Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,888cataloged exploits
35,200CVEs with public exploitation
24,695lab-tested
21,899 exploits
ReferênciaVexDay Proof
OpenDock Easy Gallery 1.4 - 'doc_directory' File Inclusion
CVE-2006-5241webappsphp
Multiple PHP remote file inclusion vulnerabilities in OpenDock Easy Gallery 1.4 and earlier, when register_globals is en
23RISK
open
Referência
CVE-2020-28091
cxuucms v3 has a SQL injection vulnerability, which can lead to the leakage of all database data via the keywords parame
23RISK
open
ReferênciaVexDay Proof
MolyX BOARD 2.5.0 - 'index.php?lang' Local File Inclusion
CVE-2007-2778webappsphp
Multiple directory traversal vulnerabilities in MolyX BOARD 2.5.0 allow remote attackers to read arbitrary files via a .
23RISK
open
ReferênciaVexDay Proof
EnjoySAP ActiveX kweditcontrol.kwedit.1 - Remote Stack Overflow (PoC)
CVE-2007-3607doswindows
Multiple unspecified vulnerabilities in ActiveX controls in the EnjoySAP SAP GUI allow remote attackers to cause a denia
23RISK
open
Referência
CVE-2007-6752
Cross-site request forgery (CSRF) vulnerability in Drupal 7.12 and earlier allows remote attackers to hijack the authent
23RISK
open
Referência
CVE-2007-6752
Cross-site request forgery (CSRF) vulnerability in Drupal 7.12 and earlier allows remote attackers to hijack the authent
23RISK
open
Referência
CVE-2012-2579
Multiple cross-site scripting (XSS) vulnerabilities in the WP SimpleMail plugin 1.0.6 for WordPress allow remote attacke
23RISK
open
Referência
CVE-2012-5346
Cross-site scripting (XSS) vulnerability in wp-live.php in the WP Live.php module 1.2.1 for WordPress allows remote atta
23RISK
open
Referência
CVE-2012-5229
Cross-site scripting (XSS) vulnerability in css/gallery-css.php in the Slideshow Gallery2 plugin for WordPress allows re
23RISK
open
ReferênciaVexDay Proof
OSSIM 0.9.9rc5 - Cross-Site Scripting / SQL Injection
CVE-2008-0919webappsphp
Cross-site scripting (XSS) vulnerability in session/login.php in Open Source Security Information Management (OSSIM) 0.9
23RISK
open
Referência
CVE-2017-9429
SQL injection vulnerability in the Event List plugin 0.7.8 for WordPress allows an authenticated user to execute arbitra
23RISK
open
Referência
CVE-2015-4064
SQL injection vulnerability in modules/module.ab-testing.php in the Landing Pages plugin before 1.8.5 for WordPress allo
23RISK
open
Referência
CVE-2015-4018
SQL injection vulnerability in feedwordpresssyndicationpage.class.php in the FeedWordPress plugin before 2015.0514 for W
23RISK
open
Referência
CVE-2015-4018
SQL injection vulnerability in feedwordpresssyndicationpage.class.php in the FeedWordPress plugin before 2015.0514 for W
23RISK
open
ReferênciaVexDay Proof
e107 Plugin BLOG Engine 2.2 - 'rid' Blind SQL Injection
CVE-2008-2455webappsphp
SQL injection vulnerability in comment.php in the MacGuru BLOG Engine plugin 2.2 for e107 allows remote attackers to exe
23RISK
open
Referência
CVE-2017-11494
SQL injection vulnerability in SOL.Connect ISET-mpp meter 1.2.4.2 and earlier allows remote attackers to execute arbitra
23RISK
open
ReferênciaVexDay Proof
ComicShout 2.5 - 'comic_id' SQL Injection
CVE-2008-2456webappsphp
SQL injection vulnerability in index.php in ComicShout 2.5 and earlier allows remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
DB Top Sites 1.0 - Remote Command Execution
CVE-2009-2111webappsphp
Static code injection vulnerability in add_reg.php in DB Top Sites 1.0 allows remote attackers to inject arbitrary PHP c
23RISK
open
Referência
CVE-2010-5060
SQL injection vulnerability in Nus.php in NUs Newssystem 1.02 allows remote attackers to execute arbitrary SQL commands
23RISK
open
Referência
CVE-2010-5060
SQL injection vulnerability in Nus.php in NUs Newssystem 1.02 allows remote attackers to execute arbitrary SQL commands
23RISK
open
Referência
CVE-2010-5193
Stack-based buffer overflow in the TIFMergeMultiFiles function in the SCRIBBLE.ScribbleCtrl.1 ActiveX control (ImageView
50RISK
open
Referência
CVE-2018-14888
inc/plugins/thankyoulike.php in the Eldenroot Thank You/Like plugin before 3.1.0 for MyBB allows XSS via a post or threa
23RISK
open
Referência
CVE-2018-14888
inc/plugins/thankyoulike.php in the Eldenroot Thank You/Like plugin before 3.1.0 for MyBB allows XSS via a post or threa
23RISK
open
Referência
CVE-2013-1604
Directory traversal vulnerability in MayGion IP Cameras with firmware before 2013.04.22 (05.53) allows remote attackers
23RISK
open
Referência
CVE-2018-5405
The Quest Kace K1000 Appliance is vulnerable to JavaScript injection.
23RISK
open
Referência
CVE-2026-66752
tiny-http 0.12.0 HTTP Request Smuggling via Transfer-Encoding Handling
33RISK
open
Referência
CVE-2023-3848
mooSocial mooDating URL view cross site scripting
43RISK
open
Referência
CVE-2017-8708
The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
23RISK
open
ReferênciaVexDay Proof
@lex Guestbook 4.0.2 - Remote Command Execution
CVE-2007-0202webappsphp
SQL injection vulnerability in index.php in @lex Guestbook 4.0.2 and earlier, when magic_quotes_gpc is disabled, allows
23RISK
open
Referência
CVE-2019-16173
LimeSurvey before v3.17.14 allows reflected XSS for escalating privileges from a low-privileged account to, for example,
23RISK
open
previouspage 370 / 730next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.