Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,231cataloged exploits
35,420CVEs with public exploitation
24,695lab-tested
22,233 exploits
Referência
CVE-2007-5817
dialog.php in CONTENTCustomizer 3.1mp and earlier allows remote attackers to perform certain privileged actions via a (1
33RISK
open
Referência
CVE-2018-17775
Seqrite End Point Security v7.4 has "Everyone: (F)" permission for %PROGRAMFILES%\Seqrite\Seqrite, which allows local us
23RISK
open
Referência
CVE-2022-23909
There is an unquoted service path in Sherpa Connector Service (SherpaConnectorService.exe) 2020.2.20328.2050. This might
23RISK
open
Referência
CVE-2009-2234
Multiple SQL injection vulnerabilities in admin.php in VICIDIAL Call Center Suite 2.0.5-173 allow remote attackers to ex
23RISK
open
ReferênciaVexDay Proof
ThWboard 3.0b2.84-php5 - SQL Injection / Code Execution
CVE-2007-0340webappsphp
SQL injection vulnerability in inc/header.inc.php in ThWboard 3.0b2.84-php5 and earlier allows remote attackers to execu
23RISK
open
ReferênciaVexDay Proof
LightRO CMS 1.0 - 'index.php?projectid' SQL Injection
CVE-2007-0904webappsphp
SQL injection vulnerability in projects.php in LightRO CMS 1.0 allows remote attackers to execute arbitrary SQL commands
23RISK
open
ReferênciaVexDay Proof
XOOPS Module debaser 0.92 - 'genre.php' Blind SQL Injection
CVE-2007-1805webappsphp
SQL injection vulnerability in genre.php in the debaser 0.92 and earlier module for Xoops allows remote attackers to exe
23RISK
open
ReferênciaVexDay Proof
Joomla! Component Phil-a-Form 1.2.0.0 - SQL Injection
CVE-2007-2933webappsphp
SQL injection vulnerability in index.php in the Phil-a-Form (com_philaform) 1.2.0.0 and earlier component for Joomla! al
23RISK
open
ReferênciaVexDay Proof
PNPHPBB2 < 1.2i - 'viewforum.php' SQL Injection
CVE-2007-3584webappsphp
SQL injection vulnerability in viewforum.php in PNphpBB2 1.2i and earlier for Postnuke allows remote attackers to execut
23RISK
open
ReferênciaVexDay Proof
Prozilla Directory Script - 'Directory.php?cat_id' SQL Injection
CVE-2007-3809webappsphp
Multiple SQL injection vulnerabilities in Prozilla Directory Script allow remote attackers to execute arbitrary SQL comm
23RISK
open
ReferênciaVexDay Proof
Mambo Component Remository - 'cat' SQL Injection
CVE-2007-4505webappsphp
SQL injection vulnerability in index.php in the RemoSitory component (com_remository) for Mambo allows remote attackers
23RISK
open
ReferênciaVexDay Proof
Autodealers CMS AutOnline - 'id' SQL Injection
CVE-2008-4074webappsphp
SQL injection vulnerability in index.php in Zanfi Autodealers CMS AutOnline allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
WebPortal CMS 0.7.4 - 'download.php' SQL Injection
CVE-2008-4345webappsphp
SQL injection vulnerability in download.php in WebPortal CMS 0.7.4 and earlier allows remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
Talkback 2.3.6 - Multiple Local File Inclusion / PHPInfo Disclosure Vulnerabilities
CVE-2008-4346webappsphp
Directory traversal vulnerability in TalkBack 2.3.6 and 2.3.6.4 allows remote attackers to include and execute arbitrary
23RISK
open
ReferênciaVexDay Proof
Injader CMS 2.1.1 - 'id' SQL Injection
CVE-2008-5890webappsphp
SQL injection vulnerability in feeds.php in Injader before 2.1.2 allows remote attackers to execute arbitrary SQL comman
23RISK
open
ReferênciaVexDay Proof
Joomla! Component live chat - SQL Injection / Open Proxy
CVE-2008-6881webappsphp
Multiple SQL injection vulnerabilities in the Live Chat (com_livechat) component 1.0 for Joomla! allow remote attackers
23RISK
open
Referência
CVE-2017-15580
osTicket 1.10.1 provides a functionality to upload 'html' files with associated formats. However, it does not properly v
28RISK
open
Referência
CVE-2008-3750
SQL injection vulnerability in tr.php in YourFreeWorld URL Rotator Script allows remote attackers to execute arbitrary S
23RISK
open
Referência
CVE-2010-1611
Cross-site request forgery (CSRF) vulnerability in AlegroCart 1.1 allows remote attackers to hijack the authentication o
23RISK
open
Referência
CVE-2025-34329
AudioCodes Fax/IVR Appliance <= 2.6.23 Unauthenticated Backup Upload RCE via ajaxBackupUploadFile.php
48RISK
open
Referência
CVE-2025-34329
AudioCodes Fax/IVR Appliance <= 2.6.23 Unauthenticated Backup Upload RCE via ajaxBackupUploadFile.php
48RISK
open
Referência
CVE-2010-4855
SQL injection vulnerability in oku.asp in xWeblog 2.2 allows remote attackers to execute arbitrary SQL commands via the
23RISK
open
Referência
CVE-2010-4855
SQL injection vulnerability in oku.asp in xWeblog 2.2 allows remote attackers to execute arbitrary SQL commands via the
23RISK
open
Referência
CVE-2010-4904
SQL injection vulnerability in the Aardvertiser (com_aardvertiser) component 2.1 and 2.1.1 for Joomla! allows remote att
23RISK
open
Referência
CVE-2017-16895
The (1) arq_updater, (2) arqcommitter, (3) standardrestorer, (4) arqglacierrestorer, and (5) arqs3glacierrestorer helper
23RISK
open
ReferênciaVexDay Proof
iG Shop 1.4 - 'page.php' SQL Injection
CVE-2007-2717webappsphp
SQL injection vulnerability in shop/page.php in iGeneric (iG) Shop 1.4 allows remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
Texas Imperial Software WFTPD 3.23 - 'SIZE' Remote Buffer Overflow
CVE-2006-4318remotewindows
Buffer overflow in WFTPD Server 3.23 allows remote attackers to execute arbitrary code via long SIZE commands.
50RISK
open
Referência
CVE-2017-15595
An issue was discovered in Xen through 4.9.x allowing x86 PV guest OS users to cause a denial of service (unbounded recu
23RISK
open
Referência
CVE-2018-11034
In 2345 Security Guard 3.7, the driver file (2345NsProtect.sys, X64 version) allows local users to cause a denial of ser
23RISK
open
Referência
CVE-2023-27010
Wondershare Dr.Fone v12.9.6 was discovered to contain weak permissions for the service WsDrvInst. This vulnerability all
41RISK
open
previouspage 432 / 742next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.