Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,313cataloged exploits
34,834CVEs with public exploitation
24,695lab-tested
21,797 exploits
Referência
CVE-2021-24750
WP Visitor Statistics (Real Time Traffic) < 4.8 - Subscriber+ SQL Injection
50RISK
open
Referência
CVE-2023-33131
Microsoft Outlook Remote Code Execution Vulnerability
41RISK
open
Referência
CVE-2020-12352
Improper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adja
23RISK
open
Referência
CVE-2020-12352
Improper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adja
23RISK
open
Referência
CVE-2020-8899
Memory corruption in Quram library when decoding qmg can lead to RCE
48RISK
open
Referência
CVE-2014-0871
RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allows remote att
23RISK
open
Referência
CVE-2011-0502
Music Animation Machine MIDI Player 2006aug19 Release 035 and possibly other versions allows user-assisted remote attack
23RISK
open
Referência
CVE-2023-53941
EasyPHP Webserver 14.1 Remote Code Execution
48RISK
open
ReferênciaVexDay Proof
PHPFK 7.03 - 'page_bottom.php' Local File Inclusion
CVE-2009-2112webappsphp
Directory traversal vulnerability in include/page_bottom.php in phpFK 7.03 allows remote attackers to include and execut
23RISK
open
Referência
CVE-2025-14708
Shiguangwu sgwbox N3 WIREDCFGGET http_eshell_server buffer overflow
48RISK
open
Referência
CVE-2018-4193
An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Windows Ser
23RISK
open
Referência
CVE-2017-8869
Buffer overflow in MediaCoder 0.8.48.5888 allows remote attackers to execute arbitrary code via a crafted .m3u file.
43RISK
open
ReferênciaVexDay Proof
Campsite 3.3.0 RC1 - Multiple Remote File Inclusions
CVE-2009-2183webappsphp
Directory traversal vulnerability in admin-files/ad.php in Campsite 3.3.0 RC1 allows remote attackers to read and possib
23RISK
open
ReferênciaVexDay Proof
e107 Plugin My_Gallery 2.3 - Arbitrary File Download
CVE-2008-1702webappsphp
Absolute path traversal vulnerability in dload.php in the my_gallery 2.3 plugin for e107 allows remote attackers to obta
23RISK
open
ReferênciaVexDay Proof
Acoustica Beatcraft 1.02 Build 19 - '.bcproj' Local Buffer Overflow
CVE-2008-4087localwindows
Stack-based buffer overflow in Acoustica Beatcraft 1.02 Build 19 allows user-assisted attackers to cause a denial of ser
23RISK
open
Referência
CVE-2021-25094
Tatsu < 3.3.12 - Unauthenticated RCE
60RISK
open
Referência
CVE-2015-2679
Multiple SQL injection vulnerabilities in MetalGenix GeniXCMS before 0.0.2 allow remote attackers to execute arbitrary S
23RISK
open
Referência
CVE-2015-2679
Multiple SQL injection vulnerabilities in MetalGenix GeniXCMS before 0.0.2 allow remote attackers to execute arbitrary S
23RISK
open
Referência
CVE-2010-3906
Cross-site scripting (XSS) vulnerability in Gitweb 1.7.3.3 and earlier allows remote attackers to inject arbitrary web s
23RISK
open
Referência
CVE-2010-4401
languages.inc.php in DynPG CMS 4.2.0 allows remote attackers to obtain sensitive information via a direct request, which
23RISK
open
Referência
CVE-2009-4775
Format string vulnerability in Ipswitch WS_FTP Professional 12 before 12.2 allows remote attackers to cause a denial of
23RISK
open
Referência
CVE-2009-4775
Format string vulnerability in Ipswitch WS_FTP Professional 12 before 12.2 allows remote attackers to cause a denial of
23RISK
open
Referência
CVE-2017-15035
EmTec PyroBatchFTP before 3.18 allows remote servers to cause a denial of service (application crash).
23RISK
open
Referência
CVE-2016-1415
Cisco WebEx Meetings Player T29.10, when WRF file support is enabled, allows remote attackers to cause a denial of servi
23RISK
open
ReferênciaVexDay Proof
Ultra Crypto Component - 'CryptoX.dll 2.0 SaveToFile()' Insecure Method
CVE-2007-4902remotewindows
Absolute path traversal vulnerability in a certain ActiveX control in CryptoX.dll 2.0 and earlier in the Ultra Crypto Co
23RISK
open
Referência
CVE-2014-3139
recoveryconsole/bpl/snmpd.php in Unitrends Enterprise Backup 7.3.0 allows remote attackers to bypass authentication by s
23RISK
open
ReferênciaVexDay Proof
freeSSHd 1.2.1 - (Authenticated) Remote Stack Overflow (PoC)
CVE-2008-2573doswindows
Stack-based buffer overflow in SFTP in freeSSHd 1.2.1 allows remote authenticated users to execute arbitrary code via a
23RISK
open
ReferênciaVexDay Proof
SyndeoCMS 2.6.0 - Local File Inclusion / Cross-Site Scripting
CVE-2008-5272webappsphp
Multiple directory traversal vulnerabilities in Fred Stuurman SyndeoCMS 2.6.0 allow remote authenticated users to read a
23RISK
open
ReferênciaVexDay Proof
XOOPS 2.3.1 - Multiple Local File Inclusions
CVE-2008-6884webappsphp
Multiple directory traversal vulnerabilities in XOOPS 2.3.1, when register_globals is enabled, allow remote attackers to
23RISK
open
Referência
CVE-2018-11505
The Werewolf Online application 0.8.8 for Android allows attackers to discover the Firebase token by reading logcat outp
23RISK
open
previouspage 310 / 727next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.