Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,025cataloged exploits
35,280CVEs with public exploitation
24,695lab-tested
22,166 exploits
ReferênciaVexDay Proof
PHP Coupon Script 3.0 - 'bus' SQL Injection
CVE-2007-2672webappsphp
SQL injection vulnerability in index.php in PHP Coupon Script 3.0 allows remote attackers to execute arbitrary SQL comma
23RISK
open
ReferênciaVexDay Proof
Newswriter SW 1.4.2 - 'main.inc.php' Remote File Inclusion
CVE-2006-5180webappsphp
PHP remote file inclusion vulnerability in include/main.inc.php in Sebastian Baumann and Philipp Wolfer Newswriter SW 1.
23RISK
open
Referência
CVE-2012-2586
Multiple cross-site scripting (XSS) vulnerabilities in Mailtraq 2.17.3.3150 allow remote attackers to inject arbitrary w
23RISK
open
Referência
CVE-2021-32403
Intelbras Router RF 301K Firmware 1.1.2 is vulnerable to Cross Site Request Forgery (CSRF) due to lack of security mecha
23RISK
open
ReferênciaVexDay Proof
xml2owl 0.1.1 - 'showcode.php' Remote Command Execution
CVE-2007-6632webappsphp
showCode.php in xml2owl 0.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the path
23RISK
open
Referência
CVE-2012-2578
Multiple cross-site scripting (XSS) vulnerabilities in SmarterMail 9.2 allow remote attackers to inject arbitrary web sc
23RISK
open
Referência
CVE-2014-5100
Multiple cross-site request forgery (CSRF) vulnerabilities in Omeka before 2.2.1 allow remote attackers to hijack the au
23RISK
open
Referência
CVE-2014-5100
Multiple cross-site request forgery (CSRF) vulnerabilities in Omeka before 2.2.1 allow remote attackers to hijack the au
23RISK
open
ReferênciaVexDay Proof
PHPMyCart 1.3 - 'cat' SQL Injection
CVE-2008-2904webappsphp
SQL injection vulnerability in shop.php in Conkurent PHPMyCart allows remote attackers to execute arbitrary SQL commands
23RISK
open
Referência
CVE-2017-14620
SmarterStats Version 11.3.6347 will Render the Referer Field of HTTP Logfiles from URL /Data/Reports/ReferringURLsWithQu
23RISK
open
ReferênciaVexDay Proof
Mambo 4.6.4 - 'Output.php' Remote File Inclusion
CVE-2008-2905webappsphp
PHP remote file inclusion vulnerability in includes/Cache/Lite/Output.php in the Cache_Lite package in Mambo 4.6.4 and e
43RISK
open
ReferênciaVexDay Proof
Micro CMS 0.3.5 - Remote Add/Delete/Password Change
CVE-2008-6553webappsphp
microcms-admin-home.php in Implied by Design Micro CMS (Micro-CMS) 3.5 (aka 0.3.5) does not require authentication as an
23RISK
open
Referência
CVE-2018-18419
Stored XSS has been discovered in the upload section of ARDAWAN.COM User Management 1.1, as demonstrated by a .jpg filen
23RISK
open
Referência
CVE-2026-9677
Shariff for WordPress <= 1.0.11 - Admin+ Stored Cross-Site Scripting
33RISK
open
Referência
CVE-2017-10129
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version
23RISK
open
Referência
CVE-2010-0674
StatCounteX 3.1 stores sensitive information under the web root with insufficient access control, which allows remote at
23RISK
open
Referência
CVE-2010-0674
StatCounteX 3.1 stores sensitive information under the web root with insufficient access control, which allows remote at
23RISK
open
Referência
CVE-2012-6048
Guitar Pro 6.1.1 r10791 allows remote attackers to cause a denial of service (crash) via a long string in a gpx file.
23RISK
open
Referência
CVE-2010-0939
Visialis ABB Forum 1.1 stores sensitive information under the web root with insufficient access control, which allows re
23RISK
open
Referência
CVE-2010-0939
Visialis ABB Forum 1.1 stores sensitive information under the web root with insufficient access control, which allows re
23RISK
open
Referência
CVE-2010-0765
fipsForum 2.6 stores sensitive information under the web root with insufficient access control, which allows remote atta
23RISK
open
Referência
CVE-2004-1580
SQL injection vulnerability in index.php in CubeCart 2.0.1 allows remote attackers to execute arbitrary SQL commands via
23RISK
open
ReferênciaVexDay Proof
vhostadmin 0.1 - 'MODULES_DIR' Remote File Inclusion
CVE-2007-0558webappsphp
PHP remote file inclusion vulnerability in modules/mail/main.php in Inter7 vHostAdmin 1.0 allows remote attackers to exe
23RISK
open
Referência
CVE-2018-11532
An issue was discovered in the ChangUonDyU Advanced Statistics plugin 1.0.2 for MyBB. changstats.php has XSS, as demonst
23RISK
open
Referência
CVE-2009-2263
Directory traversal vulnerability in index.php in Awesome PHP Mega File Manager 1.0 allows remote attackers to include a
23RISK
open
Referência
CVE-2010-2721
SQL injection vulnerability in index.php in RightInPoint Lyrics Script 3.0 allows remote attackers to execute arbitrary
23RISK
open
Referência
CVE-2010-2721
SQL injection vulnerability in index.php in RightInPoint Lyrics Script 3.0 allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
jGallery 1.3 - 'index.php' Remote File Inclusion
CVE-2007-2158webappsphp
PHP remote file inclusion vulnerability in index.php in jGallery 1.3 allows remote attackers to execute arbitrary PHP co
23RISK
open
ReferênciaVexDay Proof
Squirrelcart 1.x - 'cart.php' Remote File Inclusion
CVE-2007-4439webappsphp
PHP remote file inclusion vulnerability in popup_window.php in Squirrelcart 1.x.x and earlier allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
PEEL CMS 3.x - Admin Hash Extraction / Arbitrary File Upload
CVE-2008-1506webappsphp
PEEL, possibly 3.x and earlier, allows remote attackers to obtain configuration information via a direct request to phpi
23RISK
open
previouspage 388 / 739next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.