756next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.