Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,058cataloged exploits
35,300CVEs with public exploitation
24,695lab-tested
22,175 exploits
ReferênciaVexDay Proof
WEBBDOMAIN Post Card 1.02 - Authentication Bypass
CVE-2008-6623webappsphp
SQL injection vulnerability in getin.php in WEBBDOMAIN Post Card (aka Web Postcards) 1.02 and earlier allows remote atta
23RISK
open
ReferênciaVexDay Proof
WEBBDOMAIN Polls 1.01 - Authentication Bypass
CVE-2008-6625webappsphp
SQL injection vulnerability in getin.php in WEBBDOMAIN Polls (aka Poll) 1.0 and 1.01 allows remote attackers to execute
23RISK
open
Referência
CVE-2026-7862
Eupago Gateway For Woocommerce < 4.7.2 - Unauthenticated Arbitrary Refund Initiation
41RISK
open
Referência
CVE-2026-44711
pam_usb: Symlink attacks on pad directory and pad files enable authentication bypass and root file corruption
41RISK
open
Referência
CVE-2026-1402
Allocation of Resources Without Limits or Throttling in GitLab
33RISK
open
Referência
CVE-2010-3148
Untrusted search path vulnerability in Microsoft Visio 2003 SP3 allows local users to gain privileges via a Trojan horse
28RISK
open
ReferênciaVexDay Proof
BBlog 0.7.6 - 'mod' SQL Injection
CVE-2008-4436webappsphp
SQL injection vulnerability in bblog_plugins/builtin.help.php in bBlog 0.7.6 allows remote attackers to execute arbitrar
23RISK
open
Referência
CVE-2010-4963
SQL injection vulnerability in folder/list in Hulihan BXR 0.6.8 allows remote attackers to execute arbitrary SQL command
23RISK
open
Referência
CVE-2026-38945
Command injection in Raynet rvia version 12.6 Update 8 and previous versions allows adversaries to execute arbitrary cod
41RISK
open
ReferênciaVexDay Proof
mIRC 6.34 - Remote Buffer Overflow (PoC)
CVE-2008-4449doswindows
Stack-based buffer overflow in mIRC 6.34 allows remote attackers to execute arbitrary code via a long hostname in a PRIV
50RISK
open
Referência
CVE-2010-3149
Untrusted search path vulnerability in Adobe Device Central CS5 3.0.0(376), 3.0.1.0 (3027), and probably other versions
28RISK
open
Referência
CVE-2017-15983
MyMagazine Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing
23RISK
open
Referência
CVE-2017-15984
Creative Management System (CMS) Lite 1.4 allows SQL Injection via the S parameter to index.php.
23RISK
open
Referência
CVE-2018-25323
Allok AVI DivX MPEG to DVD Converter 2.6.1217 Buffer Overflow SEH
41RISK
open
Referência
CVE-2017-15985
Basic B2B Script allows SQL Injection via the product_view1.php pid or id parameter.
23RISK
open
Referência
CVE-2026-65013
Onlook tRPC Insecure Direct Object Reference via multiple procedures
41RISK
open
Referência
CVE-2017-15986
CPA Lead Reward Script allows SQL Injection via the username parameter.
23RISK
open
Referência
CVE-2026-56099
OpenBSD mpls_do_error Kernel Stack Memory Disclosure via MPLS Input
33RISK
open
Referência
CVE-2017-15987
Fake Magazine Cover Script allows SQL Injection via the rate.php value parameter or the content.php id parameter.
23RISK
open
ReferênciaVexDay Proof
Wikepage Opus 10 < 2006.2a (lng) - Remote Command Execution
CVE-2006-4418webappsphp
Directory traversal vulnerability in index.php for Wikepage 2006.2a Opus 10 allows remote attackers to include arbitrary
23RISK
open
ReferênciaVexDay Proof
ProManager 0.73 - 'note.php' SQL Injection
CVE-2006-4419webappsphp
SQL injection vulnerability in note.php in ProManager 0.73 allows remote attackers to execute arbitrary SQL commands via
23RISK
open
Referência
CVE-2017-15988
Nice PHP FAQ Script allows SQL Injection via the index.php nice_theme parameter, a different vulnerability than CVE-2008
23RISK
open
Referência
CVE-2017-15989
Online Exam Test Application allows SQL Injection via the resources.php sort parameter in a category action.
23RISK
open
Referência
CVE-2017-15990
Php Inventory & Invoice Management System allows Arbitrary File Upload via dashboard/edit_myaccountdetail/.
23RISK
open
Referência
CVE-2017-15991
Vastal I-Tech Agent Zone (aka The Real Estate Script) allows SQL Injection in searchCommercial.php via the property_type
23RISK
open
ReferênciaVexDay Proof
YACS CMS 6.6.1 - context[path_to_root] Remote File Inclusion
CVE-2006-4532webappsphp
PHP remote file inclusion vulnerability in articles/article.php in Yet Another Community System (YACS) CMS 6.6.1 and ear
23RISK
open
ReferênciaVexDay Proof
Vastal I-Tech Share Zone - 'id' SQL Injection
CVE-2008-4468webappsphp
SQL injection vulnerability in view_news.php in Vastal I-Tech Share Zone allows remote attackers to execute arbitrary SQ
23RISK
open
Referência
CVE-2026-8157
Vitepos < 3.4.2 - Outlet Manager+ Privilege Escalation
41RISK
open
Referência
CVE-2026-7859
Motors Car Dealership & Classified Listings < 1.4.110 - Unauthenticated Post-Meta Write via stm_ajax_add_a_car_media
33RISK
open
ReferênciaVexDay Proof
CMS Frogss 0.4 - 'podpis' SQL Injection
CVE-2006-4536webappsphp
SQL injection vulnerability in module/rejestracja.php in CMS Frogss 0.4 and earlier allows remote attackers to execute a
23RISK
open
previouspage 398 / 740next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.