Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,313cataloged exploits
34,834CVEs with public exploitation
24,695lab-tested
21,797 exploits
ReferênciaVexDay Proof
XOOPS mod_gallery Zend_Hash_key + Extract - Remote File Inclusion
CVE-2008-0138webappsphp
PHP remote file inclusion vulnerability in xoopsgallery/init_basic.php in the mod_gallery module for XOOPS, when registe
23RISK
open
ReferênciaVexDay Proof
FlashBlog 0.31b - Arbitrary File Upload
CVE-2008-2574webappsphp
Unrestricted file upload vulnerability in admin/Editor/imgupload.php in FlashBlog 0.31 beta allows remote attackers to e
23RISK
open
ReferênciaVexDay Proof
NUVICO DVR NVDV4 / PdvrAtl Module 'PdvrAtl.DLL 1.0.1.25' - Remote Buffer Overflow
CVE-2008-4547remotewindows
Heap-based buffer overflow in the PdvrAtl.PdvrOcx.1 ActiveX control (pdvratl.dll) in DVRHOST Web CMS OCX 1.0.1.25 allows
28RISK
open
Referência
CVE-2022-4050
JoomSport < 5.2.8 - Unauthenticated SQLi
63RISK
open
Referência
CVE-2022-4059
Cryptocurrency Widgets Pack < 2.0 - Unauthenticated SQLi
63RISK
open
Referência
CVE-2017-2474
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS b
23RISK
open
Referência
CVE-2022-4049
WP User <= 7.0 - Unauthenticated SQLi
63RISK
open
Referência
CVE-2010-20103
ProFTPD 1.3.3c Backdoor Command Execution
63RISK
open
Referência
CVE-2010-20103
ProFTPD 1.3.3c Backdoor Command Execution
63RISK
open
Referência
CVE-2010-20103
ProFTPD 1.3.3c Backdoor Command Execution
63RISK
open
Referência
CVE-2018-18774
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows XSS via the admin/index.php module parameter.
23RISK
open
Referência
CVE-2026-16565
Dokan < 5.0.9 - Vendor+ Cross-Vendor Product Attribute Modification via Product Attribute REST API
33RISK
open
Referência
CVE-2026-16564
Dokan < 5.0.9 - Vendor+ Arbitrary Order Status Modification via orders/bulk-actions REST Endpoint
33RISK
open
Referência
CVE-2026-16563
Academy LMS < 3.8.3 - Subscriber+ Arbitrary Lesson Content Disclosure via lessons REST Endpoint
33RISK
open
Referência
CVE-2026-16539
SM Page Duplicator <= 1.0.0 - Editor+ SQL Injection via Page Duplication
41RISK
open
Referência
CVE-2021-24174
Database Backups <= 1.2.2.6 - CSRF to Backup Download
23RISK
open
ReferênciaVexDay Proof
eXeScope 6.50 - Local Buffer Overflow
CVE-2009-1063localwindows
Buffer overflow in eXeScope 6.50 allows user-assisted remote attackers to execute arbitrary code via a crafted executabl
23RISK
open
Referência
CVE-2014-100017
Cross-site scripting (XSS) vulnerability in canned_opr.php in PhpOnlineChat 3.0 allows remote attackers to inject arbitr
23RISK
open
Referência
CVE-2014-100017
Cross-site scripting (XSS) vulnerability in canned_opr.php in PhpOnlineChat 3.0 allows remote attackers to inject arbitr
23RISK
open
ReferênciaVexDay Proof
IrayoBlog 0.2.4 - '/inc/irayofuncs.php' Remote File Inclusion
CVE-2006-5849webappsphp
PHP remote file inclusion vulnerability in inc/irayofuncs.php in IrayoBlog alpha-0.2.4 allows remote attackers to execut
23RISK
open
Referência
CVE-2021-40868
In Cloudron 6.2, the returnTo parameter on the login page is vulnerable to Reflected XSS.
38RISK
open
Referência
CVE-2021-40868
In Cloudron 6.2, the returnTo parameter on the login page is vulnerable to Reflected XSS.
38RISK
open
Referência
CVE-2018-11511
The tree list functionality in the photo gallery application in ASUSTOR ADM 3.1.0.RFQ3 has a SQL injection vulnerability
43RISK
open
Referência
CVE-2017-9978
On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, a flaw was found with the error message sent as a response
23RISK
open
Referência
CVE-2017-9978
On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, a flaw was found with the error message sent as a response
23RISK
open
Referência
CVE-2016-1821
IOAudioFamily in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a
23RISK
open
ReferênciaVexDay Proof
Omegaboard 1.0beta4 - 'functions.php' Remote File Inclusion
CVE-2007-0683webappsphp
PHP remote file inclusion vulnerability in includes/functions.php in Omegaboard 1.0beta4 and earlier allows remote attac
23RISK
open
ReferênciaVexDay Proof
Htaccess Passwort Generator 1.1 - 'ht_pfad' Remote File Inclusion
CVE-2007-1013webappsphp
PHP remote file inclusion vulnerability in generate.php in VirtualSystem Htaccess Passwort Generator 1.1 allows remote a
23RISK
open
Referência
CVE-2009-3968
Multiple SQL injection vulnerabilities in ITechBids 8.0 allow remote attackers to execute arbitrary SQL commands via the
23RISK
open
Referência
CVE-2009-3969
Stack-based buffer overflow in Faslo Player 7.0 allows remote attackers to cause a denial of service (application crash)
23RISK
open
previouspage 316 / 727next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.