Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

72,018cataloged exploits
32,219CVEs with public exploitation
1,932lab-tested
20,023 exploits
Referência
CVE-2015-6098
Buffer overflow in the Network Driver Interface Standard (NDIS) implementation in Microsoft Windows Vista SP2, Windows S
23RISK
open
Referência
CVE-2018-8410
An elevation of privilege vulnerability exists when the Windows Kernel API improperly handles registry objects in memory
23RISK
open
Referência
Excel Viewer OCX 3.1.0.6 - Multiple Denial of Service Vulnerabilities
Multiple stack-based buffer overflows in the ExcelOCX ActiveX control in ExcelViewer.ocx 3.1.0.6 allow remote attackers
23RISK
open
Referência
CVE-2020-13118
An issue was discovered in Mikrotik-Router-Monitoring-System through 2018-10-22. SQL Injection exists in check_community
23RISK
open
Referência
CVE-2013-2294
Multiple cross-site scripting (XSS) vulnerabilities in ViewGit before 0.0.7 allow remote repository users to inject arbi
23RISK
open
Referência
CVE-2013-2294
Multiple cross-site scripting (XSS) vulnerabilities in ViewGit before 0.0.7 allow remote repository users to inject arbi
23RISK
open
Referência
CVE-2014-8690
Multiple cross-site scripting (XSS) vulnerabilities in Exponent CMS before 2.1.4 patch 6, 2.2.x before 2.2.3 patch 9, an
23RISK
open
Referência
CVE-2014-8690
Multiple cross-site scripting (XSS) vulnerabilities in Exponent CMS before 2.1.4 patch 6, 2.2.x before 2.2.3 patch 9, an
23RISK
open
Referência
ScriptsFeed (SF) Auto Classifieds Software - Arbitrary File Upload
Unrestricted file upload vulnerability in ScriptsFeed Auto Classifieds allows remote authenticated users to execute arbi
23RISK
open
Referência
OpenSSL 0.9.8c-1 < 0.9.8g-9 (Debian and Derivatives) - Predictable PRNG Brute Force SSH
It was found that various OpenID Providers (OPs) had TLS Server Certificates that used weak keys, as a result of the Deb
23RISK
open
Referência
X-Forum 0.6.2 - Remote Command Execution
Static code injection vulnerability in X-Forum 0.6.2 allows remote authenticated administrators to inject arbitrary PHP
23RISK
open
Referência
CVE-2016-1915
Multiple cross-site scripting (XSS) vulnerabilities in BlackBerry Enterprise Server 12 (BES12) Self-Service before 12.4
23RISK
open
Referência
ScriptsFeed (SF) Real Estate Classifieds Software - Arbitrary File Upload
Unrestricted file upload vulnerability in ScriptsFeed Realtor Classifieds System (aka Real Estate Classifieds) allows re
23RISK
open
Referência
ScriptsFeed (SF) Recipes Listing Portal - Arbitrary File Upload
Unrestricted file upload vulnerability in ScriptsFeed Recipes Listing Portal allows remote authenticated users to execut
23RISK
open
Referência
OpenEMR 2.8.1 - 'srcdir' Multiple Remote File Inclusions
PHP remote file inclusion vulnerability in library/translation.inc.php in OpenEMR 2.8.1, with register_globals enabled,
23RISK
open
Referência
MiniBB 2.0.5 - 'Language' Local File Inclusion
Directory traversal vulnerability in index.php in MiniBB 2.0.5 allows remote attackers to read arbitrary files via a ..
23RISK
open
Referência
phpBB User Viewed Posts Tracker 1.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in includes/functions_user_viewed_posts.php in the Nivisec User Viewed Posts Tra
23RISK
open
Referência
CVE-2017-15957
my_profile.php in Ingenious School Management System 2.3.0 allows a student or teacher to upload an arbitrary file.
23RISK
open
Referência
CVE-2017-15957
my_profile.php in Ingenious School Management System 2.3.0 allows a student or teacher to upload an arbitrary file.
23RISK
open
Referência
DZCP (deV!L_z Clanportal) 1.4.5 - Remote File Disclosure
inc/filebrowser/browser.php in deV!L`z Clanportal (DZCP) 1.4.5 and earlier allows remote attackers to obtain MySQL data
23RISK
open
Referência
CVE-2006-5762
PHP remote file inclusion vulnerability in forgot_pass.php in Free File Hosting 1.1 and earlier allows remote attackers
23RISK
open
Referência
Free File Hosting 1.1 - 'forgot_pass.php' File Inclusion
PHP remote file inclusion vulnerability in forgot_pass.php in Free File Hosting 1.1 and earlier allows remote attackers
23RISK
open
Referência
CVE-2025-15255
Tenda W6-S R7websSsecurityHandler httpd stack-based overflow
48RISK
open
Referência
Exhibit Engine 1.22 - 'styles.php' Remote File Inclusion
PHP remote file inclusion vulnerability in styles.php in Exhibit Engine (EE) 1.22 and earlier allows remote attackers to
23RISK
open
Referência
CVE-2017-2510
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The
23RISK
open
Referência
CVE-2008-5821
Memory leak in WebKit.dll in WebKit, as used by Apple Safari 3.2 on Windows Vista SP1, allows remote attackers to cause
23RISK
open
Referência
CVE-2012-10060
Sysax Multi Server < 5.55 SSH Username Buffer Overflow
63RISK
open
Referência
CVE-2012-10060
Sysax Multi Server < 5.55 SSH Username Buffer Overflow
63RISK
open
Referência
CVE-2017-10046
Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (
23RISK
open
Referência
CVE-2017-9260
The TDStretchSSE::calcCrossCorr function in source/SoundTouch/sse_optimized.cpp in SoundTouch 1.9.2 allows remote attack
23RISK
open
previouspage 148 / 668next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.