Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,647cataloged exploits
34,986CVEs with public exploitation
24,695lab-tested
21,899 exploits
Referência
CVE-2018-13032
ECESSA ShieldLink SL175EHQ 10.7.4 devices have CSRF to add superuser accounts via the cgi-bin/pl_web.cgi/util_configlogi
23RISK
open
Referência
CVE-2017-0358
ntfs-3g: Modprobe influence vulnerability via environment variables
56RISK
open
Referência
CVE-2017-0358
ntfs-3g: Modprobe influence vulnerability via environment variables
56RISK
open
Referência
CVE-2017-14841
Mojoomla Annual Maintenance Contract (AMC) Management System allows Arbitrary File Upload in profilesetting image handli
23RISK
open
ReferênciaVexDay Proof
LearnLoop 2.0beta7 - 'sFilePath' Remote File Disclosure
CVE-2007-6214webappsphp
Directory traversal vulnerability in include/file_download.php in LearnLoop 2.0 beta7 allows remote attackers to read ar
23RISK
open
Referência
CVE-2026-2686
SECCN Dingcheng G10 session_login.cgi qq os command injection
48RISK
open
Referência
CVE-2022-29727
Survey Sparrow Enterprise Survey Software 2022 has a Stored cross-site scripting (XSS) vulnerability in the Signup param
23RISK
open
Referência
CVE-2012-5099
Cross-site scripting (XSS) vulnerability in list.php in PHPB2B 4.1 and earlier allows remote attackers to inject arbitra
23RISK
open
ReferênciaVexDay Proof
PHPortal 1.2 - Multiple Remote File Inclusions
CVE-2008-3022webappsphp
Multiple PHP remote file inclusion vulnerabilities in sablonlar/gunaysoft/gunaysoft.php in PHPortal 1.2 Beta allow remot
23RISK
open
ReferênciaVexDay Proof
Pritlog 0.4 - 'Filename' Remote File Disclosure
CVE-2008-6012webappsphp
Directory traversal vulnerability in index.php in Pritlog 0.4 and earlier, when magic_quotes_gpc is disabled, allows rem
23RISK
open
Referência
Veeam ONE Reporter 9.5.0.3201 - Multiple Cross-Site Request Forgery
CVE-2019-11569webappsashx
Veeam ONE Reporter 9.5.0.3201 allows CSRF.
23RISK
open
Referência
PilusCart 1.4.1 - Cross-Site Request Forgery (Add Admin)
CVE-2019-9769webappsphp
PilusCart 1.4.1 is vulnerable to index.php?module=users&action=newUser CSRF, leading to the addition of a new user as ad
23RISK
open
Referência
CVE-2017-16356
Reflected XSS in Kubik-Rubik SIGE (aka Simple Image Gallery Extended) before 3.3.0 allows attackers to execute JavaScrip
23RISK
open
Referência
CVE-2017-16356
Reflected XSS in Kubik-Rubik SIGE (aka Simple Image Gallery Extended) before 3.3.0 allows attackers to execute JavaScrip
23RISK
open
Referência
CVE-2018-9238
proberv.php in Yahei-PHP Proberv 0.4.7 has XSS via the funName parameter.
23RISK
open
Referência
CVE-2018-8738
Airties 5444 1.0.0.18 and 5444TT 1.0.0.18 devices allow XSS.
23RISK
open
Referência
CVE-2010-1948
Directory traversal vulnerability in scr/soustab.php in openMairie Openfoncier 2.00, when register_globals is enabled, a
23RISK
open
Referência
CVE-2018-13849
edit_requests.php in yTakkar Instagram-clone through 2018-04-23 has XSS via an onmouseover payload because of an inadequ
23RISK
open
Referência
CVE-2018-17832
XSS exists in WUZHI CMS 2.0 via the index.php v or f parameter.
23RISK
open
Referência
CVE-2018-9857
PHP Scripts Mall Match Clone Script 1.0.4 has XSS via the search field to searchbyid.php (aka the "View Search By Id" sc
23RISK
open
Referência
CVE-2018-19828
Artica Integria IMS 5.0.83 has XSS via the search_string parameter.
23RISK
open
ReferênciaVexDay Proof
MonGoose 2.4 (Windows) - WebServer Directory Traversal
CVE-2009-1354remotewindows
Directory traversal vulnerability in Mongoose 2.4 allows remote attackers to read arbitrary files via a .. (dot dot) in
23RISK
open
Referência
CVE-2009-4671
Login.php in RoomPHPlanning 1.6 allows remote attackers to bypass authentication and obtain administrative access by set
23RISK
open
ReferênciaVexDay Proof
Quick.CMS.Lite 0.3 - Cookie sLanguage Local File Inclusion
CVE-2006-5834webappsphp
Directory traversal vulnerability in general.php in OpenSolution Quick.Cms.Lite 0.3 allows remote attackers to include a
23RISK
open
Referência
CVE-2009-3966
Arcade Trade Script 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the a
23RISK
open
ReferênciaVexDay Proof
phpBurningPortal 1.0.1 - 'lang_path' Remote File Inclusion
CVE-2006-7102webappsphp
Multiple PHP remote file inclusion vulnerabilities in phpBurningPortal quiz-modul 1.0.1, and possibly earlier, allow rem
23RISK
open
Referência
CVE-2016-8812
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA GeForce Experience R340 before GFE 2.11.4.125 and R375 before G
23RISK
open
Referência
CVE-2014-1459
SQL injection vulnerability in dg-admin/index.php in doorGets CMS 5.2 and earlier allows remote authenticated administra
23RISK
open
Referência
CVE-2014-1459
SQL injection vulnerability in dg-admin/index.php in doorGets CMS 5.2 and earlier allows remote authenticated administra
23RISK
open
Referência
CVE-2010-1948
Directory traversal vulnerability in scr/soustab.php in openMairie Openfoncier 2.00, when register_globals is enabled, a
23RISK
open
previouspage 361 / 730next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.