Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,902cataloged exploits
34,597CVEs with public exploitation
24,695lab-tested
21,624 exploits
ReferênciaVexDay Proof
Agares ThemeSiteScript 1.0 - 'loadadminpage' Remote File Inclusion
CVE-2008-5066webappsphp
PHP remote file inclusion vulnerability in upload/admin/frontpage_right.php in Agares Media ThemeSiteScript 1.0 allows r
23RISK
open
Referência
CVE-2010-0366
Multiple unrestricted file upload vulnerabilities in (1) register.php and (2) addvideo.php in BitScripts Bits Video Scri
23RISK
open
Referência
CVE-2012-1059
Cross-site scripting (XSS) vulnerability in osCommerce/OM/Core/Site/Shop/Application/Cart/pages/main.php in OSCommerce O
23RISK
open
Referência
CVE-2012-1059
Cross-site scripting (XSS) vulnerability in osCommerce/OM/Core/Site/Shop/Application/Cart/pages/main.php in OSCommerce O
23RISK
open
Referência
CVE-2016-6253
mail.local in NetBSD versions 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows local users to change ownership of or
38RISK
open
Referência
CVE-2016-6253
mail.local in NetBSD versions 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows local users to change ownership of or
38RISK
open
Referência
CVE-2016-6253
mail.local in NetBSD versions 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows local users to change ownership of or
38RISK
open
Referência
CVE-2009-2229
Directory traversal vulnerability in engine.php in Kasseler CMS 1.3.5 lite allows remote attackers to read arbitrary fil
23RISK
open
Referência
CVE-2015-2183
Multiple SQL injection vulnerabilities in the administrative backend in ZeusCart 4 allow remote administrators to execut
23RISK
open
Referência
CVE-2015-2183
Multiple SQL injection vulnerabilities in the administrative backend in ZeusCart 4 allow remote administrators to execut
23RISK
open
Referência
CVE-2013-4759
Multiple cross-site scripting (XSS) vulnerabilities in the Magnolia Form module 1.x before 1.4.7 and 2.x before 2.0.2 fo
23RISK
open
ReferênciaVexDay Proof
mcGalleryPRO 2006 - 'path_to_folder' Remote File Inclusion
CVE-2006-4720webappsphp
PHP remote file inclusion vulnerability in random2.php in mcGalleryPRO 2006 allows remote attackers to execute arbitrary
23RISK
open
Referência
CVE-2011-4716
Directory traversal vulnerability in file in DreamBox DM800 1.6rc3, 1.5rc1, and earlier allows remote attackers to read
23RISK
open
ReferênciaVexDay Proof
Galeria Zdjec 3.0 - 'zd_numer.php' Local File Inclusion
CVE-2007-0637webappsphp
Directory traversal vulnerability in zd_numer.php in Galeria Zdjec 3.0 and earlier allows remote attackers to include an
23RISK
open
ReferênciaVexDay Proof
cattaDoc 2.21 - 'download2.php?fn1' Remote File Disclosure
CVE-2007-1930webappsphp
Directory traversal vulnerability in download2.php in cattaDoc 2.21, and possibly other versions including 3.0, allows r
23RISK
open
ReferênciaVexDay Proof
FireConfig 0.5 - 'dl.php' Remote File Disclosure
CVE-2007-5782webappsphp
Directory traversal vulnerability in dl.php in FireConfig 0.5 allows remote attackers to read arbitrary files via a .. (
23RISK
open
ReferênciaVexDay Proof
EZContents 1.4.5 - 'index.php?link' Remote File Disclosure
CVE-2007-6368webappsphp
Directory traversal vulnerability in index.php in ezContents 1.4.5 allows remote attackers to read arbitrary files via a
23RISK
open
ReferênciaVexDay Proof
Web-MeetMe 3.0.3 - 'play.php' Remote File Disclosure
CVE-2007-6215webappsphp
Multiple directory traversal vulnerabilities in play.php in Web-MeetMe 3.0.3 allow remote attackers to read arbitrary fi
23RISK
open
ReferênciaVexDay Proof
UploadImage/UploadScript 1.0 - Remote Change Admin Password
CVE-2008-0246webappsphp
admin.php in UploadScript 1.0 does not check for the original password before making a change to a new password, which a
23RISK
open
ReferênciaVexDay Proof
ErfurtWiki R1.02b - Local File Inclusion
CVE-2008-2672webappsphp
Multiple directory traversal vulnerabilities in ErfurtWiki R1.02b and earlier, when register_globals is enabled, allow r
23RISK
open
ReferênciaVexDay Proof
ZeeBuddy 2.1 - 'adid' SQL Injection
CVE-2008-3604webappsphp
SQL injection vulnerability in bannerclick.php in ZeeBuddy 2.1 allows remote attackers to execute arbitrary SQL commands
23RISK
open
Referência
CVE-2017-5473
Cross-site request forgery (CSRF) vulnerability in ntopng through 2.4 allows remote attackers to hijack the authenticati
23RISK
open
Referência
CVE-2005-0853
betaparticle blog (bp blog) stores the database under the web root, which allows remote attackers to obtain sensitive in
23RISK
open
Referência
CVE-2015-6518
Multiple cross-site scripting (XSS) vulnerabilities in phpLiteAdmin 1.1 allow remote attackers to inject arbitrary web s
23RISK
open
Referência
CVE-2014-5308
Multiple SQL injection vulnerabilities in TestLink 1.9.11 allow remote authenticated users to execute arbitrary SQL comm
23RISK
open
Referência
CVE-2014-5308
Multiple SQL injection vulnerabilities in TestLink 1.9.11 allow remote authenticated users to execute arbitrary SQL comm
23RISK
open
Referência
CVE-2011-1569
download.aspx in Douran Portal 3.9.7.8 allows remote attackers to obtain source code of arbitrary files under the web ro
23RISK
open
ReferênciaVexDay Proof
StatIt 4 - 'statitpath' Remote File Inclusion
CVE-2006-2253webappsphp
PHP remote file inclusion vulnerability in visible_count_inc.php in Statit 4 (060207) allows remote attackers to execute
23RISK
open
Referência
CVE-2019-19726
OpenBSD through 6.6 allows local users to escalate to root because a check for LD_LIBRARY_PATH in setuid programs can be
38RISK
open
Referência
CVE-2019-19726
OpenBSD through 6.6 allows local users to escalate to root because a check for LD_LIBRARY_PATH in setuid programs can be
38RISK
open
previouspage 262 / 721next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.