Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,020cataloged exploits
35,276CVEs with public exploitation
24,695lab-tested
21,899 exploits
Referência
CVE-2016-0051
The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Window
43RISK
open
Referência
CVE-2016-0099
CVE-2016-0099HIGHunder attackransomware
The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8
98RISK
open
Referência
CVE-2016-0099
CVE-2016-0099HIGHunder attackransomware
The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8
98RISK
open
Referência
CVE-2010-0610
Multiple SQL injection vulnerabilities in the Photoblog (com_photoblog) component for Joomla! allow remote attackers to
23RISK
open
Referência
CVE-2010-0610
Multiple SQL injection vulnerabilities in the Photoblog (com_photoblog) component for Joomla! allow remote attackers to
23RISK
open
Referência
CVE-2016-0168
GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012
35RISK
open
Referência
CVE-2016-0189
CVE-2016-0189HIGHunder attack
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other
100RISK
open
Referência
CVE-2016-0491
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12
60RISK
open
Referência
CVE-2010-0611
Multiple SQL injection vulnerabilities in adminlogin.php in Baal Systems 3.8 and earlier allow remote attackers to execu
23RISK
open
Referência
CVE-2010-0611
Multiple SQL injection vulnerabilities in adminlogin.php in Baal Systems 3.8 and earlier allow remote attackers to execu
23RISK
open
Referência
CVE-2016-0492
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12
60RISK
open
Referência
CVE-2016-0709
Directory traversal vulnerability in the Import/Export function in the Portal Site Manager in Apache Jetspeed before 2.3
60RISK
open
Referência
CVE-2016-0710
Multiple SQL injection vulnerabilities in the User Manager service in Apache Jetspeed before 2.3.1 allow remote attacker
50RISK
open
Referência
CVE-2016-0752
CVE-2016-0752HIGHunder attack
Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.
100RISK
open
Referência
CVE-2016-0793
Incomplete blacklist vulnerability in the servlet filter restriction mechanism in WildFly (formerly JBoss Application Se
28RISK
open
Referência
CVE-2010-0632
SQL injection vulnerability in the Parkview Consultants SimpleFAQ (com_simplefaq) component for Joomla! allows remote at
23RISK
open
Referência
CVE-2010-0642
Cisco Collaboration Server (CCS) 5 allows remote attackers to read the source code of JHTML files via URL encoded charac
23RISK
open
ReferênciaVexDay Proof
ImageAlbum 2.0.0b2 - 'id' SQL Injection
CVE-2008-0288webappsphp
Multiple SQL injection vulnerabilities in ImageAlbum 2.0.0b2 allow remote attackers to execute arbitrary SQL commands vi
23RISK
open
ReferênciaVexDay Proof
flinx 1.3 - 'id' SQL Injection
CVE-2008-0468webappsphp
SQL injection vulnerability in category.php in Flinx 1.3 and earlier allows remote attackers to execute arbitrary SQL co
23RISK
open
ReferênciaVexDay Proof
Persits XUpload 3.0 - 'AddFile()' Remote Buffer Overflow
CVE-2008-0492remotewindows
Stack-based buffer overflow in the Persits.XUpload.2 ActiveX control in XUpload.ocx 3.0.0.4 and earlier in Persits XUplo
43RISK
open
ReferênciaVexDay Proof
Bigware Shop 2.0 - 'pollid' SQL Injection
CVE-2008-0498webappsphp
SQL injection vulnerability in main_bigware_53.tpl.php in Bigware Shop 2.0 allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
phpMyClub 0.0.1 - 'page_courante' Local File Inclusion
CVE-2008-0501webappsphp
Directory traversal vulnerability in phpMyClub 0.0.1 allows remote attackers to include and execute arbitrary local file
23RISK
open
ReferênciaVexDay Proof
Mambo Component EstateAgent 0.1 - SQL Injection
CVE-2008-0517webappsphp
SQL injection vulnerability in index.php in the Darko Selesi EstateAgent (com_estateagent) 0.1 component for Mambo 4.5.x
23RISK
open
ReferênciaVexDay Proof
Mambo Component Recipes 1.00 - 'id' SQL Injection
CVE-2008-0518webappsphp
SQL injection vulnerability in index.php in the Recipes (com_recipes) 1.00 component for Mambo and Joomla! allows remote
23RISK
open
ReferênciaVexDay Proof
Mambo Component jokes 1.0 - 'cat' SQL Injection
CVE-2008-0519webappsphp
SQL injection vulnerability in index.php in the Atapin Jokes (com_jokes) 1.0 component for Mambo and Joomla! allows remo
23RISK
open
ReferênciaVexDay Proof
Simple Forum 3.2 - File Disclosure / Cross-Site Scripting
CVE-2008-0541webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in forum.php in Gerd Tentler Simple Forum 3.2 allow remote attackers
23RISK
open
ReferênciaVexDay Proof
PHP Links 1.3 - 'id' SQL Injection
CVE-2008-0565webappsphp
SQL injection vulnerability in vote.php in DeltaScripts PHP Links 1.3 and earlier allows remote attackers to execute arb
23RISK
open
ReferênciaVexDay Proof
Joomla! Component ChronoForms 2.3.5 - Remote File Inclusion
CVE-2008-0567webappsphp
Multiple PHP remote file inclusion vulnerabilities in ChronoEngine ChronoForms (com_chronocontact) 2.3.5 component for J
35RISK
open
ReferênciaVexDay Proof
Mindmeld 1.2.0.10 - Multiple Remote File Inclusions
CVE-2008-0572webappsphp
Multiple PHP remote file inclusion vulnerabilities in Mindmeld 1.2.0.10 allow remote attackers to execute arbitrary PHP
28RISK
open
ReferênciaVexDay Proof
SafeNet 10.4.0.12 - 'IPSecDrv.sys' Local kernel Ring0 SYSTEM
CVE-2008-0573localwindows
IPSecDrv.sys 10.4.0.12 in SafeNET HighAssurance Remote and SoftRemote allows local users to gain privileges via a crafte
23RISK
open
previouspage 373 / 730next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.