Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,008cataloged exploits
34,638CVEs with public exploitation
24,695lab-tested
21,662 exploits
Referência
LightCMS 1.3.4 - 'exclusive' Stored XSS
CVE-2021-3355webappsmultiple
A stored-self XSS exists in LightCMS v1.3.4, allowing an attacker to execute HTML or JavaScript code in a vulnerable Tit
23RISK
open
Referência
Postbird 0.8.4 - Javascript Injection
CVE-2021-33570webappsmultiple
Postbird 0.8.4 allows stored XSS via the onerror attribute of an IMG element in any PostgreSQL database table. This can
23RISK
open
ReferênciaVexDay Proof
Millewin 13.39.146.1 - Local Privilege Escalation
CVE-2021-3394localwindows
Millennium Millewin (also known as "Cartella clinica") 13.39.028, 13.39.28.3342, and 13.39.146.1 has insecure folder per
23RISK
open
Referência
CVE-2017-0284
Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT
23RISK
open
Referência
CVE-2021-34369
portlets/contact/ref/refContactDetail.do in Accela Civic Platform through 20.1 allows remote attackers to obtain sensiti
23RISK
open
Referência
CVE-2010-5007
Cross-site scripting (XSS) vulnerability in pages/match_report.php in UTStats Beta 4 and earlier allows remote attackers
23RISK
open
Referência
CVE-2022-40946
On D-Link DIR-819 Firmware Version 1.06 Hardware Version A1 devices, it is possible to trigger a Denial of Service via t
41RISK
open
Referência
CVE-2018-7216
Cross-site request forgery (CSRF) vulnerability in esop/toolkit/profile/regData.do in Bravo Tejari Procurement Portal al
23RISK
open
Referência
CVE-2018-7216
Cross-site request forgery (CSRF) vulnerability in esop/toolkit/profile/regData.do in Bravo Tejari Procurement Portal al
23RISK
open
Referência
CVE-2017-16783
In CMS Made Simple 2.1.6, there is Server-Side Template Injection via the cntnt01detailtemplate parameter.
23RISK
open
Referência
CVE-2010-5007
Cross-site scripting (XSS) vulnerability in pages/match_report.php in UTStats Beta 4 and earlier allows remote attackers
23RISK
open
Referência
CVE-2019-14280
In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images whe
23RISK
open
ReferênciaVexDay Proof
MODx CMS 0.9.2.1 - 'FCKeditor' Remote File Inclusion
CVE-2006-5730webappsphp
PHP remote file inclusion vulnerability in manager/media/browser/mcpuk/connectors/php/Commands/Thumbnail.php in Modx CMS
23RISK
open
ReferênciaVexDay Proof
Durian Web Application Server 3.02 - Remote Buffer Overflow
CVE-2006-6853remotewindows
Buffer overflow in Durian Web Application Server 3.02 freeware on Windows allows remote attackers to execute arbitrary c
23RISK
open
ReferênciaVexDay Proof
Ax Developer CMS 0.1.1 - 'index.php?module' Local File Inclusion
CVE-2007-5820webappsphp
Directory traversal vulnerability in index.php in Ax Developer CMS (AxDCMS) 0.1.1 allows remote attackers to include and
23RISK
open
ReferênciaVexDay Proof
Lanius CMS 1.2.16 - 'FCKeditor' Arbitrary File Upload
CVE-2007-5156webappsphp
Incomplete blacklist vulnerability in editor/filemanager/upload/php/upload.php in FCKeditor, as used in SiteX CMS 0.7.3.
23RISK
open
ReferênciaVexDay Proof
SyntaxCMS 1.3 - 'FCKeditor' Arbitrary File Upload
CVE-2007-5156webappsphp
Incomplete blacklist vulnerability in editor/filemanager/upload/php/upload.php in FCKeditor, as used in SiteX CMS 0.7.3.
23RISK
open
ReferênciaVexDay Proof
eLineStudio Site Composer (ESC) 2.6 - Multiple Vulnerabilities
CVE-2008-2861webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in eLineStudio Site Composer (ESC) 2.6 and earlier allow remote atta
23RISK
open
ReferênciaVexDay Proof
pPIM 1.0 - Arbitrary File Delete / Cross-Site Scripting
CVE-2008-4425webappsphp
Directory traversal vulnerability in upload.php in Phlatline's Personal Information Manager (pPIM) 1.0 allows remote att
23RISK
open
ReferênciaVexDay Proof
ClaSS 0.8.60 - 'export.php' Local File Inclusion
CVE-2008-5856webappsphp
Directory traversal vulnerability in scripts/export.php in ClaSS before 0.8.61 allows remote attackers to read arbitrary
23RISK
open
Referência
CVE-2019-19245
NAPC Xinet Elegant 6 Asset Library 6.1.655 allows Pre-Authentication SQL Injection via the /elegant6/login LoginForm[use
23RISK
open
Referência
CVE-2016-2539
Cross-site request forgery (CSRF) vulnerability in install_modules.php in ATutor before 2.2.2 allows remote attackers to
23RISK
open
Referência
CVE-2016-2539
Cross-site request forgery (CSRF) vulnerability in install_modules.php in ATutor before 2.2.2 allows remote attackers to
23RISK
open
Referência
CVE-2022-45717
IP-COM M50 V15.11.0.33(10768) was discovered to contain a command injection vulnerability via the usbPartitionName param
48RISK
open
Referência
CVE-2022-45709
IP-COM M50 V15.11.0.33(10768) was discovered to contain multiple command injection vulnerabilities via the pEnable, pLev
48RISK
open
Referência
CVE-2014-8577
Multiple cross-site scripting (XSS) vulnerabilities in Croogo before 2.1.0 allow remote attackers to inject arbitrary we
23RISK
open
Referência
CVE-2014-8577
Multiple cross-site scripting (XSS) vulnerabilities in Croogo before 2.1.0 allow remote attackers to inject arbitrary we
23RISK
open
Referência
CVE-2017-2353
An issue was discovered in certain Apple products. macOS before 10.12.3 is affected. The issue involves the "Bluetooth"
23RISK
open
Referência
CVE-2017-13865
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RISK
open
Referência
CVE-2017-2456
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS b
23RISK
open
previouspage 281 / 723next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.