Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,607cataloged exploits
34,986CVEs with public exploitation
24,695lab-tested
21,899 exploits
ReferênciaVexDay Proof
pl-PHP Beta 0.9 - Multiple Vulnerabilities
CVE-2007-2006webappsphp
Multiple SQL injection vulnerabilities in login.php in pL-PHP beta 0.9 allow remote attackers to execute arbitrary SQL c
23RISK
open
ReferênciaVexDay Proof
pl-PHP Beta 0.9 - Multiple Vulnerabilities
CVE-2007-2008webappsphp
Directory traversal vulnerability in admin.php in pL-PHP beta 0.9 allows remote attackers to include and execute arbitra
23RISK
open
ReferênciaVexDay Proof
Joomla! Component mosmedia 1.0.8 - Remote File Inclusion
CVE-2007-2043webappsphp
Multiple PHP remote file inclusion vulnerabilities in the Avant-Garde Solutions MOSMedia (com_mosmedia) 1.08 and earlier
23RISK
open
ReferênciaVexDay Proof
Mambo Module Weather - 'absolute_path' Remote File Inclusion
CVE-2007-2044webappsphp
PHP remote file inclusion vulnerability in mod_weather.php in the Antonis Ventouris Weather module for Mambo and Joomla!
23RISK
open
Referência
CVE-2017-0147
CVE-2017-0147HIGHunder attackransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Referência
CVE-2017-1000353
CVE-2017-1000353CRITICALunder attack
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code exe
100RISK
open
Referência
CVE-2020-10220
An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php
60RISK
open
Referência
CVE-2020-10220
An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php
60RISK
open
Referência
CVE-2020-10220
An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php
60RISK
open
Referência
CVE-2022-22965
CVE-2022-22965CRITICALunder attack
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
Referência
CVE-2022-22965
CVE-2022-22965CRITICALunder attack
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
Referência
CVE-2017-8687
The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
23RISK
open
Referência
CVE-2022-0543
CVE-2022-0543CRITICALunder attack
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific
100RISK
open
Referência
CVE-2021-31166
CVE-2021-31166CRITICALunder attack
HTTP Protocol Stack Remote Code Execution Vulnerability
100RISK
open
Referência
CVE-2023-46604
CVE-2023-46604CRITICALunder attackransomware
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISK
open
Referência
CVE-2020-37225
Powie's WHOIS Domain Check 0.9.31 Persistent Cross-Site Scripting
33RISK
open
Referência
CVE-2020-37224
Joomla J2 JOBS 1.3.0 Authenticated SQL Injection via sortby
41RISK
open
Referência
CVE-2020-37223
IObit Uninstaller 9.5.0.15 Unquoted Service Path Privilege Escalation
41RISK
open
Referência
CVE-2020-37222
Kuicms Php EE 2.0 Persistent Cross-Site Scripting via bbs reply
33RISK
open
ReferênciaVexDay Proof
aForum 1.32 - 'CommonAbsDir' Remote File Inclusion
CVE-2007-2596webappsphp
PHP remote file inclusion vulnerability in common/func.php in aForum 1.32 and earlier allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
telltarget 1.3.3 - 'tt_docroot' Remote File Inclusion
CVE-2007-2597webappsphp
Multiple PHP remote file inclusion vulnerabilities in telltarget CMS 1.3.3 allow remote attackers to execute arbitrary P
28RISK
open
ReferênciaVexDay Proof
TutorialCMS 1.00 - 'search.php?search' SQL Injection
CVE-2007-2599webappsphp
Multiple SQL injection vulnerabilities in TutorialCMS (aka Photoshop Tutorials) 1.00 and earlier allow remote attackers
23RISK
open
ReferênciaVexDay Proof
TutorialCMS 1.00 - 'search.php?search' SQL Injection
CVE-2007-2600webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in TutorialCMS (aka Photoshop Tutorials) 1.00 and earlier allow remo
23RISK
open
ReferênciaVexDay Proof
Miplex2 - 'SmartyFU.class.php' Remote File Inclusion
CVE-2007-2608webappsphp
PHP remote file inclusion vulnerability in lib/smarty/SmartyFU.class.php in Miplex2 Alpha 1 allows remote attackers to e
23RISK
open
ReferênciaVexDay Proof
PHPLojaFacil 0.1.5 - 'path_local' Remote File Inclusion
CVE-2007-2615webappsphp
Multiple PHP remote file inclusion vulnerabilities in Crie seu PHPLojaFacil 0.1.5 allow remote attackers to execute arbi
23RISK
open
Referência
CVE-2009-5093
Directory traversal vulnerability in gastbuch.php in Gästebuch (Gastebuch) 1.6 allows remote attackers to read arbitrary
23RISK
open
ReferênciaVexDay Proof
Original 0.11 - 'config.inc.php?x[1]' Remote File Inclusion
CVE-2007-2620webappsphp
PHP remote file inclusion vulnerability in inc/config.inc.php in Jakub Steiner (aka jimmac) original 0.11 allows remote
23RISK
open
ReferênciaVexDay Proof
NagiosQL 2005 2.00 - 'prepend_adm.php' Remote File Inclusion
CVE-2007-2709webappsphp
PHP remote file inclusion vulnerability in functions/prepend_adm.php in NagiosQL 2005 2.00 allows remote attackers to ex
23RISK
open
ReferênciaVexDay Proof
Snaps! Gallery 1.4.4 - Remote User Pass Change
CVE-2007-2715webappsphp
Admin/users.php in Snaps! Gallery 1.4.4 allows remote attackers to change arbitrary usernames and passwords via the (1)
28RISK
open
ReferênciaVexDay Proof
XOOPS Module resmanager 1.21 - Blind SQL Injection
CVE-2007-2735webappsphp
SQL injection vulnerability in edit_day.php in the ResManager 1.2.1 and earlier module for Xoops allows remote attackers
23RISK
open
previouspage 352 / 730next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.