Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,151cataloged exploits
35,370CVEs with public exploitation
24,695lab-tested
22,175 exploits
Referência
CVE-2016-6914
Ubiquiti UniFi Video before 3.8.0 for Windows uses weak permissions for the installation directory, which allows local u
23RISK
open
Referência
CVE-2016-6914
Ubiquiti UniFi Video before 3.8.0 for Windows uses weak permissions for the installation directory, which allows local u
23RISK
open
Referência
CVE-2010-2687
SQL injection vulnerability in printdetail.asp in Site2Nite Boat Classifieds allows remote attackers to execute arbitrar
23RISK
open
Referência
CVE-2010-2687
SQL injection vulnerability in printdetail.asp in Site2Nite Boat Classifieds allows remote attackers to execute arbitrar
23RISK
open
Referência
CVE-2010-2684
SQL injection vulnerability in index.php in Customer Paradigm PageDirector CMS allows remote attackers to execute arbitr
23RISK
open
Referência
CVE-2012-4054
Buffer overflow in the readfile function in CPE17 Autorun Killer 1.7.1 and earlier allows physically proximate attackers
23RISK
open
Referência
CVE-2010-2688
SQL injection vulnerability in detail.asp in Site2Nite Boat Classifieds allows remote attackers to execute arbitrary SQL
23RISK
open
Referência
CVE-2010-2694
SQL injection vulnerability in the redSHOP Component (com_redshop) 1.0 for Joomla! allows remote attackers to execute ar
23RISK
open
Referência
CVE-2024-11605
WP Publications <= 1.2 - Admin+ Stored XSS
33RISK
open
Referência
CVE-2009-4620
SQL injection vulnerability in the Joomloc (com_joomloc) component 1.0 for Joomla allows remote attackers to execute arb
23RISK
open
Referência
CVE-2026-16540
Simply Schedule Appointments < 1.6.12.6 - Unauthenticated Appointment Data Disclosure and Mass Deletion via purge Endpoint
41RISK
open
Referência
CVE-2026-16062
Event Booking Manager for WooCommerce < 5.3.7 - Contributor+ PHP Object Injection via Event Timeline and FAQ Content
33RISK
open
Referência
CVE-2025-6763
Comet System H3531 Web-based Management setupA.cfg missing authentication
48RISK
open
Referência
CVE-2026-28515
openDCIM <= 23.04 Missing Authorization in install.php
63RISK
open
Referência
CVE-2026-28515
openDCIM <= 23.04 Missing Authorization in install.php
63RISK
open
Referência
CVE-2016-1719
The IOHIDFamily API in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain pri
23RISK
open
Referência
CVE-2016-1719
The IOHIDFamily API in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain pri
23RISK
open
ReferênciaVexDay Proof
phpIP 4.3.2 - Multiple SQL Injections
CVE-2008-0538webappsphp
Multiple SQL injection vulnerabilities in phpIP Management 4.3.2 allow remote attackers to execute arbitrary SQL command
23RISK
open
ReferênciaVexDay Proof
FoT Video scripti 1.1b - 'oyun' SQL Injection
CVE-2008-4176webappsasp
SQL injection vulnerability in izle.asp in FoT Video scripti 1.1 beta allows remote attackers to execute arbitrary SQL c
23RISK
open
ReferênciaVexDay Proof
Pre Real Estate Listings - 'search.php' SQL Injection
CVE-2008-4177webappsphp
SQL injection vulnerability in search.php in Pre Real Estate Listings allows remote attackers to execute arbitrary SQL c
23RISK
open
Referência
CVE-2017-12617
CVE-2017-12617HIGHunder attack
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RISK
open
Referência
CVE-2017-12617
CVE-2017-12617HIGHunder attack
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RISK
open
Referência
CVE-2017-14489
The iscsi_if_rx function in drivers/scsi/scsi_transport_iscsi.c in the Linux kernel through 4.13.2 allows local users to
23RISK
open
ReferênciaVexDay Proof
PEEL CMS 3.x - Admin Hash Extraction / Arbitrary File Upload
CVE-2008-1496webappsphp
Multiple SQL injection vulnerabilities in PEEL, possibly 3.x and earlier, allow remote attackers to execute arbitrary SQ
23RISK
open
Referência
CVE-2021-34110
WinWaste.NET version 1.0.6183.16475 has incorrect permissions, allowing a local unprivileged user to replace the executa
23RISK
open
Referência
CVE-2009-3758
SQL injection vulnerability in login.php in sample code in the XenServer Resource Kit in Citrix XenCenterWeb allows remo
23RISK
open
Referência
CVE-2009-2881
Multiple SQL injection vulnerabilities in Basilic 1.5.13 allow remote attackers to execute arbitrary SQL commands via th
23RISK
open
ReferênciaVexDay Proof
Web Directory Script 2.0 - 'name' SQL Injection
CVE-2008-3787webappsphp
SQL injection vulnerability in listing_view.php in Web Directory Script 2.0 and earlier allows remote attackers to execu
23RISK
open
Referência
CVE-2009-2921
Multiple SQL injection vulnerabilities in login.php in MOC Designs PHP News 1.1 allow remote attackers to execute arbitr
23RISK
open
Referência
CVE-2017-12635
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB be
60RISK
open
previouspage 417 / 740next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.