Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,107cataloged exploits
34,679CVEs with public exploitation
24,695lab-tested
21,692 exploits
Referência
CVE-2010-2932
Buffer overflow in BarCodeWiz BarCode 3.29 ActiveX control (BarcodeWiz.dll) allows remote attackers to execute arbitrary
23RISK
open
Referência
CVE-2010-1337
Multiple PHP remote file inclusion vulnerabilities in definitions.php in Lussumo Vanilla 1.1.10, and possibly 0.9.2 and
23RISK
open
ReferênciaVexDay Proof
YapBB 1.2 Beta2 - 'yapbb_session.php' Remote File Inclusion
CVE-2006-6633webappsphp
PHP remote file inclusion vulnerability in include/yapbb_session.php in YapBB 1.2 Beta2 and earlier allows remote attack
23RISK
open
Referência
CVE-2010-1272
PHP remote file inclusion vulnerability in includes/tgpinc.php in Gnat-TGP 1.2.20 and earlier allows remote attackers to
23RISK
open
Referência
CVE-2010-1272
PHP remote file inclusion vulnerability in includes/tgpinc.php in Gnat-TGP 1.2.20 and earlier allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
pagetree CMS 0.0.2 Beta 0001 - Remote File Inclusion
CVE-2008-7067webappsphp
PHP remote file inclusion vulnerability in admin/plugins/Online_Users/main.php in PageTree CMS 0.0.2 BETA 0001 allows re
23RISK
open
ReferênciaVexDay Proof
mxBB Module mx_blogs 2.0.0-beta - Remote File Inclusion
CVE-2008-1712webappsphp
PHP remote file inclusion vulnerability in includes/functions_weblog.php in mxBB mx_blogs 2.0.0 beta allows remote attac
23RISK
open
Referência
CVE-2018-12705
DIGISOL DG-BR4000NG devices have XSS via the SSID (it is validated only on the client side).
23RISK
open
Referência
CVE-2017-10204
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version
23RISK
open
Referência
CVE-2017-10204
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version
23RISK
open
ReferênciaVexDay Proof
ScorpNews 1.0 - 'site' Remote File Inclusion
CVE-2008-2193webappsphp
PHP remote file inclusion vulnerability in example.php in Thomas Gossmann ScorpNews 2.0 allows remote attackers to execu
23RISK
open
ReferênciaVexDay Proof
webframe 0.76 - Multiple File Inclusions
CVE-2009-0514webappsphp
Multiple directory traversal vulnerabilities in WebFrame 0.76 allow remote attackers to include and execute arbitrary lo
23RISK
open
ReferênciaVexDay Proof
Orlando CMS 0.6 - Remote File Inclusion
CVE-2008-2854webappsphp
Multiple PHP remote file inclusion vulnerabilities in Orlando CMS 0.6 allow remote attackers to execute arbitrary PHP co
23RISK
open
Referência
CVE-2009-20010
Dogfood CRM spell.php RCE
63RISK
open
Referência
CVE-2009-20010
Dogfood CRM spell.php RCE
63RISK
open
ReferênciaVexDay Proof
phpDMCA 1.0.0 - Multiple Remote File Inclusions
CVE-2008-2986webappsphp
Multiple PHP remote file inclusion vulnerabilities in phpDMCA 1.0.0 allow remote attackers to execute arbitrary PHP code
23RISK
open
ReferênciaVexDay Proof
Potato News 1.0.0 - Local File Inclusion
CVE-2009-0722webappsphp
Directory traversal vulnerability in admin.php in Potato News 1.0.0 allows remote attackers to include and execute arbit
23RISK
open
ReferênciaVexDay Proof
MiNBank 1.5.0 - Multiple Remote File Inclusions
CVE-2008-6006webappsphp
Multiple PHP remote file inclusion vulnerabilities in Micronation Banking System (minba) 1.5.0 allow remote attackers to
23RISK
open
Referência
CVE-2013-6873
SQL injection vulnerability in Testa Online Test Management System (OTMS) 2.0.0.2 allows remote attackers to execute arb
23RISK
open
ReferênciaVexDay Proof
SiteX 0.7.4.418 - 'THEME_FOLDER' Local File Inclusion
CVE-2009-1846webappsphp
Multiple directory traversal vulnerabilities in SiteX 0.7.4 Build 418 and earlier allow remote attackers to include and
23RISK
open
ReferênciaVexDay Proof
Sofi WebGui 0.6.3 PRE - 'mod_dir' Remote File Inclusion
CVE-2008-6402webappsphp
PHP remote file inclusion vulnerability in hu/modules/reg-new/modstart.php in Sofi WebGui 0.6.3 PRE and earlier allows r
23RISK
open
Referência
CVE-2010-1945
Multiple PHP remote file inclusion vulnerabilities in openMairie Openfoncier 2.00, when register_globals is enabled, all
23RISK
open
Referência
CVE-2010-1946
Multiple PHP remote file inclusion vulnerabilities in openMairie Openregistrecil 1.02, when register_globals is enabled,
23RISK
open
ReferênciaVexDay Proof
OpenRat 0.8-beta4 - 'tpl_dir' Remote File Inclusion
CVE-2008-6403webappsphp
PHP remote file inclusion vulnerability in themes/default/include/html/insert.inc.php in OpenRat 0.8-beta4 and earlier a
23RISK
open
Referência
CVE-2010-2973
Integer overflow in IOSurface in Apple iOS before 4.0.2 on the iPhone and iPod touch, and before 3.2.2 on the iPad, allo
23RISK
open
Referência
CVE-2009-3756
phpBMS 0.96 allows remote attackers to obtain sensitive information via a direct request to (1) footer.php, (2) header.p
23RISK
open
Referência
CVE-2013-1414
Multiple cross-site request forgery (CSRF) vulnerabilities in Fortinet FortiOS on FortiGate firewall devices before 4.3.
23RISK
open
ReferênciaVexDay Proof
PAD Site Scripts 3.6 - Arbitrary Database Backup
CVE-2009-1941webappsphp
PAD Site Scripts 3.6 stores sensitive information under the web document root with insufficient access control, which al
23RISK
open
ReferênciaVexDay Proof
Bubbling Library 1.32 - Multiple Local File Inclusions
CVE-2008-0545webappsphp
Multiple directory traversal vulnerabilities in Bubbling Library 1.32 allow remote attackers to include and execute arbi
23RISK
open
ReferênciaVexDay Proof
PEEL CMS 3.x - Admin Hash Extraction / Arbitrary File Upload
CVE-2008-1507webappsphp
PEEL, possibly 3.x and earlier, has (1) a default info@peel.fr account with password admin, and (2) a default contact@pe
23RISK
open
previouspage 300 / 724next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.