Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,559cataloged exploits
34,978CVEs with public exploitation
24,695lab-tested
21,899 exploits
Referência
CVE-2016-20078
WordPress IMDb Profile Widget 1.0.8 Local File Inclusion via pic.php
33RISK
open
Referência
CVE-2016-20077
WordPress Plugin Photocart Link 1.6 Local File Inclusion via decode.php
33RISK
open
Referência
CVE-2016-20076
WordPress Simple-Backup 2.7.11 Arbitrary File Deletion and Download
41RISK
open
Referência
CVE-2016-20075
WordPress Ultimate Product Catalog 3.8.6 Arbitrary File Upload RCE
41RISK
open
Referência
CVE-2016-20074
WordPress Lazy Content Slider Plugin 3.4 CSRF
33RISK
open
Referência
CVE-2016-20067
WordPress CP Polls 1.0.8 Cross-Site Request Forgery
33RISK
open
Referência
CVE-2026-34021
Lack of cryptographic protection in Wertheim SafeController 5400 enables RS-485 message sniffing and replay
41RISK
open
Referência
CVE-2026-12217
DVDFab Virtual Drive Signed Kernel Driver dvdfabio.sys privileges management
41RISK
open
Referência
CVE-2026-12216
svaarala duktape duk_api_bytecode.c memory corruption
33RISK
open
Referência
CVE-2026-12204
ShopXO Scheduled Task Endpoint Crontab.php GoodsGiveIntegral authorization
33RISK
open
Referência
CVE-2026-12203
HKUDS AI-Trader Research Export agents.csv information disclosure
33RISK
open
ReferênciaVexDay Proof
more.groupware 0.74 - 'new_calendarid' SQL Injection
CVE-2006-4906webappsphp
SQL injection vulnerability in modules/calendar/week.php in More.groupware 0.74 allows remote attackers to execute arbit
23RISK
open
Referência
CVE-2009-4583
SQL injection vulnerability in the DhForum (com_dhforum) component for Joomla! allows remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
PHP DocWriter 0.3 - 'script' Remote File Inclusion
CVE-2006-4912webappsphp
PHP remote file inclusion vulnerability in PHP DocWriter 0.3 and earlier allows remote attackers to execute arbitrary PH
23RISK
open
Referência
CVE-2009-4583
SQL injection vulnerability in the DhForum (com_dhforum) component for Joomla! allows remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
Alstrasoft e-Friends 4.85 - Remote Command Execution
CVE-2006-4913webappsphp
Directory traversal vulnerability in chat/getStartOptions.php in AlstraSoft E-friends 4.85 allows remote attackers to in
23RISK
open
ReferênciaVexDay Proof
Tekman Portal 1.0 - 'tr' SQL Injection
CVE-2006-4916webappsasp
SQL injection vulnerability in uye_profil.asp in Tekman Portal (TR) 1.0 allows remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
Simple Discussion Board 0.1.0 - Remote File Inclusion
CVE-2006-4918webappsphp
Multiple PHP remote file inclusion vulnerabilities in Simple Discussion Board 0.1.0 allow remote attackers to execute ar
23RISK
open
Referência
CVE-2009-4588
Heap-based buffer overflow in the WindsPlayerIE.View.1 ActiveX control in WindsPly.ocx 3.5.0.0 Beta, 3.0.0.5, and earlie
50RISK
open
ReferênciaVexDay Proof
Site@School 2.4.02 - Arbitrary File Upload
CVE-2006-4922webappsphp
Unrestricted file upload vulnerability in starnet/editors/htmlarea/popups/images.php in Site@School (S@S) 2.4.02 and ear
23RISK
open
ReferênciaVexDay Proof
ProgSys 0.156 - 'RR.php' Remote File Inclusion
CVE-2006-4944webappsphp
PHP remote file inclusion vulnerability in includes/pear/Net/DNS/RR.php in ProgSys 0.151 and earlier allows remote attac
23RISK
open
ReferênciaVexDay Proof
Digital WebShop 1.128 - Multiple Remote File Inclusions
CVE-2006-4945webappsphp
Multiple PHP remote file inclusion vulnerabilities in Cardway (aka Frederic Boudaud) DigitalWebShop 1.128 and earlier al
23RISK
open
Referência
CVE-2009-4596
Cross-site scripting (XSS) vulnerability in index.php in PHP Inventory 1.2 allows remote attackers to inject arbitrary w
23RISK
open
ReferênciaVexDay Proof
MyReview 1.9.4 - 'email' SQL Injection / Code Execution
CVE-2006-4957webappsphp
SQL injection vulnerability in the GetMember function in functions.php in MyReview 1.9.4 allows remote attackers to exec
23RISK
open
Referência
CVE-2009-4597
Multiple SQL injection vulnerabilities in index.php in PHP Inventory 1.2 allow (1) remote authenticated users to execute
23RISK
open
ReferênciaVexDay Proof
PHP Blue Dragon CMS 2.9.1 - Cross-Site Scripting / SQL Injection Code Execution
CVE-2006-4960webappsphp
Cross-site scripting (XSS) vulnerability in index.php Php Blue Dragon 2.9.1 and earlier allows remote attackers to injec
23RISK
open
ReferênciaVexDay Proof
PHP Blue Dragon CMS 2.9.1 - Cross-Site Scripting / SQL Injection Code Execution
CVE-2006-4961webappsphp
SQL injection vulnerability in the GetModuleConfig function in public_includes/pub_kernel/pbd_modules.php in Php Blue Dr
23RISK
open
Referência
CVE-2009-4597
Multiple SQL injection vulnerabilities in index.php in PHP Inventory 1.2 allow (1) remote authenticated users to execute
23RISK
open
ReferênciaVexDay Proof
PHP Blue Dragon CMS 2.9.1 - Cross-Site Scripting / SQL Injection Code Execution
CVE-2006-4962webappsphp
Directory traversal vulnerability in pbd_engine.php in Php Blue Dragon 2.9.1 and earlier allows remote attackers to read
23RISK
open
ReferênciaVexDay Proof
PHP Blue Dragon CMS 3.0.0 - Remote Code Execution
CVE-2006-4962webappsphp
Directory traversal vulnerability in pbd_engine.php in Php Blue Dragon 2.9.1 and earlier allows remote attackers to read
23RISK
open
previouspage 348 / 730next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.