Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,151cataloged exploits
35,370CVEs with public exploitation
24,695lab-tested
22,175 exploits
Referência
CVE-2017-17613
Freelance Website Script 2.0.6 has SQL Injection via the jobdetails.php pr_id parameter or the searchbycat_list.php cati
23RISK
open
Referência
CVE-2017-17614
Food Order Script 1.0 has SQL Injection via the /list city parameter.
23RISK
open
Referência
CVE-2017-17614
Food Order Script 1.0 has SQL Injection via the /list city parameter.
23RISK
open
Referência
CVE-2026-49136
Banana Slides 0.4.0 Path Traversal via generate_image() in ai_service.py
21RISK
open
Referência
CVE-2026-43624
F5-TTS 1.1.20 Path Traversal via finetune_gradio.py create_data_project()
21RISK
open
Referência
CVE-2026-43623
microtar 0.1.0 Stack-Based Buffer Overflow via raw_to_header()
21RISK
open
Referência
CVE-2017-17623
Opensource Classified Ads Script 3.2 has SQL Injection via the advance_result.php keyword parameter.
23RISK
open
ReferênciaVexDay Proof
ZeusCart 2.0 - 'category_list.php' SQL Injection
CVE-2008-5216webappsphp
SQL injection vulnerability in category_list.php in AJ Square ZeusCart 2.0 and earlier allows remote attackers to execut
23RISK
open
Referência
CVE-2017-17623
Opensource Classified Ads Script 3.2 has SQL Injection via the advance_result.php keyword parameter.
23RISK
open
ReferênciaVexDay Proof
FREEze Greetings 1.0 - Remote Password Retrieve
CVE-2008-5218webappsphp
ScriptsEz FREEze Greetings 1.0 stores pwd.txt under the web root with insufficient access control, which allows remote a
23RISK
open
Referência
CVE-2010-3428
SQL injection vulnerability in modules/notes/json.php in Intermesh Group-Office 3.5.9 allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
wPortfolio 0.3 - Admin Password Changing
CVE-2008-5221webappsphp
The account_save action in admin/userinfo.php in wPortfolio 0.3 and earlier does not require authentication and does not
23RISK
open
Referência
CVE-2017-17624
PHP Multivendor Ecommerce 1.0 has SQL Injection via the single_detail.php sid parameter, or the category.php searchcat o
23RISK
open
ReferênciaVexDay Proof
AirvaeCommerce 3.0 - 'pid' SQL Injection
CVE-2008-5223webappsphp
SQL injection vulnerability in index.php in Airvae Commerce 3.0 allows remote attackers to execute arbitrary SQL command
23RISK
open
Referência
CVE-2026-10252
itsourcecode Online House Rental System manage_tenant.php sql injection
33RISK
open
Referência
CVE-2017-17624
PHP Multivendor Ecommerce 1.0 has SQL Injection via the single_detail.php sid parameter, or the category.php searchcat o
23RISK
open
ReferênciaVexDay Proof
TNT Forum 0.9.4 - Local File Inclusion
CVE-2008-5265webappsphp
Directory traversal vulnerability in index.php in TNT Forum 0.9.4, when magic_quotes_gpc is disabled, allows remote atta
23RISK
open
Referência
CVE-2017-17625
Professional Service Script 1.0 has SQL Injection via the service-list city parameter.
23RISK
open
ReferênciaVexDay Proof
Clean CMS 1.5 - Blind SQL Injection
CVE-2008-5289webappsphp
SQL injection vulnerability in full_txt.php in Werner Hilversum Clean CMS 1.5 allows remote attackers to execute arbitra
23RISK
open
Referência
CVE-2017-17625
Professional Service Script 1.0 has SQL Injection via the service-list city parameter.
23RISK
open
Referência
CVE-2017-17626
Readymade PHP Classified Script 3.3 has SQL Injection via the /categories subctid or mctid parameter.
23RISK
open
Referência
CVE-2017-17626
Readymade PHP Classified Script 3.3 has SQL Injection via the /categories subctid or mctid parameter.
23RISK
open
Referência
CVE-2017-17628
Responsive Realestate Script 3.2 has SQL Injection via the property-list tbud parameter.
23RISK
open
Referência
CVE-2017-17628
Responsive Realestate Script 3.2 has SQL Injection via the property-list tbud parameter.
23RISK
open
Referência
CVE-2017-17630
Yoga Class Script 1.0 has SQL Injection via the /list city parameter.
23RISK
open
Referência
CVE-2017-17630
Yoga Class Script 1.0 has SQL Injection via the /list city parameter.
23RISK
open
Referência
CVE-2017-17631
Multireligion Responsive Matrimonial 4.7.2 has SQL Injection via the success-story.php succid parameter.
23RISK
open
Referência
CVE-2017-17631
Multireligion Responsive Matrimonial 4.7.2 has SQL Injection via the success-story.php succid parameter.
23RISK
open
Referência
CVE-2017-17632
Responsive Events And Movie Ticket Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
23RISK
open
Referência
CVE-2017-17632
Responsive Events And Movie Ticket Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
23RISK
open
previouspage 419 / 740next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.