Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,313cataloged exploits
34,834CVEs with public exploitation
24,695lab-tested
21,797 exploits
Referência
CVE-2010-4401
languages.inc.php in DynPG CMS 4.2.0 allows remote attackers to obtain sensitive information via a direct request, which
23RISK
open
Referência
CVE-2009-4775
Format string vulnerability in Ipswitch WS_FTP Professional 12 before 12.2 allows remote attackers to cause a denial of
23RISK
open
Referência
CVE-2009-4775
Format string vulnerability in Ipswitch WS_FTP Professional 12 before 12.2 allows remote attackers to cause a denial of
23RISK
open
Referência
CVE-2017-15035
EmTec PyroBatchFTP before 3.18 allows remote servers to cause a denial of service (application crash).
23RISK
open
Referência
CVE-2016-1415
Cisco WebEx Meetings Player T29.10, when WRF file support is enabled, allows remote attackers to cause a denial of servi
23RISK
open
ReferênciaVexDay Proof
Ultra Crypto Component - 'CryptoX.dll 2.0 SaveToFile()' Insecure Method
CVE-2007-4902remotewindows
Absolute path traversal vulnerability in a certain ActiveX control in CryptoX.dll 2.0 and earlier in the Ultra Crypto Co
23RISK
open
Referência
CVE-2014-3139
recoveryconsole/bpl/snmpd.php in Unitrends Enterprise Backup 7.3.0 allows remote attackers to bypass authentication by s
23RISK
open
ReferênciaVexDay Proof
freeSSHd 1.2.1 - (Authenticated) Remote Stack Overflow (PoC)
CVE-2008-2573doswindows
Stack-based buffer overflow in SFTP in freeSSHd 1.2.1 allows remote authenticated users to execute arbitrary code via a
23RISK
open
ReferênciaVexDay Proof
SyndeoCMS 2.6.0 - Local File Inclusion / Cross-Site Scripting
CVE-2008-5272webappsphp
Multiple directory traversal vulnerabilities in Fred Stuurman SyndeoCMS 2.6.0 allow remote authenticated users to read a
23RISK
open
ReferênciaVexDay Proof
XOOPS 2.3.1 - Multiple Local File Inclusions
CVE-2008-6884webappsphp
Multiple directory traversal vulnerabilities in XOOPS 2.3.1, when register_globals is enabled, allow remote attackers to
23RISK
open
Referência
CVE-2018-11505
The Werewolf Online application 0.8.8 for Android allows attackers to discover the Firebase token by reading logcat outp
23RISK
open
Referência
CVE-2011-5219
Directory traversal vulnerability in examples/show_code.php in mPDF 5.3 and earlier allows remote attackers to read arbi
23RISK
open
Referência
CVE-2021-25680
The AdTran Personal Phone Manager software is vulnerable to multiple reflected cross-site scripting (XSS) issues. These
23RISK
open
Referência
CVE-2010-1053
Multiple SQL injection vulnerabilities in Zen Time Tracking 2.2 and earlier, when magic_quotes_gpc is disabled, allow re
23RISK
open
Referência
CVE-2016-3974
XML external entity (XXE) vulnerability in the Configuration Wizard in SAP NetWeaver Java AS 7.1 through 7.5 allows remo
28RISK
open
Referência
CVE-2017-15287
There is XSS in the BouquetEditor WebPlugin for Dream Multimedia Dreambox devices, as demonstrated by the "Name des Bouq
38RISK
open
Referência
CVE-2016-3974
XML external entity (XXE) vulnerability in the Configuration Wizard in SAP NetWeaver Java AS 7.1 through 7.5 allows remo
28RISK
open
Referência
CVE-2017-11319
Perspective ICM Investigation & Case 5.1.1.16 allows remote authenticated users to modify access level permissions and c
23RISK
open
Referência
CVE-2017-11319
Perspective ICM Investigation & Case 5.1.1.16 allows remote authenticated users to modify access level permissions and c
23RISK
open
Referência
CVE-2009-2379
Directory traversal vulnerability in public/index.php in BIGACE Web CMS 2.6 allows remote attackers to include and execu
23RISK
open
Referência
CVE-2010-4399
Directory traversal vulnerability in languages.inc.php in DynPG CMS 4.1.1 and 4.2.0, when magic_quotes_gpc is disabled,
23RISK
open
Referência
CVE-2010-4399
Directory traversal vulnerability in languages.inc.php in DynPG CMS 4.1.1 and 4.2.0, when magic_quotes_gpc is disabled,
23RISK
open
Referência
CVE-2019-7400
Rukovoditel before 2.4.1 allows XSS.
23RISK
open
Referência
CVE-2019-7400
Rukovoditel before 2.4.1 allows XSS.
23RISK
open
Referência
CVE-2017-16543
Zoho ManageEngine Applications Manager 13 before build 13500 allows SQL injection via GraphicalView.do, as demonstrated
23RISK
open
ReferênciaVexDay Proof
Snort 2.6.1.1/2.6.1.2/2.7.0 - 'fragementation' Remote Denial of Service
CVE-2007-1398dosmultiple
The frag3 preprocessor in Snort 2.6.1.1, 2.6.1.2, and 2.7.0 beta, when configured for inline use on Linux without the ip
23RISK
open
Referência
CVE-2012-6307
A vulnerability exists in JPEGsnoop 1.5.2 due to an unspecified issue in JPEG file handling, which could let a malicious
23RISK
open
ReferênciaVexDay Proof
MP3 TrackMaker 1.5 - '.mp3' Local Heap Overflow (PoC)
CVE-2009-0175doswindows
Heap-based buffer overflow in Heathco Software MP3 TrackMaker 1.5 allows remote attackers to cause a denial of service (
23RISK
open
ReferênciaVexDay Proof
db Software Laboratory VImpX - 'VImpX.ocx' Multiple Vulnerabilities
CVE-2008-4750remotewindows
Stack-based buffer overflow in the VImpX.VImpAX ActiveX control (VImpX.ocx) 4.8.8.0 in DB Software Laboratory VImp X, po
23RISK
open
ReferênciaVexDay Proof
TLS - Renegotiation
CVE-2009-3555CRITICALremotemultiple
The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS
70RISK
open
previouspage 311 / 727next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.