Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,886cataloged exploits
32,153CVEs with public exploitation
1,932lab-tested
19,967 exploits
Referência
CVE-2024-24724
Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Re
53RISK
open
Referência
CVE-2010-3749
The browser-plugin implementation in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1 allows
28RISK
open
Referência
CVE-2020-28976
The Canto plugin 1.3.0 for WordPress contains a blind SSRF vulnerability. It allows an unauthenticated attacker can make
43RISK
open
Referência
CVE-2015-6086
Microsoft Internet Explorer 9 through 11 allows remote attackers to obtain sensitive information from process memory via
28RISK
open
Referência
CVE-2017-3548
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Integratio
28RISK
open
Referência
CVE-2021-21975
CVE-2021-21975HIGHunder attackransomware
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RISK
open
Referência
CVE-2018-8269
A denial of service vulnerability exists when OData Library improperly handles web requests, aka "OData Denial of Servic
28RISK
open
Referência
CVE-2012-1226
Multiple directory traversal vulnerabilities in Dolibarr CMS 3.2.0 Alpha allow remote attackers to read arbitrary files
43RISK
open
Referência
Simple Text-File Login script (SiTeFiLo) 1.0.6 - File Disclosure / Remote File Inclusion
PHP remote file inclusion vulnerability in slogin_lib.inc.php in Simple Text-File Login Script (SiTeFiLo) 1.0.6 allows r
28RISK
open
Referência
CVE-2004-1560
Microsoft SQL Server 7.0 allows remote attackers to cause a denial of service (mssqlserver service halt) via a long requ
28RISK
open
Referência
CVE-2016-1011
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows
28RISK
open
Referência
CVE-2016-1011
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows
28RISK
open
Referência
CVE-2018-0776
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitra
45RISK
open
Referência
Wavemaker Studio 6.6 - Server-Side Request Forgery
com/wavemaker/studio/StudioService.java in WaveMaker Studio 6.6 mishandles the studioService.download?method=getContent&
43RISK
open
Referência
CVE-2009-1492
The getAnnots Doc method in the JavaScript API in Adobe Reader and Acrobat 9.1, 8.1.4, 7.1.1, and earlier allows remote
28RISK
open
Referência
Adobe Reader 8.1.4/9.1 - 'GetAnnots()' Remote Code Execution
The getAnnots Doc method in the JavaScript API in Adobe Reader and Acrobat 9.1, 8.1.4, 7.1.1, and earlier allows remote
28RISK
open
Referência
ManageEngine OpManager 12.4x - Unauthenticated Remote Command Execution (Metasploit)
An issue was discovered in Zoho ManageEngine OpManager in builds before 14310. One can bypass the user password requirem
28RISK
open
Referência
CVE-2015-3073
Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass inten
28RISK
open
Referência
CVE-2013-2097
ZPanel through 10.1.0 has Remote Command Execution
43RISK
open
Referência
CVE-2013-2097
ZPanel through 10.1.0 has Remote Command Execution
43RISK
open
Referência
CVE-2019-16119
SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/control
28RISK
open
Referência
CVE-2016-4138
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsof
28RISK
open
Referência
CVE-2024-49138
CVE-2024-49138HIGHunder attack
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISK
open
Referência
Microsoft Windows 11 23h2 - CLFS.sys Elevation of Privilege
CVE-2024-49138HIGHunder attack
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISK
open
Referência
CVE-2016-2851
Integer overflow in proto.c in libotr before 4.1.1 on 64-bit platforms allows remote attackers to cause a denial of serv
28RISK
open
Referência
visualpic 0.3.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in VisualPic 0.3.1 allows remote attackers to execute arbitrary PHP
28RISK
open
Referência
CVE-2025-34036
Shenzhen TVT CCTV-DVR Command Injection
53RISK
open
Referência
CVE-2025-34036
Shenzhen TVT CCTV-DVR Command Injection
53RISK
open
Referência
CVE-2021-3278
Local Service Search Engine Management System 1.0 has a vulnerability through authentication bypass using SQL injection
28RISK
open
Referência
Local Service Search Engine Management System 1.0 - SQLi Authentication Bypass
Local Service Search Engine Management System 1.0 has a vulnerability through authentication bypass using SQL injection
28RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.