Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,008cataloged exploits
34,638CVEs with public exploitation
24,695lab-tested
21,662 exploits
ReferênciaVexDay Proof
PHPQuickGallery 1.9 - 'textFile' Remote File Inclusion
CVE-2006-6044webappsphp
PHP remote file inclusion vulnerability in gallery_top.inc.php in PHPQuickGallery 1.9 and earlier allows remote attacker
23RISK
open
ReferênciaVexDay Proof
phpBB Tweaked 3 - 'phpbb_root_path' Remote File Inclusion
CVE-2007-0680webappsphp
PHP remote file inclusion vulnerability in includes/functions.php in Phpbb Tweaked 3 and earlier allows remote attackers
23RISK
open
ReferênciaVexDay Proof
phpBB Module SupaNav 1.0.0 - 'link_main.php' Remote File Inclusion
CVE-2007-3935webappsphp
PHP remote file inclusion vulnerability in link_main.php in the SupaNav 1.0.0 module for phpBB allows remote attackers t
23RISK
open
Referência
CVE-2010-2034
Directory traversal vulnerability in the Percha Image Attach (com_perchaimageattach) component 1.1 for Joomla! allows re
43RISK
open
Referência
CVE-2020-13118
An issue was discovered in Mikrotik-Router-Monitoring-System through 2018-10-22. SQL Injection exists in check_community
23RISK
open
Referência
CVE-2010-2035
Directory traversal vulnerability in the Percha Gallery (com_perchagallery) component 1.6 Beta for Joomla! allows remote
43RISK
open
Referência
CVE-2014-8690
Multiple cross-site scripting (XSS) vulnerabilities in Exponent CMS before 2.1.4 patch 6, 2.2.x before 2.2.3 patch 9, an
23RISK
open
Referência
CVE-2014-8690
Multiple cross-site scripting (XSS) vulnerabilities in Exponent CMS before 2.1.4 patch 6, 2.2.x before 2.2.3 patch 9, an
23RISK
open
Referência
CVE-2010-2036
Directory traversal vulnerability in the Percha Fields Attach (com_perchafieldsattach) component 1.x for Joomla! allows
43RISK
open
Referência
CVE-2010-2037
Directory traversal vulnerability in the Percha Downloads Attach (com_perchadownloadsattach) component 1.1 for Joomla! a
43RISK
open
ReferênciaVexDay Proof
Quake 3 Engine 1.32b - 'R_RemapShader()' Remote Client Buffer Overflow
CVE-2006-2236remotelinux
Buffer overflow in the Quake 3 Engine, as used by (1) ET 2.60, (2) Return to Castle Wolfenstein 1.41, and (3) Quake III
23RISK
open
Referência
CVE-2016-1915
Multiple cross-site scripting (XSS) vulnerabilities in BlackBerry Enterprise Server 12 (BES12) Self-Service before 12.4
23RISK
open
Referência
CVE-2026-10551
Breeze Cache < 2.5.6 - Unauthenticated Stored XSS via Minify Library
33RISK
open
ReferênciaVexDay Proof
phpBB User Viewed Posts Tracker 1.0 - Remote File Inclusion
CVE-2006-5223webappsphp
PHP remote file inclusion vulnerability in includes/functions_user_viewed_posts.php in the Nivisec User Viewed Posts Tra
23RISK
open
ReferênciaVexDay Proof
OpenEMR 2.8.1 - 'srcdir' Multiple Remote File Inclusions
CVE-2006-5811webappsphp
PHP remote file inclusion vulnerability in library/translation.inc.php in OpenEMR 2.8.1, with register_globals enabled,
23RISK
open
ReferênciaVexDay Proof
MiniBB 2.0.5 - 'Language' Local File Inclusion
CVE-2007-3272webappsphp
Directory traversal vulnerability in index.php in MiniBB 2.0.5 allows remote attackers to read arbitrary files via a ..
23RISK
open
Referência
CVE-2017-15957
my_profile.php in Ingenious School Management System 2.3.0 allows a student or teacher to upload an arbitrary file.
23RISK
open
Referência
CVE-2017-15957
my_profile.php in Ingenious School Management System 2.3.0 allows a student or teacher to upload an arbitrary file.
23RISK
open
ReferênciaVexDay Proof
ScriptsFeed (SF) Real Estate Classifieds Software - Arbitrary File Upload
CVE-2008-6942webappsphp
Unrestricted file upload vulnerability in ScriptsFeed Realtor Classifieds System (aka Real Estate Classifieds) allows re
23RISK
open
ReferênciaVexDay Proof
X-Forum 0.6.2 - Remote Command Execution
CVE-2009-1512webappsphp
Static code injection vulnerability in X-Forum 0.6.2 allows remote authenticated administrators to inject arbitrary PHP
23RISK
open
Referência
CVE-2017-17590
FS Stackoverflow Clone 1.0 has SQL Injection via the /question keywords parameter.
23RISK
open
Referência
CVE-2017-17590
FS Stackoverflow Clone 1.0 has SQL Injection via the /question keywords parameter.
23RISK
open
ReferênciaVexDay Proof
wget 1.10.2 - Unchecked Boundary Condition Denial of Service
CVE-2006-6719dosmultiple
The ftp_syst function in ftp-basic.c in Free Software Foundation (FSF) GNU wget 1.10.2 allows remote attackers to cause
23RISK
open
ReferênciaVexDay Proof
IP Reg 0.3 - Multiple SQL Injections
CVE-2007-6579webappsphp
Multiple SQL injection vulnerabilities in Ip Reg 0.3 allow remote attackers to execute arbitrary SQL commands via the vl
23RISK
open
Referência
CVE-2012-4891
Cross-site scripting (XSS) vulnerability in fw/index2.do in ManageEngine Firewall Analyzer 7.2 allows remote attackers t
23RISK
open
Referência
CVE-2012-4891
Cross-site scripting (XSS) vulnerability in fw/index2.do in ManageEngine Firewall Analyzer 7.2 allows remote attackers t
23RISK
open
Referência
CVE-2015-2680
Cross-site request forgery (CSRF) vulnerability in MetalGenix GeniXCMS before 0.0.2 allows remote attackers to hijack th
23RISK
open
Referência
CVE-2015-2680
Cross-site request forgery (CSRF) vulnerability in MetalGenix GeniXCMS before 0.0.2 allows remote attackers to hijack th
23RISK
open
Referência
CVE-2014-9605
WebUpgrade in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass aut
23RISK
open
Referência
CVE-2015-2508
The Adobe Type Manager Library in Microsoft Windows 10 allows local users to gain privileges via a crafted application,
23RISK
open
previouspage 285 / 723next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.