Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,445cataloged exploits
34,432CVEs with public exploitation
24,695lab-tested
21,497 exploits
ReferênciaVexDay Proof
PHProjekt 5.1 - Multiple Remote File Inclusions
CVE-2006-4204webappsphp
Multiple PHP remote file inclusion vulnerabilities in PHProjekt 5.1 and possibly earlier allow remote attackers to execu
23RISK
open
Referência
CVE-2019-11446
An issue was discovered in ATutor through 2.2.4. It allows the user to run commands on the server with the teacher user
23RISK
open
Referência
CVE-2014-2927
The rsync daemon in F5 BIG-IP 11.6 before 11.6.0, 11.5.1 before HF3, 11.5.0 before HF4, 11.4.1 before HF4, 11.4.0 before
23RISK
open
ReferênciaVexDay Proof
Citrix Presentation Server Client - 'WFICA.OCX' ActiveX Heap Buffer Overflow
CVE-2006-6334remotewindows
Heap-based buffer overflow in the SendChannelData function in wfica.ocx in Citrix Presentation Server Client before 9.23
35RISK
open
Referência
CVE-2023-1650
ChatBot < 4.4.7 - Unauthenticated PHP Object Injection
60RISK
open
Referência
CVE-2017-16930
The remote management interface on the Claymore Dual GPU miner 10.1 allows an unauthenticated remote attacker to execute
35RISK
open
Referência
CVE-2013-5447
Stack-based buffer overflow in IBM Forms Viewer 4.x before 4.0.0.3 and 8.x before 8.0.1.1 allows remote attackers to exe
50RISK
open
Referência
CVE-2013-5447
Stack-based buffer overflow in IBM Forms Viewer 4.x before 4.0.0.3 and 8.x before 8.0.1.1 allows remote attackers to exe
50RISK
open
ReferênciaVexDay Proof
PHP 5.2.1 - 'hash_update_file()' Freed Resource Usage
CVE-2007-1581locallinux
The resource system in PHP 5.0.0 through 5.2.1 allows context-dependent attackers to execute arbitrary code by interrupt
23RISK
open
ReferênciaVexDay Proof
IrfanView 3.99 - '.ani' Local Buffer Overflow (1)
CVE-2007-1867localwindows
Buffer overflow in IrfanView 3.99 allows remote attackers to execute arbitrary code via a crafted animated cursor (ANI)
23RISK
open
ReferênciaVexDay Proof
Lama Software 14.12.2007 - Multiple Remote File Inclusions
CVE-2008-0423webappsphp
Multiple PHP remote file inclusion vulnerabilities in Lama Software allow remote attackers to execute arbitrary PHP code
35RISK
open
ReferênciaVexDay Proof
RunCMS 1.5.2 - 'debug_show.php' SQL Injection
CVE-2007-2539webappsphp
The show_files function in RunCms 1.5.2 and earlier allows remote attackers to obtain sensitive information (file existe
23RISK
open
Referência
CVE-2008-4178
SQL injection vulnerability in tr.php in DownlineGoldmine Special Category Addon, Downline Builder Pro, New Addon, and D
23RISK
open
Referência
CVE-2008-4178
SQL injection vulnerability in tr.php in DownlineGoldmine Special Category Addon, Downline Builder Pro, New Addon, and D
23RISK
open
Referência
CVE-2008-4178
SQL injection vulnerability in tr.php in DownlineGoldmine Special Category Addon, Downline Builder Pro, New Addon, and D
23RISK
open
Referência
CVE-2017-14086
Pre-authorization Start Remote Process vulnerabilities in Trend Micro OfficeScan 11.0 and XG may allow unauthenticated u
23RISK
open
Referência
CVE-2017-14086
Pre-authorization Start Remote Process vulnerabilities in Trend Micro OfficeScan 11.0 and XG may allow unauthenticated u
23RISK
open
Referência
CVE-2016-9813
The _parse_pat function in the mpegts parser in GStreamer before 1.10.2 allows remote attackers to cause a denial of ser
23RISK
open
Referência
CVE-2018-13042
The 1Password application 6.8 for Android is affected by a Denial Of Service vulnerability. By starting the activity com
23RISK
open
Referência
CVE-2004-1720
The (1) address.html and possibly (2) calendar.html pages in Merak Mail Server 5.2.7 allow remote attackers to gain sens
23RISK
open
ReferênciaVexDay Proof
Mini Web Calendar 1.2 - File Disclosure / Cross-Site Scripting
CVE-2008-5062webappsphp
Directory traversal vulnerability in php/cal_pdf.php in Mini Web Calendar (mwcal) 1.2 allows remote attackers to read ar
23RISK
open
Referência
CVE-2014-7910
Multiple unspecified vulnerabilities in Google Chrome before 39.0.2171.65 allow attackers to cause a denial of service o
23RISK
open
Referência
CVE-2016-3986
Avast allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a
23RISK
open
Referência
CVE-2016-6256
SAP Business One for Android 1.2.3 allows remote attackers to conduct XML External Entity (XXE) attacks via crafted XML
23RISK
open
Referência
CVE-2015-1376
pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not validate hostnames, which allows remot
50RISK
open
Referência
CVE-2016-6256
SAP Business One for Android 1.2.3 allows remote attackers to conduct XML External Entity (XXE) attacks via crafted XML
23RISK
open
Referência
CVE-2013-5223
CVE-2013-5223MEDIUMunder attack
Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2760U Gateway (Rev. E1) allow remote authenticated use
75RISK
open
Referência
CVE-2023-0386
CVE-2023-0386HIGHunder attack
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISK
open
Referência
CVE-2016-9349
An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. An attacker could traverse the file system
23RISK
open
Referência
CVE-2016-9349
An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. An attacker could traverse the file system
23RISK
open
previouspage 174 / 717next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.