Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,008cataloged exploits
34,638CVEs with public exploitation
24,695lab-tested
21,662 exploits
Referência
CVE-2009-3149
Directory traversal vulnerability in _css/js.php in Elgg 1.5, when magic_quotes_gpc is disabled, allows remote attackers
23RISK
open
ReferênciaVexDay Proof
Jamroom 3.3.5 - Remote File Inclusion
CVE-2008-2886webappsphp
PHP remote file inclusion vulnerability in include/plugins/jrBrowser/purchase.php in Jamroom 3.3.0 through 3.3.5, when r
23RISK
open
Referência
CVE-2019-19143
TP-LINK TL-WR849N 0.9.1 4.16 devices do not require authentication to replace the firmware via a POST request to the cgi
23RISK
open
Referência
CVE-2011-5257
Multiple cross-site scripting (XSS) vulnerabilities in the Classipress theme before 3.1.5 for WordPress allow remote att
23RISK
open
Referência
CVE-2017-15667
In Flexense SysGauge Server 3.6.18, the Control Protocol suffers from a denial of service. The attack vector is a crafte
23RISK
open
Referência
CVE-2014-5349
Stack-based buffer overflow in Baidu Spark Browser 26.5.9999.3511 allows remote attackers to cause a denial of service (
23RISK
open
ReferênciaVexDay Proof
Mantis Bug Tracker 1.1.1 - Code Execution / Cross-Site Scripting / Cross-Site Request Forgery
CVE-2008-3331webappsphp
Cross-site scripting (XSS) vulnerability in return_dynamic_filters.php in Mantis before 1.1.2 allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
Hammer Software MetaGauge 1.0.0.17 - Directory Traversal
CVE-2008-4421remotewindows
Directory traversal vulnerability in MetaGauge 1.0.0.17, and probably other versions before 1.0.3.38, allows remote atta
23RISK
open
ReferênciaVexDay Proof
ModernBill 4.4.x - Cross-Site Scripting / Remote File Inclusion
CVE-2008-5060webappsphp
Multiple PHP remote file inclusion vulnerabilities in ModernBill 4.4 and earlier allow remote attackers to execute arbit
23RISK
open
Referência
Entrepreneur Dating Script 2.0.1 - 'marital' / 'gender' / 'country' / 'profileid' SQL Injection
CVE-2017-17648webappsphp
Entrepreneur Dating Script 2.0.1 has SQL Injection via the search_result.php marital, gender, country, or profileid para
23RISK
open
Referência
CVE-2016-5425
The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distribu
38RISK
open
Referência
CVE-2016-5425
The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distribu
38RISK
open
Referência
Online Marriage Registration System 1.0 - 'searchdata' SQL Injection
CVE-2020-35151webappsphp
The Online Marriage Registration System 1.0 post parameter "searchdata" in the user/search.php request is vulnerable to
23RISK
open
Referência
CVE-2017-13849
An issue was discovered in certain Apple products. iOS before 11.1 is affected. tvOS before 11.1 is affected. watchOS be
23RISK
open
Referência
CVE-2011-0960
Multiple SQL injection vulnerabilities in Cisco Unified Operations Manager (CUOM) before 8.6 allow remote attackers to e
23RISK
open
Referência
CVE-2012-3485
Tunnelblick 3.3beta20 and earlier relies on argv[0] to determine the name of an appropriate (1) kernel module pathname o
38RISK
open
Referência
CVE-2019-0732
A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard when Wind
23RISK
open
Referência
CVE-2019-0732
A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard when Wind
23RISK
open
Referência
CVE-2024-5488
SEOPress < 7.9 - Unauthenticated Object Injection
63RISK
open
Referência
CVE-2013-1466
Multiple cross-site scripting (XSS) vulnerabilities in glFusion before 1.2.2.pl4 allow remote attackers to inject arbitr
23RISK
open
Referência
CVE-2008-6799
connection.php in FlashChat 5.0.8 allows remote attackers to bypass the role filter mechanism and gain administrative pr
23RISK
open
Referência
CVE-2012-6624
Cross-site scripting (XSS) vulnerability in the SoundCloud Is Gold plugin 2.1 for WordPress allows remote attackers to i
23RISK
open
Referência
CVE-2014-8800
Cross-site scripting (XSS) vulnerability in nextend-facebook-settings.php in the Nextend Facebook Connect plugin before
23RISK
open
Referência
CVE-2022-36664
Password Manager for IIS 2.0 has a cross-site scripting (XSS) vulnerability via the /isapi/PasswordManager.dll ResultURL
33RISK
open
Referência
CVE-2009-2223
Directory traversal vulnerability in locms/smarty.php in LightOpenCMS 0.1 allows remote attackers to include and execute
23RISK
open
Referência
CVE-2015-1725
Buffer overflow in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows S
23RISK
open
Referência
Cyclos 4.14.7 - DOM Based Cross-Site Scripting (XSS)
CVE-2021-31674webappsmultiple
Cyclos 4 PRO 4.14.7 and before does not validate user input at error inform, which allows remote unauthenticated attacke
23RISK
open
ReferênciaVexDay Proof
Mambo Module galleria 1.0b - Remote File Inclusion
CVE-2006-3396webappsphp
PHP remote file inclusion vulnerability in galleria.html.php in Galleria Mambo Module 1.0 and earlier for Mambo allows r
23RISK
open
Referência
CVE-2018-4090
An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. tvOS
23RISK
open
Referência
CVE-2019-19230
An unsafe deserialization vulnerability exists in CA Release Automation (Nolio) 6.6 with the DataManagement component th
48RISK
open
previouspage 280 / 723next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.