Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,652cataloged exploits
34,545CVEs with public exploitation
24,695lab-tested
21,554 exploits
Referência
CVE-2024-53584
OpenPanel v0.3.4 was discovered to contain an OS command injection vulnerability via the timezone parameter.
48RISK
open
ReferênciaVexDay Proof
OpenBASE 0.6a - 'root_prefix' Remote File Inclusion
CVE-2007-2947webappsphp
Multiple PHP remote file inclusion vulnerabilities in OpenBASE Alpha 0.6 allow remote attackers to execute arbitrary PHP
23RISK
open
Referência
CVE-2017-17591
Realestate Crowdfunding Script 2.7.2 has SQL Injection via the single-cause.php pid parameter.
23RISK
open
Referência
CVE-2017-17591
Realestate Crowdfunding Script 2.7.2 has SQL Injection via the single-cause.php pid parameter.
23RISK
open
Referência
CVE-2014-100003
SQL injection vulnerability in includes/ym-download_functions.include.php in the Code Futures YourMembers plugin for Wor
23RISK
open
Referência
CVE-2014-100003
SQL injection vulnerability in includes/ym-download_functions.include.php in the Code Futures YourMembers plugin for Wor
23RISK
open
ReferênciaVexDay Proof
Musoo 0.21 - Remote File Inclusion
CVE-2007-3297webappsphp
Multiple PHP remote file inclusion vulnerabilities in Musoo 0.21 allow remote attackers to execute arbitrary PHP code vi
23RISK
open
ReferênciaVexDay Proof
Joomla! Component wmtportfolio 1.0 - Remote File Inclusion
CVE-2007-5310webappsphp
PHP remote file inclusion vulnerability in admin.wmtportfolio.php in the webmaster-tips.net wmtportfolio 1.0 (com_wmtpor
23RISK
open
ReferênciaVexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
CVE-2007-6495webappsasp
inc_newuser.asp in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to change the permis
23RISK
open
ReferênciaVexDay Proof
PicoFlat CMS 0.4.14 - 'index.php' Remote File Inclusion
CVE-2007-5390webappsphp
PHP remote file inclusion vulnerability in index.php in PicoFlat CMS 0.4.14 and earlier allows remote attackers to execu
23RISK
open
Referência
CVE-2018-11564
Stored XSS in YOOtheme Pagekit 1.0.13 and earlier allows a user to upload malicious code via the picture upload feature.
23RISK
open
Referência
CVE-2018-11564
Stored XSS in YOOtheme Pagekit 1.0.13 and earlier allows a user to upload malicious code via the picture upload feature.
23RISK
open
Referência
CVE-2021-29447
WordPress Authenticated XXE attack when installation is running PHP 8
63RISK
open
Referência
CVE-2014-9258
SQL injection vulnerability in ajax/getDropdownValue.php in GLPI before 0.85.1 allows remote authenticated users to exec
23RISK
open
Referência
CVE-2021-29447
WordPress Authenticated XXE attack when installation is running PHP 8
63RISK
open
Referência
CVE-2011-4898
wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier generates different error message
23RISK
open
Referência
CVE-2015-4071
The Helpdesk Pro Plugin before 1.4.0 for Joomla! allows remote attackers to read the support tickets of arbitrary users
23RISK
open
Referência
CVE-2015-4071
The Helpdesk Pro Plugin before 1.4.0 for Joomla! allows remote attackers to read the support tickets of arbitrary users
23RISK
open
Referência
CVE-2013-5945
Multiple SQL injection vulnerabilities in D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.0
23RISK
open
Referência
CVE-2018-8814
Cross-site request forgery (CSRF) vulnerability in WolfCMS 0.8.3.1 allows remote attackers to hijack the authentication
23RISK
open
ReferênciaVexDay Proof
phpCC 4.2 Beta - 'base_dir' Remote File Inclusion
CVE-2006-4073webappsphp
Multiple PHP remote file inclusion vulnerabilities in Fabian Hainz phpCC Beta 4.2 allow remote attackers to execute arbi
23RISK
open
Referência
CVE-2012-1417
Multiple cross-site scripting (XSS) vulnerabilities in Local Phone book and Blacklist form in Yealink VOIP Phones allow
23RISK
open
Referência
CVE-2012-1417
Multiple cross-site scripting (XSS) vulnerabilities in Local Phone book and Blacklist form in Yealink VOIP Phones allow
23RISK
open
ReferênciaVexDay Proof
SIPS 0.3.1 - 'box.inc.php' Remote File Inclusion
CVE-2006-4733webappsphp
PHP remote file inclusion vulnerability in sipssys/code/box.inc.php in Haakon Nilsen simple, integrated publishing syste
23RISK
open
ReferênciaVexDay Proof
MyPHPcommander 2.0 - 'package.php' Remote File Inclusion
CVE-2007-0568webappsphp
PHP remote file inclusion vulnerability in system/lib/package.php in MyPHPCommander 2.0 allows remote attackers to execu
23RISK
open
ReferênciaVexDay Proof
FCRing 1.31 - 'fcring.php?s_fuss' Remote File Inclusion
CVE-2007-1133webappsphp
PHP remote file inclusion vulnerability in fcring.php in FCRing 1.3 allows remote attackers to execute arbitrary PHP cod
23RISK
open
ReferênciaVexDay Proof
EclipseBB 0.5.0 Lite - 'phpbb_root_path' Remote File Inclusion
CVE-2007-0581webappsphp
PHP remote file inclusion vulnerability in functions.php in EclipseBB 0.5.0 Lite allows remote attackers to execute arbi
23RISK
open
ReferênciaVexDay Proof
Ocean FTP Server 1.00 - Denial of Service
CVE-2005-0847doswindows
Code Ocean FTP server 1.0 allows remote attackers to cause a denial of service via a large number of connections.
23RISK
open
ReferênciaVexDay Proof
Versado CMS 1.07 - 'ajax_listado.php?urlModulo' Remote File Inclusion
CVE-2007-2541webappsphp
PHP remote file inclusion vulnerability in includes/ajax_listado.php in Versado CMS 1.07 allows remote attackers to exec
23RISK
open
ReferênciaVexDay Proof
NagiosQL 2005 2.00 - 'prepend_adm.php' Remote File Inclusion
CVE-2007-2709webappsphp
PHP remote file inclusion vulnerability in functions/prepend_adm.php in NagiosQL 2005 2.00 allows remote attackers to ex
23RISK
open
previouspage 234 / 719next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.