Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,526cataloged exploits
34,478CVEs with public exploitation
24,695lab-tested
21,497 exploits
Referência
CVE-2018-10832
ModbusPal 1.6b is vulnerable to an XML External Entity (XXE) attack. Projects are saved as .xmpp files and automations c
23RISK
open
Referência
CVE-2018-19371
The SaveUserSettings service in Content Manager in SDL Web 8.5.0 has an XXE Vulnerability that allows reading sensitive
23RISK
open
Referência
CVE-2018-19371
The SaveUserSettings service in Content Manager in SDL Web 8.5.0 has an XXE Vulnerability that allows reading sensitive
23RISK
open
ReferênciaVexDay Proof
EkinBoard 1.1.0 - Arbitrary File Upload / Authentication Bypass
CVE-2008-7157webappsphp
Unrestricted file upload vulnerability in EkinBoard 1.1.0 and earlier allows remote attackers to execute arbitrary code
23RISK
open
Referência
CVE-2017-5447
An out-of-bounds read during the processing of glyph widths during text layout. This results in a potentially exploitabl
28RISK
open
Referência
CVE-2010-2332
Impact Financials, Inc. Impact PDF Reader 2.0, 1.2, and other versions for iPhone and iPod touch allows remote attackers
23RISK
open
Referência
CVE-2017-16716
A SQL Injection issue was discovered in WebAccess versions prior to 8.3. WebAccess does not properly sanitize its inputs
23RISK
open
ReferênciaVexDay Proof
OneCMS 2.4 - SQL Injection / Upload
CVE-2008-7209webappsphp
Unrestricted file upload vulnerability in the add2 action in a_upload.php in OneCMS 2.4, and possibly earlier, allows re
23RISK
open
Referência
CVE-2018-6323
The elf_object_p function in elfcode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU B
23RISK
open
ReferênciaVexDay Proof
PHPCollab 2.x / NetOffice 2.x - 'sendpassword.php' SQL Injection
CVE-2006-1495webappsphp
SQL injection vulnerability in general/sendpassword.php in (1) PHPCollab 2.4 and 2.5.rc3, and (2) NetOffice 2.5.3-pl1 an
23RISK
open
Referência
CVE-2017-5850
httpd in OpenBSD allows remote attackers to cause a denial of service (memory consumption) via a series of requests for
28RISK
open
Referência
CVE-2010-2045
Directory traversal vulnerability in the Dione Form Wizard (aka FDione or com_dioneformwizard) component 1.0.2 for Jooml
38RISK
open
Referência
CVE-2019-12189
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do search field.
23RISK
open
Referência
CVE-2009-2396
PHP remote file inclusion vulnerability in template/album.php in DM Albums 1.9.2, as used standalone or as a WordPress p
23RISK
open
Referência
CVE-2017-5850
httpd in OpenBSD allows remote attackers to cause a denial of service (memory consumption) via a series of requests for
28RISK
open
Referência
CVE-2017-14939
decode_line_info in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.
23RISK
open
ReferênciaVexDay Proof
PHP 4.4.6/5.2.1 - ext/gd Already Freed Resources Usage
CVE-2007-1582locallinux
The resource system in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allows context-dependent attackers to execute arb
23RISK
open
Referência
CVE-2009-2653
The NtUserConsoleControl function in win32k.sys in Microsoft Windows XP SP2 and SP3, and Server 2003 before SP1, allows
23RISK
open
Referência
Nagios Log Server 2024R1.3.1 - Stored XSS
CVE-2025-29471HIGHwebappsmultiple
Cross Site Scripting vulnerability in Nagios Log Server v.2024R1.3.1 allows a remote attacker to execute arbitrary code
41RISK
open
Referência
CVE-2009-2333
Multiple directory traversal vulnerabilities in CMS Chainuk 1.2 and earlier allow remote attackers to include and execut
23RISK
open
Referência
CVE-2009-3053
Directory traversal vulnerability in the Agora (com_agora) component 3.0.0b for Joomla! allows remote attackers to inclu
38RISK
open
Referência
CVE-2014-8386
Multiple stack-based buffer overflows in Advantech AdamView 4.3 and earlier allow remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
PHP Live Helper 2.0.1 - Multiple Vulnerabilities
CVE-2008-3764webappsphp
Eval injection vulnerability in globalsoff.php in Turnkey PHP Live Helper 2.0.1 and earlier allows remote attackers to e
23RISK
open
ReferênciaVexDay Proof
NuMedia Soft Nms DVD Burning SDK - ActiveX 'NMSDVDX.dll' Command Execution
CVE-2008-4342remotewindows
NuMedia Soft NMS DVD Burning SDK Activex NMSDVDX.DVDEngineX.1 ActiveX control (NMSDVDX.dll) 1.013C and earlier, as used
28RISK
open
ReferênciaVexDay Proof
mailwatch 1.0.4 - 'doc' Local File Inclusion
CVE-2008-5991webappsphp
Directory traversal vulnerability in docs.php in MailWatch for MailScanner 1.0.4 and earlier allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
Xitami Web Server 2.5c2 - LRWP Processing Format String (PoC)
CVE-2008-6519doswindows
Format string vulnerability in Xitami Web Server 2.2a through 2.5c2, and possibly other versions, allows remote attacker
23RISK
open
ReferênciaVexDay Proof
BlogPHP 2.0 - Privilege Escalation / SQL Injection
CVE-2008-6745webappsphp
index.php in BlogPHP 2.0 allows remote attackers to gain administrator privileges via a crafted email parameter in a reg
23RISK
open
ReferênciaVexDay Proof
Xilisoft Video Converter Wizard 3 - '.cue' Stack Buffer Overflow (PoC)
CVE-2009-1370doswindows
Stack-based buffer overflow in ape_plugin.plg in Xilisoft Video Converter 3.1.53.0704n and 5.1.23.0402 allows remote att
23RISK
open
Referência
CVE-2021-24155
Backup Guard < 1.6.0 - Authenticated Arbitrary File Upload
60RISK
open
Referência
CVE-2021-24155
Backup Guard < 1.6.0 - Authenticated Arbitrary File Upload
60RISK
open
previouspage 184 / 717next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.