Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,107cataloged exploits
34,679CVEs with public exploitation
24,695lab-tested
21,692 exploits
ReferênciaVexDay Proof
CWB PRO 1.5 - 'INCLUDE_PATH' Remote File Inclusion
CVE-2007-1809webappsphp
Multiple PHP remote file inclusion vulnerabilities in GraFX Company WebSite Builder (CWB) PRO 1.5 allow remote attackers
23RISK
open
ReferênciaVexDay Proof
XnView 1.92.1 - 'FontName' Slideshow Buffer Overflow
CVE-2008-0069localwindows
Stack-based buffer overflow in XnView 1.92 and 1.92.1 allows user-assisted remote attackers to execute arbitrary code vi
23RISK
open
ReferênciaVexDay Proof
PHPStore Real Estate - Arbitrary File Upload
CVE-2008-6930webappsphp
Unrestricted file upload vulnerability in PHPStore Real Estate allows remote authenticated users to execute arbitrary co
23RISK
open
Referência
CVE-2015-4038
The WP Membership plugin 1.2.3 for WordPress allows remote authenticated users to gain administrator privileges via an i
23RISK
open
Referência
CVE-2015-1362
Buffer overflow in the Customize 35mm tab in Two Pilots Exif Pilot 4.7.2 allows remote attackers to execute arbitrary co
23RISK
open
Referência
CVE-2015-1362
Buffer overflow in the Customize 35mm tab in Two Pilots Exif Pilot 4.7.2 allows remote attackers to execute arbitrary co
23RISK
open
ReferênciaVexDay Proof
Pligg CMS 9.9.0 - Cross-Site Scripting / Local File Inclusion / SQL Injection
CVE-2008-7090webappsphp
Multiple directory traversal vulnerabilities in Pligg 9.9 and earlier allow remote attackers to (1) determine the existe
23RISK
open
Referência
CVE-2017-14702
ERS Data System 1.8.1.0 allows remote attackers to execute arbitrary code, related to "com.branaghgroup.ecers.update.Upd
23RISK
open
Referência
CVE-2018-15172
TP-Link WR840N devices have a buffer overflow via a long Authorization HTTP header.
23RISK
open
Referência
CVE-2015-4624
Hak5 WiFi Pineapple 2.0 through 2.3 uses predictable CSRF tokens.
50RISK
open
Referência
CVE-2018-14336
TP-Link WR840N devices allow remote attackers to cause a denial of service (connectivity loss) via a series of packets w
23RISK
open
Referência
CVE-2010-2126
Multiple PHP remote file inclusion vulnerabilities in Snipe Gallery 3.1.5 allow remote attackers to execute arbitrary PH
23RISK
open
ReferênciaVexDay Proof
Bitweaver 1.3 - 'tmpImagePath' Attachment mod_mime
CVE-2006-3102webappsphp
Race condition in articles/BitArticle.php in Bitweaver 1.3, when run on Apache with the mod_mime extension, allows remot
23RISK
open
Referência
CVE-2010-1982
Directory traversal vulnerability in the JA Voice (com_javoice) component 2.0 for Joomla! allows remote attackers to rea
38RISK
open
Referência
CVE-2010-1982
Directory traversal vulnerability in the JA Voice (com_javoice) component 2.0 for Joomla! allows remote attackers to rea
38RISK
open
Referência
CVE-2018-5752
The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev4
23RISK
open
Referência
CVE-2018-5752
The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev4
23RISK
open
Referência
CVE-2021-46424
Telesquare TLR-2005KSH 1.0.0 is affected by an arbitrary file deletion vulnerability that allows a remote attacker to de
50RISK
open
ReferênciaVexDay Proof
TWiki 4.2.0 - 'configure' Remote File Disclosure
CVE-2008-3195webappscgi
Directory traversal vulnerability in bin/configure in TWiki before 4.2.3, when a certain step in the installation guide
23RISK
open
Referência
CVE-2009-3154
SQL injection vulnerability in the Almond Classifieds (com_aclassf) component 7.5 for Joomla! allows remote attackers to
23RISK
open
Referência
FTP Server 1.32 - Denial of Service
CVE-2019-9600dosandroid
The Olive Tree FTP Server (aka com.theolivetree.ftpserver) application through 1.32 for Android allows remote attackers
23RISK
open
ReferênciaVexDay Proof
ApowerManager 3.1.7 - Phone Manager Remote Denial of Service (PoC)
CVE-2019-9601dosandroid
The ApowerManager application through 3.1.7 for Android allows remote attackers to cause a denial of service via many si
23RISK
open
Referência
CVE-2019-17080
mintinstall (aka Software Manager) 7.9.9 for Linux Mint allows code execution if a REVIEWS_CACHE file is controlled by a
23RISK
open
Referência
CVE-2014-2021
Cross-site scripting (XSS) vulnerability in admincp/apilog.php in vBulletin 4.2.2 and earlier, and 5.0.x through 5.0.5 a
23RISK
open
Referência
CVE-2017-14322
The function in charge to check whether the user is already logged in init.php in Interspire Email Marketer (IEM) prior
35RISK
open
Referência
CVE-2013-6025
The XMLParse procedure in SAP Sybase Adaptive Server Enterprise (ASE) 15.7 ESD 2 allows remote authenticated users to re
23RISK
open
ReferênciaVexDay Proof
Opera Web Browser 9.00 - 'iframe' Remote Denial of Service
CVE-2006-3353dosmultiple
Opera 9 allows remote attackers to cause a denial of service (crash) via a crafted web page that triggers an out-of-boun
23RISK
open
Referência
CVE-2017-2446
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RISK
open
Referência
CVE-2017-2446
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RISK
open
ReferênciaVexDay Proof
Foxit Reader 2.0 - 'PDF' Remote Denial of Service
CVE-2007-2186doswindows
Foxit Reader 2.0 allows remote attackers to cause a denial of service (application crash) via a crafted PDF document.
23RISK
open
previouspage 302 / 724next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.