Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,902cataloged exploits
34,597CVEs with public exploitation
24,695lab-tested
21,624 exploits
Referência
CVE-2007-6752
Cross-site request forgery (CSRF) vulnerability in Drupal 7.12 and earlier allows remote attackers to hijack the authent
23RISK
open
Referência
CVE-2012-2579
Multiple cross-site scripting (XSS) vulnerabilities in the WP SimpleMail plugin 1.0.6 for WordPress allow remote attacke
23RISK
open
Referência
CVE-2012-5346
Cross-site scripting (XSS) vulnerability in wp-live.php in the WP Live.php module 1.2.1 for WordPress allows remote atta
23RISK
open
Referência
CVE-2012-5229
Cross-site scripting (XSS) vulnerability in css/gallery-css.php in the Slideshow Gallery2 plugin for WordPress allows re
23RISK
open
Referência
CVE-2012-2917
Cross-site scripting (XSS) vulnerability in the Share and Follow plugin 1.80.3 for WordPress allows remote attackers to
23RISK
open
Referência
CVE-2017-9429
SQL injection vulnerability in the Event List plugin 0.7.8 for WordPress allows an authenticated user to execute arbitra
23RISK
open
Referência
CVE-2015-4064
SQL injection vulnerability in modules/module.ab-testing.php in the Landing Pages plugin before 1.8.5 for WordPress allo
23RISK
open
Referência
CVE-2015-4064
SQL injection vulnerability in modules/module.ab-testing.php in the Landing Pages plugin before 1.8.5 for WordPress allo
23RISK
open
Referência
CVE-2015-4018
SQL injection vulnerability in feedwordpresssyndicationpage.class.php in the FeedWordPress plugin before 2015.0514 for W
23RISK
open
Referência
CVE-2015-4018
SQL injection vulnerability in feedwordpresssyndicationpage.class.php in the FeedWordPress plugin before 2015.0514 for W
23RISK
open
Referência
CVE-2017-11494
SQL injection vulnerability in SOL.Connect ISET-mpp meter 1.2.4.2 and earlier allows remote attackers to execute arbitra
23RISK
open
ReferênciaVexDay Proof
OpenDock Easy Gallery 1.4 - 'doc_directory' File Inclusion
CVE-2006-5241webappsphp
Multiple PHP remote file inclusion vulnerabilities in OpenDock Easy Gallery 1.4 and earlier, when register_globals is en
23RISK
open
ReferênciaVexDay Proof
MolyX BOARD 2.5.0 - 'index.php?lang' Local File Inclusion
CVE-2007-2778webappsphp
Multiple directory traversal vulnerabilities in MolyX BOARD 2.5.0 allow remote attackers to read arbitrary files via a .
23RISK
open
ReferênciaVexDay Proof
EnjoySAP ActiveX kweditcontrol.kwedit.1 - Remote Stack Overflow (PoC)
CVE-2007-3607doswindows
Multiple unspecified vulnerabilities in ActiveX controls in the EnjoySAP SAP GUI allow remote attackers to cause a denia
23RISK
open
ReferênciaVexDay Proof
OSSIM 0.9.9rc5 - Cross-Site Scripting / SQL Injection
CVE-2008-0919webappsphp
Cross-site scripting (XSS) vulnerability in session/login.php in Open Source Security Information Management (OSSIM) 0.9
23RISK
open
ReferênciaVexDay Proof
phpdaily - SQL Injection / Cross-Site Scripting / Local File Download
CVE-2008-4758webappsphp
Directory traversal vulnerability in download_file.php in PHP-Daily allows remote attackers to read arbitrary local file
23RISK
open
ReferênciaVexDay Proof
DB Top Sites 1.0 - Remote Command Execution
CVE-2009-2111webappsphp
Static code injection vulnerability in add_reg.php in DB Top Sites 1.0 allows remote attackers to inject arbitrary PHP c
23RISK
open
Referência
CVE-2023-0224
GiveWP < 2.24.1 - Unauthenticated SQLi
48RISK
open
Referência
CVE-2014-10031
Buffer overflow in the IMAPd service in Qualcomm Eudora WorldMail 9.0.333.0 allows remote attackers to execute arbitrary
23RISK
open
Referência
CVE-2011-4713
Directory traversal vulnerability in catalog/content.php in osCSS2 2.1.0 and earlier allows remote attackers to read arb
23RISK
open
Referência
CVE-2017-14960
xDashboard in OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 has SQL I
23RISK
open
ReferênciaVexDay Proof
MyBulletinBoard (MyBB) 1.03 - 'misc.php' SQL Injection
CVE-2006-0959webappsphp
SQL injection vulnerability in misc.php in MyBulletinBoard (MyBB) 1.03, when register_globals is enabled, allows remote
23RISK
open
Referência
CVE-2009-4578
Cross-site scripting (XSS) vulnerability in the Facileforms (com_facileforms) component for Joomla! and Mambo allows rem
23RISK
open
ReferênciaVexDay Proof
acFTP FTP Server 1.4 - 'USER' Remote Buffer Overflow (PoC)
CVE-2006-2242doswindows
acFTP 1.4 allows remote attackers to cause a denial of service (application crash) via a long string with "{" (brace) ch
23RISK
open
Referência
CVE-2014-3738
Cross-site scripting (XSS) vulnerability in Zenoss 4.2.5 allows remote attackers to inject arbitrary web script or HTML
23RISK
open
Referência
CVE-2014-3738
Cross-site scripting (XSS) vulnerability in Zenoss 4.2.5 allows remote attackers to inject arbitrary web script or HTML
23RISK
open
Referência
CVE-2014-9610
Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication an
23RISK
open
Referência
CVE-2014-9610
Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication an
23RISK
open
ReferênciaVexDay Proof
SimpCMS 04.10.2007 - 'site' Remote File Inclusion
CVE-2007-2009webappsphp
PHP remote file inclusion vulnerability in index.php in SimpCMS Light 04.10.2007 and earlier allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
maGAZIn 2.0 - 'PHPThumb.php?src' Remote File Disclosure
CVE-2007-2643webappsphp
Directory traversal vulnerability in phpThumb.php in PinkCrow Designs Gallery or maGAZIn 2.0 allows remote attackers to
23RISK
open
previouspage 261 / 721next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.