Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,231cataloged exploits
35,420CVEs with public exploitation
24,695lab-tested
22,233 exploits
Referência
CVE-2015-1515
The dwall.sys driver in SoftSphere DefenseWall Personal Firewall 3.24 allows local users to write data to arbitrary memo
23RISK
open
Referência
CVE-2011-5039
Multiple SQL injection vulnerabilities in Infoproject Biznis Heroj allow remote attackers to execute arbitrary SQL comma
23RISK
open
Referência
CVE-2020-0618
CVE-2020-0618CRITICALunder attack
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page
100RISK
open
Referência
CVE-2020-0646
CVE-2020-0646CRITICALunder attack
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.N
100RISK
open
Referência
CVE-2020-0674
CVE-2020-0674HIGHunder attack
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
93RISK
open
Referência
CVE-2020-0688
CVE-2020-0688HIGHunder attackransomware
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open
Referência
CVE-2020-0688
CVE-2020-0688HIGHunder attackransomware
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open
Referência
CVE-2011-5103
SQL injection vulnerability in Alurian Prismotube PHP Video Script allows remote attackers to execute arbitrary SQL comm
23RISK
open
Referência
CVE-2011-5110
Multiple SQL injection vulnerabilities in Blogs Manager 1.101 and earlier allow remote attackers to execute arbitrary SQ
23RISK
open
Referência
CVE-2011-5130
dev/less.php in Family Connections CMS (FCMS) 2.5.0 - 2.7.1, when register_globals is enabled, allows remote attackers t
50RISK
open
Referência
CVE-2011-5135
Multiple SQL injection vulnerabilities in the save_connection function in lib/lib.iotask.php in the iotask module in Doc
23RISK
open
ReferênciaVexDay Proof
VUPlayer 2.49 - '.asx' HREF Local Buffer Overflow (2)
CVE-2009-0174localwindows
Stack-based buffer overflow in VUPlayer 2.49 allows remote attackers to execute arbitrary code via a long .asf URI in th
28RISK
open
Referência
CVE-2020-11108
The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abus
60RISK
open
Referência
CVE-2020-11108
The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abus
60RISK
open
ReferênciaVexDay Proof
LimeSurvey 4.1.11 - 'File Manager' Path Traversal
CVE-2020-11455webappsphp
LimeSurvey before 4.1.12+200324 contains a path traversal vulnerability in application/controllers/admin/LimeSurveyFileM
60RISK
open
Referência
LimeSurvey 4.1.11 - 'Survey Groups' Persistent Cross-Site Scripting
CVE-2020-11456webappsphp
LimeSurvey before 4.1.12+200324 has stored XSS in application/views/admin/surveysgroups/surveySettings.php and applicati
45RISK
open
Referência
CVE-2020-1147
CVE-2020-1147HIGHunder attack
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the softwar
100RISK
open
Referência
CVE-2026-16228
SourceCodester Class and Exam Timetabling System edit_schoolyr.php sql injection
33RISK
open
Referência
CVE-2015-1635
CVE-2015-1635CRITICALunder attack
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RISK
open
Referência
CVE-2015-1635
CVE-2015-1635CRITICALunder attack
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RISK
open
Referência
CVE-2015-1635
CVE-2015-1635CRITICALunder attack
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RISK
open
Referência
CVE-2026-8733
Investintech SlimPDFReader SlimPDFReader.exe sub_3B4610 stack-based overflow
33RISK
open
ReferênciaVexDay Proof
SkaLinks 1.5 - Authentication Bypass
CVE-2009-0451webappsphp
SQL injection vulnerability in Skalfa SkaLinks 1.5 allows remote attackers to execute arbitrary SQL commands via the Adm
23RISK
open
ReferênciaVexDay Proof
Online Grades 3.2.4 - Authentication Bypass
CVE-2009-0452webappsphp
Multiple SQL injection vulnerabilities in parents/login.php in Online Grades 3.2.4, when magic_quotes_gpc is disabled, a
23RISK
open
Referência
CVE-2026-8731
Open5GS NRF client.c ogs_sbi_client_add denial of service
33RISK
open
Referência
CVE-2026-8730
Open5GS NRF context.c ogs_sbi_nf_instance_set_id denial of service
33RISK
open
Referência
CVE-2026-8728
Open5GS NRF conv.c ogs_sbi_discovery_option_parse_plmn_list denial of service
33RISK
open
Referência
CVE-2011-5166
Multiple stack-based buffer overflows in KnFTP 1.0.0 allow remote attackers to execute arbitrary code via a long string
23RISK
open
Referência
CVE-2026-8725
CoreWorxLab CAAL test-hass Endpoint webhooks.py server-side request forgery
33RISK
open
Referência
CVE-2026-8724
Dataease Data Dashboard SqlparserUtils.java SqlparserUtils.transFilter sql injection
33RISK
open
previouspage 435 / 742next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.