Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,647cataloged exploits
34,986CVEs with public exploitation
24,695lab-tested
21,899 exploits
ReferênciaVexDay Proof
Centreon 1.4.2.3 - 'get_image.php' Remote File Disclosure
CVE-2008-1119webappsphp
Directory traversal vulnerability in include/doc/get_image.php in Centreon 1.4.2.3 and earlier allows remote attackers t
23RISK
open
ReferênciaVexDay Proof
Podcast Generator 1.0 Beta 2 - Remote File Inclusion / File Disclosure
CVE-2008-1124webappsphp
Multiple PHP remote file inclusion vulnerabilities in Podcast Generator 1.0 BETA 2 and earlier allow remote attackers to
28RISK
open
ReferênciaVexDay Proof
Mambo Component garyscookbook 1.1.1 - SQL Injection
CVE-2008-1137webappsphp
SQL injection vulnerability in the Garys Cookbook (com_garyscookbook) 1.1.1 and earlier component for Mambo and Joomla!
23RISK
open
Referência
CVE-2010-0802
SQL injection vulnerability in index.php in (nv2) Awards 1.1.0, a modification for Invision Power Board, allows remote a
23RISK
open
ReferênciaVexDay Proof
DESlock+ < 3.2.6 - 'DLMFENC.sys' Local Kernel Ring0 link list zero (PoC)
CVE-2008-1138doswindows
DLMFENC.sys 1.0.0.26 in DESlock+ 3.2.6 and earlier allows local users to cause a denial of service (system crash) via a
23RISK
open
Referência
CVE-2026-70619
Odysseus Missing Admin Authorization via Embedding Endpoint Routes
41RISK
open
Referência
CVE-2026-70619
Odysseus Missing Admin Authorization via Embedding Endpoint Routes
41RISK
open
Referência
CVE-2021-44529
CVE-2021-44529CRITICALunder attackransomware
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execut
100RISK
open
Referência
CVE-2026-70620
Odysseus SSRF via Embedding Endpoint Configuration
33RISK
open
ReferênciaVexDay Proof
Affiliate Market 0.1 Beta - Cross-Site Scripting / SQL Injection
CVE-2008-1177webappsphp
SQL injection vulnerability in shop/detail.php in Affiliate Market (affmarket) 0.1 BETA allows remote attackers to execu
23RISK
open
ReferênciaVexDay Proof
Dovecot IMAP 1.0.10 < 1.1rc2 - Remote Email Disclosure
CVE-2008-1218remotemultiple
Argument injection vulnerability in Dovecot 1.0.x before 1.0.13, and 1.1.x before 1.1.rc3, when using blocking passdbs,
23RISK
open
Referência
CVE-2020-0618
CVE-2020-0618CRITICALunder attack
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page
100RISK
open
Referência
CVE-2020-0618
CVE-2020-0618CRITICALunder attack
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page
100RISK
open
Referência
CVE-2022-30333
CVE-2022-30333HIGHunder attackransomware
RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) o
100RISK
open
Referência
CVE-2020-7247
CVE-2020-7247CRITICALunder attack
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISK
open
Referência
CVE-2020-7247
CVE-2020-7247CRITICALunder attack
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISK
open
Referência
CVE-2020-7247
CVE-2020-7247CRITICALunder attack
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISK
open
Referência
CVE-2020-7247
CVE-2020-7247CRITICALunder attack
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISK
open
Referência
CVE-2020-7247
CVE-2020-7247CRITICALunder attack
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISK
open
ReferênciaVexDay Proof
phpBB Mod FileBase 2.0 - 'id' SQL Injection
CVE-2008-1305webappsphp
SQL injection vulnerability in filebase.php in the Filebase mod for phpBB allows remote attackers to execute arbitrary S
23RISK
open
Referência
CVE-2023-32560
An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disrup
78RISK
open
Referência
CVE-2023-32560
An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disrup
78RISK
open
ReferênciaVexDay Proof
Bloo 1.00 - Multiple SQL Injections
CVE-2008-1313webappsphp
Multiple SQL injection vulnerabilities in index.php in Bloo 1.00 and earlier allow remote attackers to execute arbitrary
23RISK
open
Referência
CVE-2020-7209
LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2.
60RISK
open
Referência
CVE-2020-7209
LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2.
60RISK
open
Referência
CVE-2026-61514
Puwell IP Camera 2.x - 4.x Unauthenticated Access via TCP Port 23456
48RISK
open
Referência
CVE-2026-61515
Puwell IP Camera 2.x - 4.x Unauthenticated Command Injection via DebugShell
48RISK
open
Referência
CVE-2026-16548
Bit Assist < 1.8.2 - Unauthenticated Arbitrary File Upload via Response Endpoint
33RISK
open
Referência
CVE-2026-16547
REST API Log < 1.7.1 - Unauthenticated Sensitive Log Data Disclosure via Download Endpoint
33RISK
open
Referência
CVE-2026-16546
Wired Impact Volunteer Management < 2.8.2 - Subscriber+ Arbitrary RSVP Removal via wivm_remove_rsvp
33RISK
open
previouspage 355 / 730next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.