Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,313cataloged exploits
34,834CVEs with public exploitation
24,695lab-tested
21,797 exploits
ReferênciaVexDay Proof
e107 - 'include()' Remote File Upload
CVE-2004-2262webappsphp
ImageManager in e107 before 0.617 does not properly check the types of uploaded files, which allows remote attackers to
28RISK
open
ReferênciaVexDay Proof
GeoVision LiveX 8200 - ActiveX 'LIVEX_~1.OCX' File Corruption
CVE-2009-0865remotewindows
Directory traversal vulnerability in the SnapShotToFile method in the GeoVision LiveX (aka LiveX_v8200) ActiveX control
23RISK
open
ReferênciaVexDay Proof
MySQL Commander 2.7 - 'home' Remote File Inclusion
CVE-2007-1439webappsphp
PHP remote file inclusion vulnerability in ressourcen/dbopen.php in bitesser MySQL Commander 2.7 and earlier, when regis
23RISK
open
ReferênciaVexDay Proof
Apollo 37zz - '.m3u' Local Heap Overflow (PoC)
CVE-2009-1351doswindows
Heap-based buffer overflow in Apollo 37zz allows remote attackers to cause a denial of service (application crash) and p
23RISK
open
ReferênciaVexDay Proof
PowerCHM 5.7 - Long URL Local Stack Overflow (PoC)
CVE-2009-1352doswindows
Stack-based buffer overflow in Dawningsoft PowerCHM 5.7 allows remote attackers to cause a denial of service (applicatio
23RISK
open
ReferênciaVexDay Proof
PHP 5.2.3 Win32std - 'win_shell_execute' Safe Mode / disable_functions Bypass
CVE-2007-4010localwindows
The win32std extension in PHP 5.2.3 does not follow safe_mode and disable_functions restrictions, which allows remote at
23RISK
open
ReferênciaVexDay Proof
DigiMode Maya 1.0.2 - '.m3u' / '.m3l' Buffer Overflow (PoC)
CVE-2009-1817doswindows
Multiple buffer overflows in DigiMode Maya 1.0.2 allow remote attackers to execute arbitrary code via a long string in a
23RISK
open
ReferênciaVexDay Proof
SanyBee Gallery 0.1.1 - 'p' Local File Inclusion
CVE-2007-6648webappsphp
Directory traversal vulnerability in index.php in SanyBee Gallery 0.1.0 and 0.1.1 allows remote attackers to include and
23RISK
open
ReferênciaVexDay Proof
WordPress Plugin fGallery 2.4.1 - 'fimrss.php' SQL Injection
CVE-2008-0491webappsphp
SQL injection vulnerability in fim_rss.php in the fGallery 2.4.1 plugin for WordPress allows remote attackers to execute
23RISK
open
Referência
CVE-2024-0566
Smart Manager < 8.28.0 - Admin+ SQL Injection
41RISK
open
Referência
CVE-2013-5961
Unrestricted file upload vulnerability in lazyseo.php in the Lazy SEO plugin 1.1.9 for WordPress allows remote attackers
23RISK
open
Referência
CVE-2013-5961
Unrestricted file upload vulnerability in lazyseo.php in the Lazy SEO plugin 1.1.9 for WordPress allows remote attackers
23RISK
open
Referência
CVE-2013-4949
Unrestricted file upload vulnerability in view.php in Machform 2 allows remote attackers to execute arbitrary PHP code b
23RISK
open
Referência
CVE-2013-4949
Unrestricted file upload vulnerability in view.php in Machform 2 allows remote attackers to execute arbitrary PHP code b
23RISK
open
Referência
CVE-2009-3364
Stack-based buffer overflow in FTPShell Client 4.1 RC2 allows remote FTP servers to execute arbitrary code via a long re
23RISK
open
Referência
CVE-2016-0007
The sandbox implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8,
23RISK
open
Referência
CVE-2016-0007
The sandbox implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8,
23RISK
open
Referência
CVE-2011-2641
Opera 11.11 allows remote attackers to cause a denial of service (application crash) by setting the FACE attribute of a
23RISK
open
Referência
CVE-2022-39290
CSRF key bypass using HTTP methods in zoneminder
41RISK
open
Referência
CVE-2014-8357
backupsettings.html in the web administrative portal in Zhone zNID GPON 2426A before S3.0.501 places a session key in a
23RISK
open
Referência
CVE-2014-8357
backupsettings.html in the web administrative portal in Zhone zNID GPON 2426A before S3.0.501 places a session key in a
23RISK
open
Referência
CVE-2009-3598
Cross-site scripting (XSS) vulnerability in survey_result.php in eCardMAX FormXP 2007 allows remote attackers to inject
23RISK
open
ReferênciaVexDay Proof
iPhotoAlbum 1.1 - 'header.php' Remote File Inclusion
CVE-2005-2246webappsphp
Multiple PHP remote file inclusion vulnerabilities in iPhotoAlbum 1.1 allow remote attackers to execute arbitrary code v
23RISK
open
ReferênciaVexDay Proof
Hex Workshop 5.1.4 - Color Mapping File Local Buffer Overflow (PoC)
CVE-2008-5756doswindows
Buffer overflow in BreakPoint Software Hex Workshop 5.1.4 allows user-assisted attackers to cause a denial of service an
23RISK
open
Referência
CVE-2010-1069
SQL injection vulnerability in games/game.php in ProArcadeScript allows remote attackers to execute arbitrary SQL comman
23RISK
open
Referência
CVE-2015-1561
The escape_command function in include/Administration/corePerformance/getStats.php in Centreon (formerly Merethis Centre
23RISK
open
Referência
CVE-2015-2678
Multiple cross-site scripting (XSS) vulnerabilities in MetalGenix GeniXCMS before 0.0.2 allow remote attackers to inject
23RISK
open
Referência
CVE-2015-2678
Multiple cross-site scripting (XSS) vulnerabilities in MetalGenix GeniXCMS before 0.0.2 allow remote attackers to inject
23RISK
open
Referência
CVE-2019-14339
The ContentProvider in the Canon PRINT jp.co.canon.bsd.ad.pixmaprint 2.5.5 application for Android does not properly res
23RISK
open
Referência
CVE-2015-8368
ntopng (aka ntop) before 2.2 allows remote authenticated users to change the login context and gain privileges via the u
23RISK
open
previouspage 320 / 727next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.