Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

72,018cataloged exploits
32,219CVEs with public exploitation
1,932lab-tested
20,023 exploits
Referência
CVE-2018-25120
D-Link DNS-343 ShareCenter <= 1.05 Command Injection via /goform/Mail_Test
48RISK
open
Referência
CVE-2018-25120
D-Link DNS-343 ShareCenter <= 1.05 Command Injection via /goform/Mail_Test
48RISK
open
Referência
CVE-2018-25120
D-Link DNS-343 ShareCenter <= 1.05 Command Injection via /goform/Mail_Test
48RISK
open
Referência
CVE-2011-2757
Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0.0.12 and earlier allows remot
50RISK
open
Referência
Axigen 2.0.0b1 - Remote Denial of Service (1)
Heap-based buffer underflow in axigen 1.2.6 through 2.0.0b1 allows remote attackers to cause a denial of service (applic
23RISK
open
Referência
CVE-2016-5678
NUUO NVRmini 2 1.0.0 through 3.0.0 and NUUO NVRsolo 1.0.0 through 3.0.0 have hardcoded root credentials, which allows re
23RISK
open
Referência
Chilkat XML - ActiveX Arbitrary File Creation/Execution
The Chilkat XML ChilkatUtil.CkData.1 ActiveX control (ChilkatUtil.dll) 3.0.3.0 and earlier allows remote attackers to cr
23RISK
open
Referência
CVE-2021-26828
CVE-2021-26828HIGHunder attack
OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and exe
83RISK
open
Referência
IrfanView 4.10 - '.fpx' Memory Corruption
fpx.dll 3.9.8.0 in the FlashPix plugin for IrfanView 4.10 allows remote attackers to execute arbitrary code via a crafte
23RISK
open
Referência
NewsOffice 1.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in news_show.php in Newanz NewsOffice 1.0 and 1.1, when register_globals is enab
35RISK
open
Referência
CVE-2020-25494
Xinuos (formerly SCO) Openserver v5 and v6 allows attackers to execute arbitrary commands via shell metacharacters in ou
35RISK
open
Referência
CVE-2012-6500
Directory traversal vulnerability in download.lib.php in Pragyan CMS 3.0 and earlier allows remote attackers to read arb
23RISK
open
Referência
CVE-2004-2116
Directory traversal vulnerability in Tiny Server 1.1 allows remote attackers to read or download arbitrary files via a .
23RISK
open
Referência
CVE-2009-2550
Stack-based buffer overflow in Hamster Audio Player 0.3a allows remote attackers to execute arbitrary code via a long st
23RISK
open
Referência
CVE-2009-2550
Stack-based buffer overflow in Hamster Audio Player 0.3a allows remote attackers to execute arbitrary code via a long st
23RISK
open
Referência
CVE-2010-3313
phpgwapi/js/fckeditor/editor/dialog/fck_spellerpages/spellerpages/serverscripts/spellchecker.php in EGroupware 1.4.001+.
23RISK
open
Referência
CVE-2015-7622
Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.
28RISK
open
Referência
Corel WordPerfect X3 13.0.0.565 - '.prs' Local Buffer Overflow
Stack-based buffer overflow in Corel WordPerfect Office X3 (13.0.0.565) allows user-assisted remote attackers to execute
23RISK
open
Referência
CVE-2016-0051
The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Window
43RISK
open
Referência
CVE-2012-0406
The DPA_Utilities.cProcessAuthenticationData function in EMC Data Protection Advisor (DPA) 5.5 through 5.8 SP1 allows re
23RISK
open
Referência
zKup CMS 2.0 < 2.3 - Arbitrary File Upload
zKup CMS 2.0 through 2.3 does not require administrative authentication for admin/configuration/modifier.php, which allo
23RISK
open
Referência
zKup CMS 2.0 < 2.3 - Remote Add Admin
zKup CMS 2.0 through 2.3 does not require administrative authentication for admin/configuration/modifier.php, which allo
23RISK
open
Referência
AGTC MyShop 3.2 - Insecure Cookie Handling
AGTC MyShop 3.2b allows remote attackers to bypass authentication and obtain administrative access setting the log_accep
23RISK
open
Referência
CVE-2010-2307
Multiple directory traversal vulnerabilities in the web server for Motorola SURFBoard cable modem SBV6120E running firmw
38RISK
open
Referência
ooVoo 1.7.1.35 - 'URL Protocol' Remote Unicode Buffer Overflow (PoC)
Buffer overflow in oovoo.exe in ooVoo 1.7.1.35, and possibly other versions before 1.7.1.59, allows remote attackers to
23RISK
open
Referência
V-Webmail 1.6.4 - 'pear_dir' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/mailaccess/pop3/core.php in V-Webmail 1.3 allows remote attackers to
23RISK
open
Referência
CVE-2007-2482
Directory traversal vulnerability in wordtube-button.php in the wordTube 1.43 and earlier plugin for WordPress, when reg
23RISK
open
Referência
CVE-2019-9650
An XSS issue was discovered in upcoming_events.php in the Upcoming Events plugin before 1.33 for MyBB via a crafted name
23RISK
open
Referência
CVE-2019-9650
An XSS issue was discovered in upcoming_events.php in the Upcoming Events plugin before 1.33 for MyBB via a crafted name
23RISK
open
Referência
Microsoft Windows Explorer - '.zip' Denial of Service
Windows Explorer in Microsoft Windows XP SP3 allows user-assisted attackers to cause a denial of service (application cr
23RISK
open
previouspage 151 / 668next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.