Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,559cataloged exploits
34,978CVEs with public exploitation
24,695lab-tested
21,899 exploits
Referência
CVE-2019-16759
CVE-2019-16759CRITICALunder attack
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RISK
open
Referência
CVE-2026-8759
xiandafu beetl SpELFunction SpELFunction.java expression language injection
33RISK
open
Referência
CVE-2026-8758
Metasoft 美特软件 MetaCRM upload3.jsp unrestricted upload
33RISK
open
Referência
CVE-2021-38647
CVE-2021-38647CRITICALunder attackransomware
Open Management Infrastructure Remote Code Execution Vulnerability
100RISK
open
Referência
CVE-2017-0147
CVE-2017-0147HIGHunder attackransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Referência
CVE-2017-1000353
CVE-2017-1000353CRITICALunder attack
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code exe
100RISK
open
Referência
CVE-2020-10220
An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php
60RISK
open
Referência
CVE-2020-10220
An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php
60RISK
open
Referência
CVE-2020-10220
An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php
60RISK
open
Referência
CVE-2022-22965
CVE-2022-22965CRITICALunder attack
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
Referência
CVE-2022-22965
CVE-2022-22965CRITICALunder attack
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
Referência
CVE-2017-8687
The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
23RISK
open
Referência
CVE-2020-37225
Powie's WHOIS Domain Check 0.9.31 Persistent Cross-Site Scripting
33RISK
open
Referência
CVE-2020-37224
Joomla J2 JOBS 1.3.0 Authenticated SQL Injection via sortby
41RISK
open
Referência
CVE-2020-37223
IObit Uninstaller 9.5.0.15 Unquoted Service Path Privilege Escalation
41RISK
open
Referência
CVE-2020-37222
Kuicms Php EE 2.0 Persistent Cross-Site Scripting via bbs reply
33RISK
open
ReferênciaVexDay Proof
BtiTracker 1.4.1 - Become Admin SQL Injection
CVE-2007-2854webappsphp
Multiple SQL injection vulnerabilities in account_change.php in BtiTracker 1.4.1 and earlier allow remote attackers to e
23RISK
open
Referência
CVE-2009-5134
Buffer overflow in the "create torrent dialog" functionality in uTorrent 1.8.3 build 15772, and possibly other versions
23RISK
open
ReferênciaVexDay Proof
Microsoft Visual Basic 6.0 Project - Company Name Stack Overflow (PoC)
CVE-2007-2884doswindows
Multiple stack-based buffer overflows in Microsoft Visual Basic 6 allow user-assisted remote attackers to cause a denial
35RISK
open
ReferênciaVexDay Proof
Microsoft Visual Basic 6.0 Project - Description Stack Overflow (PoC)
CVE-2007-2884doswindows
Multiple stack-based buffer overflows in Microsoft Visual Basic 6 allow user-assisted remote attackers to cause a denial
35RISK
open
ReferênciaVexDay Proof
UltraISO 8.6.2.2011 - '.cue/'.bin' Local Buffer Overflow (PoC)
CVE-2007-2888doswindows
Stack-based buffer overflow in UltraISO 8.6.2.2011 and earlier allows user-assisted remote attackers to execute arbitrar
50RISK
open
ReferênciaVexDay Proof
CPCommerce 1.1.0 - 'id_category' SQL Injection
CVE-2007-2890webappsphp
SQL injection vulnerability in category.php in cpCommerce 1.1.0 and earlier allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
OpenBASE 0.6a - 'root_prefix' Remote File Inclusion
CVE-2007-2947webappsphp
Multiple PHP remote file inclusion vulnerabilities in OpenBASE Alpha 0.6 allow remote attackers to execute arbitrary PHP
23RISK
open
ReferênciaVexDay Proof
Pheap 2.0 - Authentication Bypass / Remote Code Execution
CVE-2007-2985webappsphp
Pheap 2.0 allows remote attackers to bypass authentication by setting a pheap_login cookie value to the administrator's
23RISK
open
ReferênciaVexDay Proof
AdminBot 9.0.5 - 'live_status.lib.php' Remote File Inclusion
CVE-2007-2986webappsphp
PHP remote file inclusion vulnerability in lib/live_status.lib.php in AdminBot MX 9.0.5 allows remote attackers to execu
35RISK
open
ReferênciaVexDay Proof
Acoustica MP3 CD Burner 4.51 Build 147 - '.asx' Local Buffer Overflow
CVE-2007-3006localwindows
Buffer overflow in Acoustica MP3 CD Burner 4.32 allows user-assisted remote attackers to execute arbitrary code via a .a
23RISK
open
ReferênciaVexDay Proof
Microsoft Windows Message Queuing Service - RPC Buffer Overflow (MS07-065) (1)
CVE-2007-3039remotewindows
Stack-based buffer overflow in the Microsoft Message Queuing (MSMQ) service in Microsoft Windows 2000 Server SP4, Window
50RISK
open
ReferênciaVexDay Proof
Microsoft Windows Message Queuing Service - RPC Buffer Overflow (MS07-065) (2)
CVE-2007-3039remotewindows
Stack-based buffer overflow in the Microsoft Message Queuing (MSMQ) service in Microsoft Windows 2000 Server SP4, Window
50RISK
open
ReferênciaVexDay Proof
Microsoft Windows Server 2000 SP4 (Advanced Server) - Message Queue (MS07-065)
CVE-2007-3039remotewindows
Stack-based buffer overflow in the Microsoft Message Queuing (MSMQ) service in Microsoft Windows 2000 Server SP4, Window
50RISK
open
ReferênciaVexDay Proof
PNPHPBB2 < 1.2 - 'index.php' SQL Injection
CVE-2007-3052webappsphp
SQL injection vulnerability in index.php in the PNphpBB2 1.2i and earlier module for PostNuke allows remote attackers to
23RISK
open
previouspage 347 / 730next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.