Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,020cataloged exploits
35,276CVEs with public exploitation
24,695lab-tested
21,899 exploits
Referência
CVE-2017-9429
SQL injection vulnerability in the Event List plugin 0.7.8 for WordPress allows an authenticated user to execute arbitra
23RISK
open
Referência
CVE-2015-4064
SQL injection vulnerability in modules/module.ab-testing.php in the Landing Pages plugin before 1.8.5 for WordPress allo
23RISK
open
Referência
CVE-2015-4018
SQL injection vulnerability in feedwordpresssyndicationpage.class.php in the FeedWordPress plugin before 2015.0514 for W
23RISK
open
Referência
CVE-2015-4018
SQL injection vulnerability in feedwordpresssyndicationpage.class.php in the FeedWordPress plugin before 2015.0514 for W
23RISK
open
ReferênciaVexDay Proof
e107 Plugin BLOG Engine 2.2 - 'rid' Blind SQL Injection
CVE-2008-2455webappsphp
SQL injection vulnerability in comment.php in the MacGuru BLOG Engine plugin 2.2 for e107 allows remote attackers to exe
23RISK
open
Referência
CVE-2017-11494
SQL injection vulnerability in SOL.Connect ISET-mpp meter 1.2.4.2 and earlier allows remote attackers to execute arbitra
23RISK
open
ReferênciaVexDay Proof
ComicShout 2.5 - 'comic_id' SQL Injection
CVE-2008-2456webappsphp
SQL injection vulnerability in index.php in ComicShout 2.5 and earlier allows remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
DB Top Sites 1.0 - Remote Command Execution
CVE-2009-2111webappsphp
Static code injection vulnerability in add_reg.php in DB Top Sites 1.0 allows remote attackers to inject arbitrary PHP c
23RISK
open
Referência
CVE-2010-5060
SQL injection vulnerability in Nus.php in NUs Newssystem 1.02 allows remote attackers to execute arbitrary SQL commands
23RISK
open
Referência
CVE-2010-5060
SQL injection vulnerability in Nus.php in NUs Newssystem 1.02 allows remote attackers to execute arbitrary SQL commands
23RISK
open
Referência
CVE-2010-5193
Stack-based buffer overflow in the TIFMergeMultiFiles function in the SCRIBBLE.ScribbleCtrl.1 ActiveX control (ImageView
50RISK
open
Referência
CVE-2023-3049
File Upload in TMT's Lockcell
48RISK
open
Referência
CVE-2015-4631
Multiple cross-site scripting (XSS) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before
23RISK
open
Referência
CVE-2015-4631
Multiple cross-site scripting (XSS) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before
23RISK
open
Referência
CVE-2021-44916
Opmantek Open-AudIT Community 4.2.0 (Fixed in 4.3.0) is affected by a Cross Site Scripting (XSS) vulnerability. If a bad
23RISK
open
Referência
CVE-2009-4147
The _rtld function in the Run-Time Link-Editor (rtld) in libexec/rtld-elf/rtld.c in FreeBSD 7.1 and 8.0 does not clear t
38RISK
open
Referência
CVE-2016-3643
CVE-2016-3643HIGHunder attack
SolarWinds Virtualization Manager 6.3.1 and earlier allow local users to gain privileges by leveraging a misconfiguratio
71RISK
open
Referência
CVE-2016-3643
CVE-2016-3643HIGHunder attack
SolarWinds Virtualization Manager 6.3.1 and earlier allow local users to gain privileges by leveraging a misconfiguratio
71RISK
open
ReferênciaVexDay Proof
TCExam 4.0.011 - 'SessionUserLang' Shell Injection
CVE-2007-2430webappsphp
shared/code/tce_tmx.php in TCExam 4.0.011 and earlier allows remote attackers to create arbitrary PHP files in cache/ by
23RISK
open
Referência
CVE-2017-6896
Privilege escalation vulnerability on the DIGISOL DG-HR1400 1.00.02 wireless router enables an attacker to escalate from
23RISK
open
Referência
CVE-2017-6896
Privilege escalation vulnerability on the DIGISOL DG-HR1400 1.00.02 wireless router enables an attacker to escalate from
23RISK
open
ReferênciaVexDay Proof
2WIRE Modems/Routers - 'CRLF' Denial of Service
CVE-2006-4523doshardware
The web-based management interface in 2Wire, Inc. HomePortal and OfficePortal Series modems and routers allows remote at
23RISK
open
Referência
CVE-2018-20418
index.php?p=admin/actions/entries/save-entry in Craft CMS 3.0.25 allows XSS by saving a new title from the console tab.
23RISK
open
Referência
CVE-2018-11091
An issue was discovered in MyBiz MyProcureNet 5.0.0. A malicious file can be uploaded to the webserver by an attacker. I
48RISK
open
ReferênciaVexDay Proof
eIQnetworks ESA SEARCHREPORT - Remote Overflow (Metasploit)
CVE-2007-5699remotewindows
Stack-based buffer overflow in eIQNetworks Enterprise Security Analyzer (ESA) 2.5 allows remote attackers to execute arb
23RISK
open
Referência
CVE-2014-9558
Multiple SQL injection vulnerabilities in SmartCMS v.2.
23RISK
open
Referência
CVE-2015-7346
SQL injection vulnerability in ZCMS 1.1.
23RISK
open
Referência
CVE-2015-7346
SQL injection vulnerability in ZCMS 1.1.
23RISK
open
Referência
CVE-2014-9179
Cross-site scripting (XSS) vulnerability in the SupportEzzy Ticket System plugin 1.2.5 for WordPress allows remote authe
23RISK
open
Referência
CVE-2008-7010
Skalfa Software SkaLinks Exchange Script 1.5 allows remote attackers to add new administrators and gain privileges via a
23RISK
open
previouspage 377 / 730next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.