Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,445cataloged exploits
34,432CVEs with public exploitation
24,695lab-tested
21,497 exploits
Referência
CVE-2014-9633
The bdisk.sys driver in COMODO Backup before 4.4.1.23 allows remote attackers to gain privileges via a crafted device ha
23RISK
open
Referência
CVE-2017-9742
The score_opcodes function in opcodes/score7-dis.c in GNU Binutils 2.28 allows remote attackers to cause a denial of ser
23RISK
open
Referência
CVE-2017-9756
The aarch64_ext_ldst_reglist function in opcodes/aarch64-dis.c in GNU Binutils 2.28 allows remote attackers to cause a d
23RISK
open
Referência
CVE-2008-0729
Mobile Safari on Apple iPhone 1.1.2 and 1.1.3 allows remote attackers to cause a denial of service (memory exhaustion an
23RISK
open
Referência
CVE-2018-19287
XSS in the Ninja Forms plugin before 3.3.18 for WordPress allows Remote Attackers to execute JavaScript via the includes
38RISK
open
Referência
CVE-2022-0848
OS Command Injection in part-db/part-db
60RISK
open
Referência
CVE-2014-8493
ZTE ZXHN H108L with firmware 4.0.0d_ZRQ_GR4 allows remote attackers to modify the CWMP configuration via a crafted reque
23RISK
open
Referência
CVE-2014-8493
ZTE ZXHN H108L with firmware 4.0.0d_ZRQ_GR4 allows remote attackers to modify the CWMP configuration via a crafted reque
23RISK
open
Referência
CVE-2016-1607
Multiple cross-site request forgery (CSRF) vulnerabilities in the administrative interface in Novell Filr before 2.0 Sec
23RISK
open
Referência
CVE-2019-12900
BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.
48RISK
open
Referência
CVE-2019-12900
BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.
48RISK
open
Referência
CVE-2017-6823
Fiyo CMS 2.0.6.1 allows remote authenticated users to gain privileges via a modified level parameter to dapur/ in an app
23RISK
open
Referência
CVE-2017-2491
Use after free vulnerability in the String.replace method JavaScriptCore in Apple Safari in iOS before 10.3 allows remot
23RISK
open
Referência
CVE-2015-3000
SysAid Help Desk before 15.2 allows remote attackers to cause a denial of service (CPU and memory consumption) via a lar
23RISK
open
Referência
CVE-2012-3816
WinRadius Server 2009 allows remote attackers to cause a denial of service (crash) via a long password in an Access-Requ
23RISK
open
Referência
CVE-2019-8404
An issue was discovered in Webiness Inventory 2.3. The ProductModel component allows Arbitrary File Upload via a crafted
23RISK
open
Referência
CVE-2019-8404
An issue was discovered in Webiness Inventory 2.3. The ProductModel component allows Arbitrary File Upload via a crafted
23RISK
open
Referência
CVE-2017-1000367
Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_
23RISK
open
Referência
CVE-2017-1000367
Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_
23RISK
open
ReferênciaVexDay Proof
TOSMO/Mambo 1.4.13a - 'absolute_path' Remote File Inclusion
CVE-2007-2317webappsphp
Multiple PHP remote file inclusion vulnerabilities in MiniBB Forum 1.5a and earlier, as used by TOSMO/Mambo 4.0.12 and p
23RISK
open
ReferênciaVexDay Proof
FirmWorX 0.1.2 - Multiple Remote File Inclusions
CVE-2007-2891webappsphp
Multiple PHP remote file inclusion vulnerabilities in FirmWorX 0.1.2 allow remote attackers to execute arbitrary PHP cod
23RISK
open
ReferênciaVexDay Proof
NVR SP2 2.0 'nvUtility.dll 1.0.14.0' - 'DeleteXMLFile()' Insecure Method
CVE-2007-4583remotewindows
Multiple absolute path traversal vulnerabilities in the nvUtility.Utility.1 ActiveX control in nvUtility.dll 1.0.14.0 in
23RISK
open
ReferênciaVexDay Proof
NVR SP2 2.0 'nvUtility.dll 1.0.14.0' - 'SaveXMLFile()' Insecure Method
CVE-2007-4583remotewindows
Multiple absolute path traversal vulnerabilities in the nvUtility.Utility.1 ActiveX control in nvUtility.dll 1.0.14.0 in
23RISK
open
ReferênciaVexDay Proof
Maian Search 1.1 - Insecure Cookie Handling
CVE-2008-3317webappsphp
admin/index.php in Maian Search 1.1 and earlier allows remote attackers to bypass authentication and gain administrative
23RISK
open
Referência
Joomla! Component jLike 1.0 - Information Leak
CVE-2018-6610webappsphp
Information Leakage exists in the jLike 1.0 component for Joomla! via a task=getUserByCommentId request.
23RISK
open
Referência
CVE-2020-9496
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RISK
open
Referência
CVE-2010-0249
CVE-2010-0249HIGHunder attack
Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and S
100RISK
open
Referência
CVE-2020-9496
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RISK
open
Referência
CVE-2020-9496
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RISK
open
Referência
CVE-2012-0277
Heap-based buffer overflow in XnView before 1.99 allows remote attackers to cause a denial of service (application crash
23RISK
open
previouspage 172 / 717next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.