Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,526cataloged exploits
34,478CVEs with public exploitation
24,695lab-tested
21,534 exploits
Referência
CVE-2018-8718
Cross-site request forgery (CSRF) vulnerability in the Mailer Plugin 1.20 for Jenkins 2.111 allows remote authenticated
23RISK
open
ReferênciaVexDay Proof
Xserver 0.1 Alpha - 'POST' Remote Buffer Overflow (PoC)
CVE-2007-3957doslinux
Buffer overflow in Nipun Jain xserver 0.1 alpha allows remote attackers to cause a denial of service via a POST request
23RISK
open
ReferênciaVexDay Proof
Symphony 1.7.01 (non-patched) - Remote Code Execution
CVE-2008-3592webappsphp
Unrestricted file upload vulnerability in the File Manager in the admin panel in Twentyone Degrees Symphony 1.7.01 and e
23RISK
open
ReferênciaVexDay Proof
PassWiki 0.9.16 RC3 - 'site_id' Local File Inclusion
CVE-2008-6423webappsphp
Directory traversal vulnerability in passwiki.php in PassWiki 0.9.16 RC3 and earlier allows remote attackers to read arb
23RISK
open
Referência
CVE-2010-2329
Buffer overflow in Rosoft Audio Converter 4.4.4 allows remote attackers to execute arbitrary code via a long playlist en
23RISK
open
Referência
CVE-2010-2329
Buffer overflow in Rosoft Audio Converter 4.4.4 allows remote attackers to execute arbitrary code via a long playlist en
23RISK
open
Referência
CVE-2025-34102
CryptoLog Unauthenticated RCE via SQL Injection and Command Injection
63RISK
open
Referência
CVE-2016-7387
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 3
23RISK
open
Referência
CVE-2025-34102
CryptoLog Unauthenticated RCE via SQL Injection and Command Injection
63RISK
open
Referência
CVE-2025-34102
CryptoLog Unauthenticated RCE via SQL Injection and Command Injection
63RISK
open
Referência
CVE-2017-2454
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RISK
open
Referência
CVE-2017-2455
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RISK
open
Referência
CVE-2020-2229
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons, resulting in a sto
23RISK
open
Referência
CVE-2014-8657
The Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway 1.0 with firmware CH6640-3.5.11.7-NOSH allows r
23RISK
open
Referência
CVE-2009-4755
Multiple stack-based buffer overflows in Mercury Audio Player 1.21 allow remote attackers to execute arbitrary code via
23RISK
open
Referência
CVE-2009-4755
Multiple stack-based buffer overflows in Mercury Audio Player 1.21 allow remote attackers to execute arbitrary code via
23RISK
open
Referência
CVE-2016-7644
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchO
23RISK
open
Referência
CVE-2026-11434
FluentCMS Blocks Plugin blocks cross site scripting
33RISK
open
Referência
CVE-2015-4040
Directory traversal vulnerability in the configuration utility in F5 BIG-IP before 12.0.0 and Enterprise Manager 3.0.0 t
23RISK
open
Referência
CVE-2012-4334
The ConnectDDNS method in the (1) STWConfigNVR 1.1.13.15 and (2) STWConfig 1.1.14.13 ActiveX controls in Samsung NET-i v
23RISK
open
ReferênciaVexDay Proof
WebED 0.0.9 - 'index.php' Remote File Disclosure
CVE-2007-6213webappsphp
Multiple directory traversal vulnerabilities in mod/chat/index.php in WebED 0.0.9 allow remote attackers to read arbitra
23RISK
open
Referência
CVE-2014-6308
Directory traversal vulnerability in OSClass before 3.4.2 allows remote attackers to read arbitrary files via a .. (dot
43RISK
open
ReferênciaVexDay Proof
Friendly Technologies - Read/Write Registry/Read Files
CVE-2008-4050remotewindows
A certain ActiveX control in fwRemoteCfg.dll 3.3.3.1 in Friendly Technologies FriendlyPPPoE Client 3.0.0.57 allows remot
23RISK
open
ReferênciaVexDay Proof
GOM Player 2.1.16.6134 - Subtitle Local Buffer Overflow (PoC)
CVE-2009-1497doswindows
Stack-based buffer overflow in srt2smi.exe in Gretech Online Movie Player (GOM Player) 2.1.16.4635 allows remote attacke
23RISK
open
Referência
pfSense 2.4.4-P3 - 'User Manager' Persistent Cross-Site Scripting
CVE-2020-11457webappsfreebsd
pfSense before 2.4.5 has stored XSS in system_usermanager_addprivs.php in the WebGUI via the descr parameter (aka full n
23RISK
open
Referência
CVE-2017-2460
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RISK
open
Referência
CVE-2017-2459
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RISK
open
Referência
CVE-2026-11413
JingDong JD Cloud Box AX6600 jdcweb_rpc set_macfilter stack-based overflow
41RISK
open
ReferênciaVexDay Proof
BinGo News 3.01 - 'bnrep' Remote File Inclusion
CVE-2006-4648webappsphp
PHP remote file inclusion vulnerability in bp_ncom.php in BinGo News (BP News) 3.01 and earlier allows remote attackers
23RISK
open
Referência
CVE-2018-10286
The Ericsson-LG iPECS NMS A.1Ac web application discloses sensitive information such as the NMS admin credentials and th
23RISK
open
previouspage 189 / 718next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.