Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,565cataloged exploits
34,981CVEs with public exploitation
24,695lab-tested
21,899 exploits
Referência
CVE-2026-7271
DV0x creative-ad-agent creative-ad-agent-server sdk-server.ts path traversal
33RISK
open
Referência
CVE-2026-7269
SourceCodester Pharmacy Sales and Inventory System index.php cross site scripting
33RISK
open
Referência
CVE-2026-7268
SourceCodester Pizzafy Ecommerce System ajax.php save_category sql injection
33RISK
open
Referência
CVE-2026-7267
SourceCodester Pizzafy Ecommerce System view_prod.php sql injection
33RISK
open
Referência
CVE-2026-7266
SourceCodester Pizzafy Ecommerce System ajax.php save_order sql injection
33RISK
open
Referência
CVE-2026-7265
SourceCodester Pizzafy Ecommerce System index.php category sql injection
33RISK
open
Referência
CVE-2026-7264
SourceCodester Pizzafy Ecommerce System ajax.php get_cart_items sql injection
33RISK
open
Referência
CVE-2026-7248
D-Link DI-8100 CGI Endpoint tgfile.htm tgfile_htm buffer overflow
48RISK
open
Referência
CVE-2026-7247
D-Link DI-8100 File Extension file_exten.asp file_exten_asp buffer overflow
41RISK
open
Referência
CVE-2026-7244
Totolink A8000RU CGI cstecgi.cgi setWiFiEasyGuestCfg os command injection
48RISK
open
Referência
CVE-2026-7243
Totolink A8000RU CGI cstecgi.cgi setRadvdCfg os command injection
48RISK
open
Referência
CVE-2025-10539
Improper TLS Certificate Validation RCE via Malicious Update in DeskTime Time Tracking App
33RISK
open
Referência
CVE-2026-7241
Totolink A8000RU CGI cstecgi.cgi setWiFiBasicCfg os command injection
48RISK
open
Referência
CVE-2026-7240
Totolink A8000RU CGI cstecgi.cgi setVpnAccountCfg os command injection
48RISK
open
Referência
CVE-2026-5306
Check & Log Email < 2.0.13 - Unauthenticated Stored XSS
33RISK
open
Referência
CVE-2026-7227
SourceCodester Pizzafy Ecommerce System ajax.php login sql injection
33RISK
open
ReferênciaVexDay Proof
Remotesoft .NET Explorer 2.0.1 - Local Stack Overflow (PoC)
CVE-2007-0766doswindows
Stack-based buffer overflow in Remotesoft .NET Explorer 2.0.1 allows user-assisted remote attackers to cause a denial of
23RISK
open
ReferênciaVexDay Proof
Flip 2.01 final - 'previewtheme.php?inc_path' Remote File Inclusion
CVE-2007-0785webappsphp
PHP remote file inclusion vulnerability in previewtheme.php in Flipsource Flip 2.01-final 1.0 and earlier allows remote
35RISK
open
ReferênciaVexDay Proof
Photo Galerie Standard 1.1 - 'view.php' SQL Injection
CVE-2007-0786webappsphp
SQL injection vulnerability in view.php in Noname Media Photo Galerie Standard 1.1.1 and earlier allows remote attackers
23RISK
open
ReferênciaVexDay Proof
SmartFTP Client 2.0.1002 - Remote Heap Overflow Denial of Service
CVE-2007-0790doswindows
Heap-based buffer overflow in SmartFTP 2.0.1002 allows remote FTP servers to execute arbitrary code via a large banner.
23RISK
open
ReferênciaVexDay Proof
SMA-DB 0.3.9 - 'settings.php' Remote File Inclusion
CVE-2007-0797webappsphp
PHP remote file inclusion vulnerability in theme/settings.php in bluevirus-design SMA-DB 0.3.9 and earlier allows remote
23RISK
open
Referência
CVE-2021-1497
CVE-2021-1497CRITICALunder attack
Cisco HyperFlex HX Command Injection Vulnerabilities
100RISK
open
Referência
CVE-2022-29303
CVE-2022-29303CRITICALunder attack
SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php.
100RISK
open
ReferênciaVexDay Proof
Categories hierarchy phpBB Mod 2.1.2 - 'phpbb_root_path' Remote File Inclusion
CVE-2007-0809webappsphp
PHP remote file inclusion vulnerability in includes/class_template.php in Categories hierarchy (aka CH or mod-CH) 2.1.2
23RISK
open
ReferênciaVexDay Proof
Geeklog 2 - 'BaseView.php' Remote File Inclusion
CVE-2007-0810webappsphp
PHP remote file inclusion vulnerability in MVCnPHP/BaseView.php in GeekLog 2 and earlier allows remote attackers to exec
23RISK
open
ReferênciaVexDay Proof
Woltlab Burning Board Lite 1.0.2pl3e - 'pms.php' SQL Injection
CVE-2007-0812webappsphp
SQL injection vulnerability in pms.php in Woltlab Burning Board (wBB) Lite 1.0.2pl3e and earlier allows remote authentic
23RISK
open
ReferênciaVexDay Proof
LightRO CMS 1.0 - 'inhalt.php' Remote File Inclusion
CVE-2007-0824webappsphp
PHP remote file inclusion vulnerability in inhalt.php in LightRO CMS 1.0 allows remote attackers to execute arbitrary PH
23RISK
open
ReferênciaVexDay Proof
Kisisel Site 2007 - 'tr' SQL Injection
CVE-2007-0826webappsphp
SQL injection vulnerability in forum.asp in Kisisel Site 2007 allows remote attackers to execute arbitrary SQL commands
23RISK
open
ReferênciaVexDay Proof
Alibaba Alipay - Remove ActiveX Remote Code Execution
CVE-2007-0827remotewindows
The Alibaba Alipay PTA Module ActiveX control (PTA.DLL) allows remote attackers to execute arbitrary code via a JavaScri
23RISK
open
ReferênciaVexDay Proof
Advanced Poll 2.0.5-dev - Remote Admin Session Generator
CVE-2007-0845webappsphp
admin/index.php in Advanced Poll 2.0.0 through 2.0.5-dev allows remote attackers to bypass authentication and gain admin
23RISK
open
previouspage 349 / 730next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.