Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,151cataloged exploits
35,370CVEs with public exploitation
24,695lab-tested
22,233 exploits
Referência
CVE-2010-5048
Cross-site scripting (XSS) vulnerability in admin.jcomments.php in the JoomlaTune JComments (com_jcomments) component 2.
23RISK
open
Referência
CVE-2015-2999
Multiple SQL injection vulnerabilities in SysAid Help Desk before 15.2 allow remote administrators to execute arbitrary
23RISK
open
Referência
CVE-2023-3897
Bypassing CAPTCHA & Enumerating Usernames via Password Reset Page
33RISK
open
ReferênciaVexDay Proof
Alstrasoft e-Friends 4.21 - Admin Session Retrieve
CVE-2007-2824webappsphp
SQL injection vulnerability in paypal.php in AlstraSoft E-Friends 4.21 and earlier allows remote attackers to execute ar
23RISK
open
Referência
CVE-2010-2138
Multiple directory traversal vulnerabilities in ProMan 0.1.1 and earlier allow remote attackers to include and execute a
23RISK
open
Referência
CVE-2010-2138
Multiple directory traversal vulnerabilities in ProMan 0.1.1 and earlier allow remote attackers to include and execute a
23RISK
open
ReferênciaVexDay Proof
Interact 2.4.1 - Multiple Remote File Inclusions
CVE-2008-2220webappsphp
Multiple PHP remote file inclusion vulnerabilities in Interact Learning Community Environment Interact 2.4.1, when regis
23RISK
open
Referência
CVE-2017-0145
CVE-2017-0145HIGHunder attackransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Referência
CVE-2017-0145
CVE-2017-0145HIGHunder attackransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Referência
CVE-2017-0145
CVE-2017-0145HIGHunder attackransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
ReferênciaVexDay Proof
cmsWorks 2.2 RC4 - 'mod_root' Remote File Inclusion
CVE-2008-2877webappsphp
PHP remote file inclusion vulnerability in admin/include/lib.module.php in cmsWorks 2.2 RC4, when register_globals is en
23RISK
open
ReferênciaVexDay Proof
Free Hosting Manager 1.2/2.0 - Insecure Cookie Handling
CVE-2008-3557webappsphp
Free Hosting Manager 1.2 and 2.0 allows remote attackers to bypass authentication and gain administrative access by sett
23RISK
open
Referência
CVE-2010-2142
SQL injection vulnerability in default.asp in Cyberhost allows remote attackers to execute arbitrary SQL commands via th
23RISK
open
Referência
CVE-2009-2772
Multiple cross-site scripting (XSS) vulnerabilities in PG Roommate Finder Solution allow remote attackers to inject arbi
23RISK
open
ReferênciaVexDay Proof
Click N Print Coupons 2006.01 - 'key' SQL Injection
CVE-2006-6859webappsasp
SQL injection vulnerability in coupon_detail.asp in Website Designs For Less Click N' Print Coupons 2005.01 and earlier
23RISK
open
Referência
CVE-2014-8507
Multiple SQL injection vulnerabilities in the queryLastApp method in packages/WAPPushManager/src/com/android/smspush/Wap
23RISK
open
Referência
CVE-2022-4774
Bit Form < 1.9 - RCE via Unauthenticated Arbitrary File Upload
48RISK
open
ReferênciaVexDay Proof
otscms 2.1.5 - SQL Injection / Cross-Site Scripting
CVE-2007-0846webappsphp
Cross-site scripting (XSS) vulnerability in forum.php in Open Tibia Server CMS (OTSCMS) 2.1.5 and earlier allows remote
23RISK
open
ReferênciaVexDay Proof
phpQuiz 0.1.2 - SQL Injection / Code Execution
CVE-2006-4978webappsphp
Multiple SQL injection vulnerabilities in Walter Beschmout PhpQuiz 1.2 and earlier allow remote attackers to execute arb
23RISK
open
Referência
CVE-2016-9111
Incorrect access control mechanisms in Citrix Receiver Desktop Lock 4.5 allow an attacker to bypass the authentication r
23RISK
open
Referência
CVE-2016-9111
Incorrect access control mechanisms in Citrix Receiver Desktop Lock 4.5 allow an attacker to bypass the authentication r
23RISK
open
Referência7
CVE-2025-0364: BigAnt Server RCE Exploit
BigAntSoft BigAnt Server Account Registration Bypass to File Upload RCE
48RISK
open
Referência
CVE-2010-2143
Directory traversal vulnerability in index.php in Symphony CMS 2.0.7 allows remote attackers to read arbitrary files and
23RISK
open
Referência
CVE-2017-0147
CVE-2017-0147HIGHunder attackransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Referência
CVE-2017-0147
CVE-2017-0147HIGHunder attackransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
ReferênciaVexDay Proof
creative Guestbook 1.0 - Multiple Vulnerabilities
CVE-2007-1479webappsphp
Cross-site scripting (XSS) vulnerability in Guestbook.php in Creative Guestbook 1.0 allows remote attackers to inject ar
23RISK
open
ReferênciaVexDay Proof
k-links directory - SQL Injection / Cross-Site Scripting
CVE-2008-3581webappsphp
Cross-site scripting (XSS) vulnerability in index.php in Qsoft K-Links allows remote attackers to inject arbitrary web s
23RISK
open
ReferênciaVexDay Proof
Alstrasoft Article Manager Pro 1.6 - Authentication Bypass
CVE-2008-5649webappsphp
SQL injection vulnerability in admin/admin.php in AlstraSoft Article Manager Pro 1.6 allows remote attackers to execute
23RISK
open
Referência
CVE-2018-5282
Kentico 9.0 through 11.0 has a stack-based buffer overflow via the SqlName, SqlPswd, Database, UserName, or Password fie
23RISK
open
Referência
CVE-2020-8424
Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account takeover via passwordmychange.php
23RISK
open
previouspage 425 / 742next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.