Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,647cataloged exploits
34,986CVEs with public exploitation
24,695lab-tested
21,899 exploits
Referência
Sophos XG115w Firewall 17.0.10 MR-10 - Authentication Bypass
CVE-2022-1040CRITICALunder attackwebappshardware
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sopho
100RISK
open
Referência
CVE-2022-47966
CVE-2022-47966CRITICALunder attackransomware
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RISK
open
Referência
CVE-2022-47966
CVE-2022-47966CRITICALunder attackransomware
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RISK
open
Referência
CVE-2022-47966
CVE-2022-47966CRITICALunder attackransomware
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RISK
open
ReferênciaVexDay Proof
audioCMS arash 0.1.4 - 'arashlib_dir' Remote File Inclusion
CVE-2007-2301webappsphp
Multiple PHP remote file inclusion vulnerabilities in audioCMS arash 0.1.4 allow remote attackers to execute arbitrary P
23RISK
open
ReferênciaVexDay Proof
NMDeluxe 1.0.1 - 'footer.php?template' Local File Inclusion
CVE-2007-2303webappsphp
Directory traversal vulnerability in includes/footer.php in News Manager Deluxe (NMDeluxe) 1.0.1 allows remote attackers
23RISK
open
ReferênciaVexDay Proof
Quick and Dirty Blog (qdblog) 0.4 - SQL Injection / Local File Inclusion
CVE-2007-2304webappsphp
Multiple directory traversal vulnerabilities in Quick and Dirty Blog (QDBlog) 0.4, and possibly earlier, allow remote at
23RISK
open
ReferênciaVexDay Proof
JulmaCMS 1.4 - 'file.php' Remote File Disclosure
CVE-2007-2324webappsphp
Directory traversal vulnerability in file.php in JulmaCMS 1.4 allows remote attackers to read arbitrary files via a .. (
23RISK
open
ReferênciaVexDay Proof
CreaDirectory 1.2 - 'error.asp?id' SQL Injection
CVE-2007-2342webappsasp
SQL injection vulnerability in error.asp in CreaScripts CreaDirectory 1.2 allows remote attackers to execute arbitrary S
23RISK
open
ReferênciaVexDay Proof
burnCMS 0.2 - 'root' Remote File Inclusion
CVE-2007-2364webappsphp
Multiple PHP remote file inclusion vulnerabilities in burnCMS 0.2 and earlier allow remote attackers to execute arbitrar
23RISK
open
Referência
CVE-2025-32432
CVE-2025-32432CRITICALunder attack
Craft CMS Allows Remote Code Execution
100RISK
open
ReferênciaVexDay Proof
Photoshop CS2/CS3 / Paint Shop Pro 11.20 - '.png' Local Buffer Overflow
CVE-2007-2365localwindows
Buffer overflow in Adobe Photoshop CS2 and CS3, Photoshop Elements 5.0, Illustrator CS3, and GoLive 9 allows user-assist
35RISK
open
ReferênciaVexDay Proof
Photoshop CS2/CS3 / Paint Shop Pro 11.20 - '.png' Local Buffer Overflow
CVE-2007-2366localwindows
Buffer overflow in Corel Paint Shop Pro 11.20 allows user-assisted remote attackers to execute arbitrary code via a craf
35RISK
open
ReferênciaVexDay Proof
WebSPELL 4.01.02 - 'picture.php' File Disclosure
CVE-2007-2368webappsphp
picture.php in WebSPELL 4.01.02 and earlier allows remote attackers to read arbitrary files via the file parameter.
23RISK
open
Referência
CVE-2009-4988
Stack-based buffer overflow in NT_Naming_Service.exe in SAP Business One 2005 A 6.80.123 and 6.80.320 allows remote atta
50RISK
open
ReferênciaVexDay Proof
phpMyNewsletter 0.8 (beta5) - Multiple Vulnerabilities
CVE-2007-2371webappsphp
admin/index.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier provides access to configuration modification
23RISK
open
ReferênciaVexDay Proof
phpMyNewsletter 0.8 (beta5) - Multiple Vulnerabilities
CVE-2007-2372webappsphp
admin/send_mod.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier prints a Location header but does not exit
23RISK
open
ReferênciaVexDay Proof
XOOPS Module WF-Links 1.03 - 'cid' SQL Injection
CVE-2007-2373webappsphp
SQL injection vulnerability in viewcat.php in the WF-Links (wflinks) 1.03 and earlier module for XOOPS allows remote att
23RISK
open
Referência
CVE-2016-10033
CVE-2016-10033CRITICALunder attack
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISK
open
Referência
CVE-2021-47981
Quick.CMS 6.7 Cross-Site Scripting via CSRF to Sliders Form
33RISK
open
Referência
CVE-2020-13927
CVE-2020-13927CRITICALunder attack
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but th
100RISK
open
Referência
CVE-2020-13927
CVE-2020-13927CRITICALunder attack
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but th
100RISK
open
Referência
CVE-2026-1184
Deserialization of Untrusted Data in GitLab
33RISK
open
Referência
CVE-2026-1322
Business Logic Errors in GitLab
33RISK
open
Referência
CVE-2026-1338
Authorization Bypass Through User-Controlled Key in GitLab
33RISK
open
Referência
CVE-2026-3074
Authorization Bypass Through User-Controlled Key in GitLab
33RISK
open
Referência
CVE-2026-3160
Unintended Proxy or Intermediary ('Confused Deputy') in GitLab
33RISK
open
Referência
CVE-2026-3607
Access Control Check Implemented After Asset is Accessed in GitLab
33RISK
open
Referência
CVE-2026-4524
Authentication Bypass Using an Alternate Path or Channel in GitLab
33RISK
open
Referência
CVE-2026-4527
Cross-Site Request Forgery (CSRF) in GitLab
33RISK
open
previouspage 364 / 730next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.