Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,957cataloged exploits
32,195CVEs with public exploitation
1,932lab-tested
20,003 exploits
Referência
CVE-2022-24263
Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-m
23RISK
open
Referência
CVE-2018-8533
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing malicious X
28RISK
open
Referência
CVE-2010-3135
Untrusted search path vulnerability in Cisco Packet Tracer 5.2 allows local users, and possibly remote attackers, to exe
23RISK
open
Referência
CVE-2017-10682
SQL injection vulnerability in the administrative backend in Piwigo through 2.9.1 allows remote users to execute arbitra
23RISK
open
Referência
CVE-2016-9332
An issue was discovered in Moxa SoftCMS versions prior to Version 1.6. Moxa SoftCMS Webserver does not properly validate
23RISK
open
Referência
LinkedIn Toolbar 3.0.2.1098 - Remote Buffer Overflow
Buffer overflow in the IEToolbar.IEContextMenu.1 ActiveX control in LinkedInIEToolbar.dll in the LinkedIn Toolbar 3.0.2.
23RISK
open
Referência
CVE-2021-34369
portlets/contact/ref/refContactDetail.do in Accela Civic Platform through 20.1 allows remote attackers to obtain sensiti
23RISK
open
Referência
CVE-2021-40964
A Path Traversal vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to
23RISK
open
Referência
CVE-2010-1315
Directory traversal vulnerability in weberpcustomer.php in the webERPcustomer (com_weberpcustomer) component 1.2.1 and 1
38RISK
open
Referência
CVE-2010-1540
Directory traversal vulnerability in index.php in the MyBlog (com_myblog) component 3.0.329 for Joomla! allows remote at
38RISK
open
Referência
CVE-2010-1461
Directory traversal vulnerability in the Photo Battle (com_photobattle) component 1.0.1 for Joomla! allows remote attack
38RISK
open
Referência
X-Cart - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in X-Cart allow remote attackers to execute arbitrary PHP code via a
23RISK
open
Referência
Opera Web Browser 9.00 - 'iframe' Remote Denial of Service
Opera 9 allows remote attackers to cause a denial of service (crash) via a crafted web page that triggers an out-of-boun
23RISK
open
Referência
CVE-2019-17080
mintinstall (aka Software Manager) 7.9.9 for Linux Mint allows code execution if a REVIEWS_CACHE file is controlled by a
23RISK
open
Referência
CVE-2014-2021
Cross-site scripting (XSS) vulnerability in admincp/apilog.php in vBulletin 4.2.2 and earlier, and 5.0.x through 5.0.5 a
23RISK
open
Referência
CVE-2017-14322
The function in charge to check whether the user is already logged in init.php in Interspire Email Marketer (IEM) prior
35RISK
open
Referência
Foxit Reader 2.0 - 'PDF' Remote Denial of Service
Foxit Reader 2.0 allows remote attackers to cause a denial of service (application crash) via a crafted PDF document.
23RISK
open
Referência
Opera 9.2 - '.torrent' Remote Denial of Service
The BitTorrent implementation in Opera 9.2 allows remote attackers to cause a denial of service (CPU consumption and app
23RISK
open
Referência
CVE-2013-6025
The XMLParse procedure in SAP Sybase Adaptive Server Enterprise (ASE) 15.7 ESD 2 allows remote authenticated users to re
23RISK
open
Referência
phpMyNewsletter 0.8 (beta5) - Multiple Vulnerabilities
admin/send_mod.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier prints a Location header but does not exit
23RISK
open
Referência
Data Dynamics ActiveBar (Actbar3.ocx 3.2) - Multiple Insecure Methods
The Data Dynamics ActiveBar ActiveX control (actbar3.ocx) 3.2 and earlier allows remote attackers to create or overwrite
23RISK
open
Referência
Data Dynamics ActiveBar - ActiveX 'actbar3.ocx 3.1' Insecure Methods
The Data Dynamics ActiveBar ActiveX control (actbar3.ocx) 3.2 and earlier allows remote attackers to create or overwrite
23RISK
open
Referência
CVE-2017-2446
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RISK
open
Referência
CVE-2017-2446
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RISK
open
Referência
CVE-2007-3162
Buffer overflow in the NotSafe function in the idaiehlp ActiveX control in idaiehlp.dll 1.9.1.74 in Internet Download Ac
23RISK
open
Referência
Internet Download Accelerator 5.2 - Remote Buffer Overflow (PoC)
Buffer overflow in the NotSafe function in the idaiehlp ActiveX control in idaiehlp.dll 1.9.1.74 in Internet Download Ac
23RISK
open
Referência
CVE-2019-16645
An issue was discovered in Embedthis GoAhead 2.5.0. Certain pages (such as goform/login and config/log_off_page.htm) cre
23RISK
open
Referência
CVE-2019-15501
Reflected cross site scripting (XSS) in L-Soft LISTSERV before 16.5-2018a exists via the /scripts/wa.exe OK parameter.
38RISK
open
Referência
LSoft ListServ < 16.5-2018a - Cross-Site Scripting
Reflected cross site scripting (XSS) in L-Soft LISTSERV before 16.5-2018a exists via the /scripts/wa.exe OK parameter.
38RISK
open
Referência
Miplex2 - 'SmartyFU.class.php' Remote File Inclusion
PHP remote file inclusion vulnerability in lib/smarty/SmartyFU.class.php in Miplex2 Alpha 1 allows remote attackers to e
23RISK
open
previouspage 135 / 667next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.