Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,647cataloged exploits
34,986CVEs with public exploitation
24,695lab-tested
21,899 exploits
ReferênciaVexDay Proof
Webfwlog 0.92 - 'debug.php' Remote File Disclosure
CVE-2007-0585webappsphp
include/debug.php in Webfwlog 0.92 and earlier, when register_globals is enabled, allows remote attackers to obtain sour
23RISK
open
ReferênciaVexDay Proof
68 Classifieds 4.0 - 'category.php' SQL Injection
CVE-2008-2336webappsphp
SQL injection vulnerability in category.php in 68 Classifieds 4.0.1 allows remote attackers to execute arbitrary SQL com
23RISK
open
ReferênciaVexDay Proof
IMGallery 2.5 - Multiple SQL Injections
CVE-2008-2337webappsphp
Multiple SQL injection vulnerabilities in IMGallery 2.5, when magic_quotes_gpc is disabled, allow remote attackers to ex
23RISK
open
ReferênciaVexDay Proof
plusphp url shortening software 1.6 - Remote File Inclusion
CVE-2008-2480webappsphp
PHP remote file inclusion vulnerability in plus.php in plusPHP Short URL Multi-User Script 1.6 allows remote attackers t
23RISK
open
Referência
CVE-2012-4344
Cross-site scripting (XSS) vulnerability in Ipswitch WhatsUp Gold 15.02 allows remote attackers to inject arbitrary web
23RISK
open
ReferênciaVexDay Proof
Claroline E-Learning 1.75 - 'ldap.inc.php' Remote File Inclusion
CVE-2006-2284webappsphp
Multiple PHP remote file inclusion vulnerabilities in Claroline 1.7.5 allow remote attackers to execute arbitrary PHP co
23RISK
open
Referência
CVE-2012-2156
Multiple cross-site scripting (XSS) vulnerabilities in Plume CMS 1.2.4 and earlier allow remote attackers to inject arbi
23RISK
open
Referência
CVE-2025-2749
CVE-2025-2749HIGHunder attack
Kentico Xperience <= 13.0.178 Staging Media File Upload Authenticated RCE
71RISK
open
Referência
CVE-2021-31962
Kerberos AppContainer Security Feature Bypass Vulnerability
48RISK
open
ReferênciaVexDay Proof
newsmanager 2.0 - Remote File Inclusion / File Disclosure / SQL Injection
CVE-2008-2341webappsphp
PHP remote file inclusion vulnerability in ch_readalso.php in News Manager 2.0 allows remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
MeltingIce File System 1.0 - Arbitrary Add User
CVE-2008-2348webappsphp
MeltingIce File System 1.0 allows remote attackers to bypass application authentication, create new user accounts, and e
23RISK
open
ReferênciaVexDay Proof
CMS WebManager-Pro - Multiple SQL Injections
CVE-2008-2351webappsphp
Multiple SQL injection vulnerabilities in index.php in CMS WebManager-Pro allow remote attackers to execute arbitrary SQ
23RISK
open
ReferênciaVexDay Proof
How2ASP.net WebBoard 4.1 - SQL Injection
CVE-2008-2417webappsphp
SQL injection vulnerability in showQAnswer.asp in How2ASP.net Webboard 4.1 allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
Konqueror 3.5.9 - 'color'/'bgcolor' Multiple Remote Crash Vulnerabilities
CVE-2008-5712doslinux
The HTML parser in KDE Konqueror 3.5.9 allows remote attackers to cause a denial of service (application crash) via (1)
23RISK
open
Referência
CVE-2016-5425
The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distribu
38RISK
open
Referência
CVE-2016-5425
The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distribu
38RISK
open
Referência
CVE-2017-13849
An issue was discovered in certain Apple products. iOS before 11.1 is affected. tvOS before 11.1 is affected. watchOS be
23RISK
open
Referência
CVE-2011-0960
Multiple SQL injection vulnerabilities in Cisco Unified Operations Manager (CUOM) before 8.6 allow remote attackers to e
23RISK
open
Referência
CVE-2012-3485
Tunnelblick 3.3beta20 and earlier relies on argv[0] to determine the name of an appropriate (1) kernel module pathname o
38RISK
open
Referência
CVE-2019-0732
A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard when Wind
23RISK
open
Referência
CVE-2019-0732
A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard when Wind
23RISK
open
Referência
CVE-2024-5488
SEOPress < 7.9 - Unauthenticated Object Injection
63RISK
open
Referência
CVE-2008-6799
connection.php in FlashChat 5.0.8 allows remote attackers to bypass the role filter mechanism and gain administrative pr
23RISK
open
Referência
CVE-2012-6624
Cross-site scripting (XSS) vulnerability in the SoundCloud Is Gold plugin 2.1 for WordPress allows remote attackers to i
23RISK
open
ReferênciaVexDay Proof
Web Group Communication Center (WGCC) 1.0.3 - SQL Injection
CVE-2008-2446webappsphp
Multiple SQL injection vulnerabilities in Web Group Communication Center (WGCC) 1.0.3 PreRelease 1 and earlier allow rem
23RISK
open
Referência
CVE-2022-36664
Password Manager for IIS 2.0 has a cross-site scripting (XSS) vulnerability via the /isapi/PasswordManager.dll ResultURL
33RISK
open
Referência
Online Marriage Registration System 1.0 - 'searchdata' SQL Injection
CVE-2020-35151webappsphp
The Online Marriage Registration System 1.0 post parameter "searchdata" in the user/search.php request is vulnerable to
23RISK
open
Referência
CVE-2021-31152
Multilaser Router AC1200 V02.03.01.45_pt contains a cross-site request forgery (CSRF) vulnerability. An attacker can ena
23RISK
open
Referência
CVE-2012-0782
Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/setup-config.php in the installation component in WordPr
23RISK
open
Referência
CVE-2020-28091
cxuucms v3 has a SQL injection vulnerability, which can lead to the leakage of all database data via the keywords parame
23RISK
open
previouspage 359 / 730next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.