Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,559cataloged exploits
34,978CVEs with public exploitation
24,695lab-tested
21,899 exploits
Referência
CVE-2026-9523
Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform getCalcmeterDetailDayListTree sql injection
33RISK
open
ReferênciaVexDay Proof
FlashBB 1.1.8 - 'phpbb_root_path' Remote File Inclusion
CVE-2006-7032webappsphp
PHP remote file inclusion vulnerability in phpbb/getmsg.php in FlashBB 1.1.5 and earlier allows remote attackers to exec
23RISK
open
Referência
CVE-2009-4756
Stack-based buffer overflow in TraktorBeatport.exe 1.0.0.283 in Beatport Player 1.0.0.0 allows remote attackers to execu
23RISK
open
ReferênciaVexDay Proof
Linux Kernel 2.6.x - 'sys_timer_create()' Local Denial of Service
CVE-2006-7051doslinux
The sys_timer_create function in posix-timers.c for Linux kernel 2.6.x allows local users to cause a denial of service (
23RISK
open
Referência
CVE-2009-4756
Stack-based buffer overflow in TraktorBeatport.exe 1.0.0.283 in Beatport Player 1.0.0.0 allows remote attackers to execu
23RISK
open
ReferênciaVexDay Proof
TinyPHP Forum 3.6 - 'profile.php' Remote Code Execution
CVE-2006-7063webappsphp
Directory traversal vulnerability in profile.php in TinyPHPforum 3.6 and earlier allows remote attackers to include and
23RISK
open
ReferênciaVexDay Proof
PhpNews 1.0 - 'Include' Remote File Inclusion
CVE-2006-7081webappsphp
Multiple PHP remote file inclusion vulnerabilities in PhpNews 1.0 allow remote attackers to execute arbitrary PHP code v
23RISK
open
Referência
CVE-2022-41082
CVE-2022-41082HIGHunder attackransomware
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
Referência
CVE-2026-9520
blitz-js blitz Sign-in LoginForm.tsx cross site scripting
33RISK
open
Referência
CVE-2025-59287
CVE-2025-59287CRITICALunder attack
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RISK
open
ReferênciaVexDay Proof
PHPWind 5.0.1 - 'AdminUser' Blind SQL Injection
CVE-2006-7101webappsphp
SQL injection vulnerability in admin.php in PHPWind 5.0.1 and earlier allows remote attackers to execute arbitrary SQL c
23RISK
open
ReferênciaVexDay Proof
Power Phlogger 2.0.9 - 'config.inc.php3' File Inclusion
CVE-2006-7106webappsphp
PHP remote file inclusion vulnerability in config.inc.php3 in Power Phlogger 2.0.9 and earlier allows remote attackers t
23RISK
open
ReferênciaVexDay Proof
FreePBX 2.1.3 - 'upgrade.php' Remote File Inclusion
CVE-2006-7107webappsphp
PHP remote file inclusion vulnerability in upgrade.php in Coalescent Systems freePBX 2.1.3 allows remote attackers to ex
23RISK
open
Referência
CVE-2018-15961
CVE-2018-15961CRITICALunder attack
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unr
100RISK
open
Referência
CVE-2023-38035
CVE-2023-38035CRITICALunder attackransomware
A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an
100RISK
open
Referência
CVE-2021-27065
CVE-2021-27065HIGHunder attackransomware
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
Referência
CVE-2021-27065
CVE-2021-27065HIGHunder attackransomware
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
Referência
CVE-2025-24813
CVE-2025-24813CRITICALunder attack
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
Referência
CVE-2021-3129
CVE-2021-3129CRITICALunder attackransomware
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
Referência
CVE-2021-3129
CVE-2021-3129CRITICALunder attackransomware
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
ReferênciaVexDay Proof
Microsoft Help Workshop 4.03.0002 - '.cnt' Local Buffer Overflow
CVE-2007-0352localwindows
Stack-based buffer overflow in Microsoft Help Workshop 4.03.0002 allows user-assisted remote attackers to execute arbitr
35RISK
open
Referência
CVE-2009-4781
TUKEVA Password Reminder before 1.0.0.4 uses a hard-coded password for rem.accdb, which allows local users to discover c
23RISK
open
ReferênciaVexDay Proof
Apple Mac OSX 10.4.8 - SLP Daemon Service Registration Buffer Overflow (PoC)
CVE-2007-0355dososx
Buffer overflow in the Apple Minimal SLP v2 Service Agent (slpd) in Mac OS X 10.4.11 and earlier, including 10.4.8, allo
23RISK
open
ReferênciaVexDay Proof
CCRP Folder Treeview Control (ccrpftv6.ocx) - IE Denial of Service
CVE-2007-0356doswindows
The Common Controls Replacement Project (CCRP) FolderTreeview (FTV) ActiveX control (ccrpftv6.ocx) allows remote attacke
28RISK
open
Referência
CVE-2009-4783
Multiple SQL injection vulnerabilities in Theeta CMS, possibly 0.01, allow remote attackers to execute arbitrary SQL com
23RISK
open
ReferênciaVexDay Proof
Oreon 1.2.3 RC4 - '/lang/index.php' Remote File Inclusion
CVE-2007-0360webappsphp
PHP remote file inclusion vulnerability in lang/index.php in Oreon 1.2.3 RC4 and earlier allows remote attackers to exec
23RISK
open
ReferênciaVexDay Proof
phpBP RC3 (2.204) - SQL Injection / Remote Code Execution
CVE-2007-0369webappsphp
SQL injection vulnerability in phpBP RC3 (2.204) and earlier allows remote attackers to execute arbitrary SQL commands v
23RISK
open
Referência
CVE-2009-4784
SQL injection vulnerability in the Joaktree (com_joaktree) component 1.0 for Joomla! allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
BrowseDialog Class 'ccrpbds6.dll' Internet Explorer 7 - Denial of Service
CVE-2007-0371doswindows
A certain ActiveX control in the Common Controls Replacement Project (CCRP) CCRP BrowseDialog Server (ccrpbds6.dll) allo
23RISK
open
Referência
CVE-2020-10189
CVE-2020-10189CRITICALunder attack
Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted d
100RISK
open
previouspage 337 / 730next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.