Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,325cataloged exploits
36,055CVEs with public exploitation
24,695lab-tested
22,721 exploits
Referência
CVE-2026-19923
code-projects Online Shopping System checkout_process.php sql injection
33RISK
open
Referência
CVE-2026-19922
code-projects Online Shopping System checkout.php cross site scripting
33RISK
open
ReferênciaVexDay Proof
PostNuke 0.764 - Blind SQL Injection
CVE-2008-1591webappsphp
The pnVarPrepForStore function in PostNuke 0.764 and earlier skips input sanitization when magic_quotes_runtime is enabl
23RISK
open
Referência
CVE-2026-19921
code-projects Online Shopping System homeaction.php sql injection
33RISK
open
Referência
CVE-2022-27925
CVE-2022-27925HIGHunder attackransomware
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts file
100RISK
open
Referência
CVE-2024-12987
CVE-2024-12987MEDIUMunder attack
DrayTek Vigor2960/Vigor300B Web Management Interface apmcfgupload os command injection
100RISK
open
Referência
CVE-2023-20887
CVE-2023-20887CRITICALunder attack
Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware
100RISK
open
ReferênciaVexDay Proof
iGaming CMS 1.5 - Multiple SQL Injections
CVE-2008-5841webappsphp
Multiple SQL injection vulnerabilities in iGaming 1.5 and earlier allow remote attackers to execute arbitrary SQL comman
23RISK
open
ReferênciaVexDay Proof
Joomla! Plugin tinybrowser 1.5.12 - Arbitrary File Upload / Execution
CVE-2011-4908webappsphp
TinyBrowser plugin for Joomla! before 1.5.13 allows arbitrary file upload via upload.php.
50RISK
open
ReferênciaVexDay Proof
EasyNews 40tr - SQL Injection / Cross-Site Scripting / Local File Inclusion
CVE-2008-1650webappsphp
SQL injection vulnerability in dynamicpages/index.php in EasyNews 4.0 allows remote attackers to execute arbitrary SQL c
23RISK
open
ReferênciaVexDay Proof
Prediction Football 1.x - 'matchid' SQL Injection
CVE-2008-1732webappsphp
SQL injection vulnerability in showpredictionsformatch.php in Prediction Football 1.x allows remote attackers to execute
23RISK
open
Referência
CVE-2026-32834
Easy PayPal Events & Tickets < 1.4 Authentication Bypass via QR Code Scanning
41RISK
open
Referência
CVE-2011-5005
Unrestricted file upload vulnerability in QuiXplorer 2.3 and earlier allows remote attackers to execute arbitrary code b
23RISK
open
Referência
CVE-2026-7744
CodeAstro Online Classroom addnewstudent sql injection
33RISK
open
Referência
CVE-2026-9702
InPost PL < 1.9.1 - Unauthenticated WooCommerce Order Parcel-Locker Hijacking
41RISK
open
ReferênciaVexDay Proof
LiveCart 1.1.1 - 'id' Blind SQL Injection
CVE-2008-1750webappsphp
SQL injection vulnerability in Integry Systems LiveCart 1.1.1 and earlier allows remote attackers to execute arbitrary S
23RISK
open
Referência
CVE-2010-1653
Directory traversal vulnerability in graphics.php in the Graphics (com_graphics) component 1.0.6 and 1.5.0 for Joomla! a
43RISK
open
Referência
CVE-2016-10045
The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail comman
60RISK
open
ReferênciaVexDay Proof
KwsPHP Module ConcoursPhoto 2.0 - 'C_ID' SQL Injection
CVE-2008-1758webappsphp
SQL injection vulnerability in the ConcoursPhoto module for KwsPHP allows remote attackers to execute arbitrary SQL comm
23RISK
open
Referência
CVE-2026-19904
SourceCodester Online Book Store System System Settings index.php site_settings cross site scripting
33RISK
open
Referência
CVE-2020-14883
CVE-2020-14883HIGHunder attack
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
Referência
CVE-2026-19903
SourceCodester Online Clothing Store SQL Database Backup shopping.sql file access
33RISK
open
Referência
CVE-2011-5043
TomatoSoft Free Mp3 Player 1.0 allows remote attackers to cause a denial of service (application crash) via a long strin
23RISK
open
Referência
CVE-2011-5164
Stack-based buffer overflow in VanDyke Software AbsoluteFTP 1.9.6 through 2.2.10 allows remote FTP servers to execute ar
43RISK
open
ReferênciaVexDay Proof
Akamai Download Manager < 2.2.3.7 - ActiveX Remote Download
CVE-2008-1770remotewindows
CRLF injection vulnerability in Akamai Download Manager ActiveX control before 2.2.3.6 allows remote attackers to force
28RISK
open
Referência
CVE-2011-5173
Buffer overflow in Bugbear Entertainment FlatOut 2005 allows user-assisted remote attackers to cause a denial of service
23RISK
open
Referência
CVE-2026-19899
SourceCodester Class and Exam Timetabling System edit_teacher.php sql injection
33RISK
open
ReferênciaVexDay Proof
BosClassifieds 3.0 - 'index.php' SQL Injection
CVE-2008-1838webappsphp
SQL injection vulnerability in BosClassifieds Classified Ads System 3.0 allows remote attackers to execute arbitrary SQL
23RISK
open
Referência
CVE-2023-38831
CVE-2023-38831HIGHunder attackransomware
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
ReferênciaVexDay Proof
CDNetworks Nefficient Download - 'NeffyLauncher.dll' Code Execution
CVE-2008-1886remotewindows
The NeffyLauncher 1.0.5 ActiveX control (NeffyLauncher.dll) in CDNetworks Nefficient Download uses weak cryptography for
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.