Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,649cataloged exploits
34,987CVEs with public exploitation
24,695lab-tested
21,899 exploits
Referência
CVE-2010-0673
SQL injection vulnerability in cplphoto.php in the Copperleaf Photolog plugin 0.16, and possibly earlier, for WordPress
23RISK
open
Referência
CVE-2010-0673
SQL injection vulnerability in cplphoto.php in the Copperleaf Photolog plugin 0.16, and possibly earlier, for WordPress
23RISK
open
Referência
CVE-2021-30147
DMA Softlab Radius Manager 4.4.0 allows CSRF with impacts such as adding new manager accounts via admin.php.
23RISK
open
Referência
CVE-2026-16765
CodeAstro Online Classroom loginlinkadmin.php sql injection
33RISK
open
Referência
CVE-2012-1669
Directory traversal vulnerability in index.php in phpMoneyBooks before 1.0.3 allows remote attackers to include and exec
23RISK
open
Referência
CVE-2012-1669
Directory traversal vulnerability in index.php in phpMoneyBooks before 1.0.3 allows remote attackers to include and exec
23RISK
open
ReferênciaVexDay Proof
ISPworker 1.21 - 'download.php' Remote File Disclosure
CVE-2007-5813webappsphp
Multiple directory traversal vulnerabilities in download.php in ISPworker 1.21 allow remote attackers to read arbitrary
23RISK
open
Referência
CVE-2017-14838
TeamWork Job Links allows Arbitrary File Upload in profileChange and coverChange.
23RISK
open
Referência
CVE-2017-14839
TeamWork Photo Fusion allows Arbitrary File Upload in changeAvatar and changeCover.
23RISK
open
ReferênciaVexDay Proof
FlashBlog - 'articulo_id' SQL Injection
CVE-2008-2572webappsphp
SQL injection vulnerability in php/leer_comentarios.php in FlashBlog allows remote attackers to execute arbitrary SQL co
23RISK
open
ReferênciaVexDay Proof
freeSSHd 1.2.1 - (Authenticated) Remote Overflow (SEH)
CVE-2008-2573remotewindows
Stack-based buffer overflow in SFTP in freeSSHd 1.2.1 allows remote authenticated users to execute arbitrary code via a
23RISK
open
Referência
CVE-2025-34029
Edimax EW-7438RPn Mini OS Command Injection via syscmd.asp
48RISK
open
Referência
CVE-2009-2925
Directory traversal vulnerability in DJcalendar.cgi in DJCalendar allows remote attackers to read arbitrary files via a
23RISK
open
Referência
CVE-2014-3878
Multiple cross-site scripting (XSS) vulnerabilities in the web client interface in Ipswitch IMail Server 12.3 and 12.4,
23RISK
open
ReferênciaVexDay Proof
Company WebSite Builder PRO 1.9.8 - 'INCLUDE_PATH' Remote File Inclusion
CVE-2007-1513webappsphp
PHP remote file inclusion vulnerability in comanda.php in GraFX Company WebSite Builder (CWB) PRO 1.9.8, when register_g
23RISK
open
Referência
CVE-2009-3173
Unrestricted file upload vulnerability in admin/add_album.php in The Rat CMS Alpha 2 allows remote attackers to execute
23RISK
open
Referência
CVE-2018-19933
Bolt CMS <3.6.2 allows XSS via text input click preview button as demonstrated by the Title field of a Configured and Ne
23RISK
open
Referência
CVE-2018-6230
A SQL injection vulnerability in an Trend Micro Email Encryption Gateway 5.5 search configuration script could allow an
23RISK
open
Referência
CVE-2015-2524
Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 do not proper
23RISK
open
ReferênciaVexDay Proof
CJG EXPLORER PRO 3.2 - 'g_pcltar_lib_dir' Remote File Inclusion
CVE-2007-2660webappsphp
PHP remote file inclusion vulnerability in pcltrace.lib.php in the PclTar module in Vincent Blavet PhpConcept Library, a
23RISK
open
ReferênciaVexDay Proof
Minerva 2.0.21 build 238a - 'phpbb_root_path' File Inclusion
CVE-2006-5077webappsphp
PHP remote file inclusion vulnerability in admin/admin_topic_action_logging.php in Chris Smith Minerva Build 238 and ear
23RISK
open
ReferênciaVexDay Proof
Megabbs Forum 2.2 - SQL Injection / Cross-Site Scripting
CVE-2008-2022webappsasp
Mulatiple cross-site scripting (XSS) vulnerabilities in PD9 Software MegaBBS 2.2 allow remote attackers to inject arbitr
23RISK
open
Referência
CVE-2013-7209
Cross-site request forgery (CSRF) vulnerability in admBase/login.page in the Admin module in JForum allows remote attack
23RISK
open
Referência
CVE-2009-3807
Stack-based buffer overflow in MixVibes 7.043 Pro allows remote attackers to cause a denial of service (crash) via a lon
23RISK
open
ReferênciaVexDay Proof
Joomla! Component JooBB 0.5.9 - Blind SQL Injection
CVE-2008-2651webappsphp
SQL injection vulnerability in the Joomla! Bulletin Board (aka Joo!BB or com_joobb) component 0.5.9 for Joomla! allows r
23RISK
open
Referência
CVE-2020-15255
CSV injection in Anuko Time Tracker
41RISK
open
Referência
CVE-2006-5863
PHP remote file inclusion vulnerability in inc/session.php for LetterIt 2 allows remote attackers to execute arbitrary P
23RISK
open
Referência
minewebcms 1.15.2 - Cross-site Scripting (XSS)
CVE-2022-1163MEDIUMwebappsphp
Cross-site Scripting (XSS) - Stored in mineweb/minewebcms
33RISK
open
Referência
CVE-2009-3038
A certain ActiveX control in lnresobject.dll 7.1.1.119 in the Research In Motion (RIM) Lotus Notes connector for BlackBe
23RISK
open
Referência
CVE-2010-1364
SQL injection vulnerability in index.php in Uiga Personal Portal, as downloaded on 20100301, allows remote attackers to
23RISK
open
previouspage 369 / 730next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.