Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,647cataloged exploits
34,986CVEs with public exploitation
24,695lab-tested
21,899 exploits
Referência
CVE-2020-14871
CVE-2020-14871CRITICALunder attack
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported ve
100RISK
open
ReferênciaVexDay Proof
linksnet newsfeed 1.0 - Remote File Inclusion
CVE-2007-2707webappsphp
PHP remote file inclusion vulnerability in linksnet_linkslog_rss.php in Linksnet Newsfeed 1.0 allows remote attackers to
35RISK
open
Referência
CVE-2023-22952
CVE-2023-22952HIGHunder attack
In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because o
100RISK
open
Referência
CVE-2015-7387
ZOHO ManageEngine EventLog Analyzer 10.6 build 10060 and earlier allows remote attackers to bypass intended restrictions
60RISK
open
Referência
CVE-2015-7387
ZOHO ManageEngine EventLog Analyzer 10.6 build 10060 and earlier allows remote attackers to bypass intended restrictions
60RISK
open
Referência
CVE-2017-16666
Xplico before 1.2.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the name
60RISK
open
Referência
CVE-2017-16666
Xplico before 1.2.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the name
60RISK
open
Referência
CVE-2014-4872
BMC Track-It! 11.3.0.355 does not require authentication on TCP port 9010, which allows remote attackers to upload arbit
60RISK
open
Referência
CVE-2019-11600
A SQL injection vulnerability in the activities API in OpenProject before 8.3.2 allows a remote attacker to execute arbi
45RISK
open
Referência
CVE-2016-6563
D-Link DIR routers contain a stack-based buffer overflow in the HNAP Login action
60RISK
open
Referência
CVE-2018-18809
CVE-2018-18809CRITICALunder attack
TIBCO JasperReports Library Directory Traversal Vulnerability
100RISK
open
Referência
CVE-2015-3043
CVE-2015-3043HIGHunder attack
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457
100RISK
open
ReferênciaVexDay Proof
CA BrightStor Backup 11.5.2.0 - 'caloggderd.exe' Denial of Service
CVE-2007-2772doswindows
(1) caloggerd.exe (camt70.dll) and (2) mediasvr.exe (catirpc.dll and rwxdr.dll) in CA BrightStor Backup 11.5.2.0 SP2 all
28RISK
open
ReferênciaVexDay Proof
CA BrightStor Backup 11.5.2.0 - 'Mediasvr.exe' Denial of Service
CVE-2007-2772doswindows
(1) caloggerd.exe (camt70.dll) and (2) mediasvr.exe (catirpc.dll and rwxdr.dll) in CA BrightStor Backup 11.5.2.0 SP2 all
28RISK
open
Referência
CVE-2026-14603
WowOptin < 1.4.38 - Unauthenticated Opt-in Deactivation and Template Row Injection
41RISK
open
ReferênciaVexDay Proof
SAP MaxDB 7.6.03.07 - Remote Command Execution
CVE-2008-0244remotemultiple
SAP MaxDB 7.6.03 build 007 and earlier allows remote attackers to execute arbitrary commands via "&&" and other shell me
60RISK
open
ReferênciaVexDay Proof
Netgear SSL312 Router - Denial of Service
CVE-2009-0680doshardware
cgi-bin/welcome/VPN_only in the web interface in Netgear SSL312 allows remote attackers to cause a denial of service (de
23RISK
open
Referência
CVE-2019-1622
Cisco Data Center Network Manager Information Disclosure Vulnerability
70RISK
open
Referência
CVE-2019-1622
Cisco Data Center Network Manager Information Disclosure Vulnerability
70RISK
open
Referência
CVE-2017-17692
Samsung Internet Browser 5.4.02.3 allows remote attackers to bypass the Same Origin Policy and obtain sensitive informat
60RISK
open
Referência
CVE-2017-17692
Samsung Internet Browser 5.4.02.3 allows remote attackers to bypass the Same Origin Policy and obtain sensitive informat
60RISK
open
ReferênciaVexDay Proof
Alstrasoft Template Seller Pro 3.25 - Remote Code Execution
CVE-2007-2777webappsphp
Unrestricted file upload vulnerability in admin/addsptemplate.php in AlstraSoft Template Seller Pro 3.25 and earlier all
23RISK
open
Referência
CVE-2020-6418
CVE-2020-6418HIGHunder attack
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corru
100RISK
open
ReferênciaVexDay Proof
Libstats 1.0.3 - 'template_csv.php' Remote File Inclusion
CVE-2007-2779webappsphp
PHP remote file inclusion vulnerability in template_csv.php in Libstats 1.0.3 and earlier allows remote attackers to exe
23RISK
open
ReferênciaVexDay Proof
LeadTools Thumbnail Browser Control - 'lttmb14E.ocx' Remote Buffer Overflow
CVE-2007-2787remotewindows
Stack-based buffer overflow in the BrowseDir function in the (1) lttmb14E.ocx or (2) LTRTM14e.DLL ActiveX control in Lea
23RISK
open
ReferênciaVexDay Proof
Ol BookMarks Manager 0.7.4 - 'root' Remote File Inclusion
CVE-2007-2816webappsphp
Multiple PHP remote file inclusion vulnerabilities in ol'bookmarks 0.7.4 allow remote attackers to execute arbitrary PHP
28RISK
open
ReferênciaVexDay Proof
Ol BookMarks Manager 0.7.4 - SQL Injection
CVE-2007-2817webappsphp
SQL injection vulnerability in read/index.php in ol'bookmarks 0.7.4 allows remote attackers to execute arbitrary SQL com
23RISK
open
Referência
CVE-2007-2821
SQL injection vulnerability in wp-admin/admin-ajax.php in WordPress before 2.2 allows remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
TutorialCMS 1.01 - Authentication Bypass
CVE-2007-2822webappsphp
TutorialCMS 1.01 and earlier, when register_globals is enabled, allows remote attackers to bypass authentication via the
23RISK
open
ReferênciaVexDay Proof
LeadTools Raster Variant - 'LTRVR14e.dll' Remote File Overwrite
CVE-2007-2851remotewindows
A certain ActiveX control in LeadTools Raster Variant Object Library (LTRVR14e.dll) 14.5.0.44 allows remote attackers to
23RISK
open
previouspage 367 / 730next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.