Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,526cataloged exploits
34,478CVEs with public exploitation
24,695lab-tested
21,534 exploits
Referência
CVE-2015-8612
The EnableNetwork method in the Network class in plugins/mechanism/Network.py in Blueman before 2.0.3 allows local users
38RISK
open
Referência
CVE-2021-45814
Nettmp NNT 5.1 is affected by a SQL injection vulnerability. An attacker can bypass authentication and access the panel
23RISK
open
Referência
CVE-2020-14944
Global RADAR BSA Radar 1.6.7234.24750 and earlier lacks valid authorization controls in multiple functions. This can all
23RISK
open
ReferênciaVexDay Proof
DataTrac Activity Console - Denial of Service
CVE-2005-1667doswindows
DataTrac Activity Console 1.1 allows remote attackers to cause a denial of service via a long HTTP GET request.
23RISK
open
Referência
CVE-2018-5708
An issue was discovered on D-Link DIR-601 B1 2.02NA devices. Being on the same local network as, but being unauthenticat
23RISK
open
Referência
CVE-2014-125118
eScan 5.5-2 Web Management Console Command Injection
63RISK
open
ReferênciaVexDay Proof
Moodle 1.5.2 - 'moodledata' Remote Session Disclosure
CVE-2007-1647webappsphp
Moodle 1.5.2 and earlier stores sensitive information under the web root with insufficient access control, and provides
23RISK
open
ReferênciaVexDay Proof
PcP-Guestbook 3.0 - 'lang' Local File Inclusion
CVE-2007-1933webappsphp
Multiple directory traversal vulnerabilities in PcP-Guestbook (PcP-Book) 3.0 allow remote attackers to include and execu
23RISK
open
ReferênciaVexDay Proof
Joomla! Component Expose RC35 - Arbitrary File Upload
CVE-2007-3932webappsphp
uploadimg.php in the Expose RC35 and earlier (com_expose) component for Joomla! sends an error message but does not exit
23RISK
open
ReferênciaVexDay Proof
PayPal eStore - Admin Password Change
CVE-2008-6535webappsphp
admin/settings.php in PayPal eStores allows remote attackers to bypass intended access restrictions and change the admin
23RISK
open
ReferênciaVexDay Proof
PHPUserBase 1.3b - 'unverified.inc.php' Local File Inclusion
CVE-2008-7240webappsphp
Directory traversal vulnerability in include/unverified.inc.php in Linux Web Shop (LWS) php User Base 1.3beta allows rem
23RISK
open
ReferênciaVexDay Proof
Flatnux 2009-01-27 - Remote File Inclusion
CVE-2009-0572webappsphp
PHP remote file inclusion vulnerability in include/flatnux.php in FlatnuX CMS (aka Flatnuke3) 2009-01-27 and 2009-02-04,
23RISK
open
Referência
CVE-2013-4864
MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to send HTTP requests to intranet servers via the url
23RISK
open
Referência
CVE-2010-0761
SQL injection vulnerability in index.php in CommodityRentals Books/eBooks Rentals Script allows remote attackers to exec
23RISK
open
Referência
CVE-2017-0165
An elevation of privilege vulnerability exists when Microsoft Windows running on Windows 10, Windows 10 1511, Windows 8.
23RISK
open
Referência
CVE-2018-14057
Pimcore before 5.3.0 allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging validati
23RISK
open
Referência
CVE-2018-14057
Pimcore before 5.3.0 allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging validati
23RISK
open
Referência
CVE-2011-4831
Directory traversal vulnerability in webFileBrowser.php in Web File Browser 0.4b14 allows remote authenticated users to
23RISK
open
Referência
ManageEngine Service Desk 10.0 - Cross-Site Scripting
CVE-2019-15083webappsjava
Default installations of Zoho ManageEngine ServiceDesk Plus 10.0 before 10500 are vulnerable to XSS injected by a workst
23RISK
open
Referência
CVE-2020-6862
V6.0.10P2T2 and V6.0.10P2T5 of F6x2W product are impacted by Information leak vulnerability. Unauthorized users could lo
23RISK
open
Referência
CVE-2014-9448
Buffer overflow in Mini-stream RM-MP3 Converter 3.1.2.1.2010.03.30 allows remote attackers to execute arbitrary code or
23RISK
open
Referência
CVE-2014-9448
Buffer overflow in Mini-stream RM-MP3 Converter 3.1.2.1.2010.03.30 allows remote attackers to execute arbitrary code or
23RISK
open
Referência
CVE-2018-5985
SQL Injection exists in the LiveCRM SaaS Cloud 1.0 component for Joomla! via an r=site/login&company_id= request.
28RISK
open
Referência
CVE-2021-22911
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RISK
open
Referência
CVE-2017-5344
An issue was discovered in dotCMS through 3.6.1. The findChildrenByFilter() function which is called by the web accessib
23RISK
open
Referência
CVE-2013-6796
The SMTP server in DeepOfix 3.3 and earlier allows remote attackers to bypass authentication via an empty password, whic
23RISK
open
Referência
CVE-2013-6796
The SMTP server in DeepOfix 3.3 and earlier allows remote attackers to bypass authentication via an empty password, whic
23RISK
open
Referência
CVE-2019-15083
Default installations of Zoho ManageEngine ServiceDesk Plus 10.0 before 10500 are vulnerable to XSS injected by a workst
23RISK
open
Referência
CVE-2018-5988
SQL Injection exists in Flexible Poll 1.2 via the id parameter to mobile_preview.php or index.php.
28RISK
open
Referência
CVE-2020-37125
Edimax Technology EW-7438RPn-v3 Mini 1.27 - Remote Code Execution
48RISK
open
previouspage 195 / 718next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.