Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,302cataloged exploits
35,469CVEs with public exploitation
24,695lab-tested
22,266 exploits
ReferênciaVexDay Proof
otscms 2.1.5 - SQL Injection / Cross-Site Scripting
CVE-2007-0847webappsphp
SQL injection vulnerability in mod/PM/reply.php in Open Tibia Server CMS (OTSCMS) 2.1.5 and earlier allows remote attack
23RISK
open
Referência
CVE-2020-8657
CVE-2020-8657CRITICALunder attack
An issue was discovered in EyesOfNetwork 5.3. The installation uses the same API key (hardcoded as EONAPI_KEY in include
100RISK
open
ReferênciaVexDay Proof
OPENi-CMS Site Protection Plugin - Remote File Inclusion
CVE-2007-0881webappsphp
PHP remote file inclusion vulnerability in the Seitenschutz plugin for OPENi-CMS 1.0 allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
Axigen 2.0.0b1 - Remote Denial of Service (2)
CVE-2007-0887doslinux
axigen 1.2.6 through 2.0.0b1 does not properly parse login credentials, which allows remote attackers to cause a denial
28RISK
open
ReferênciaVexDay Proof
OpenX 2.6.3 - 'MAX_type' Local File Inclusion
CVE-2009-0291webappsphp
Directory traversal vulnerability in fc.php in OpenX 2.6.3 allows remote attackers to include and execute arbitrary file
23RISK
open
Referência
CVE-2018-16509
An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handlin
60RISK
open
Referência
CVE-2018-3810
Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unau
60RISK
open
Referência
CVE-2009-3023
Buffer overflow in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 6.0 allows remote authen
60RISK
open
ReferênciaVexDay Proof
philboard 1.14 - 'philboard_forum.asp' SQL Injection
CVE-2007-0920webappsasp
SQL injection vulnerability in philboard_forum.asp in Philboard 1.14 and earlier allows remote attackers to execute arbi
23RISK
open
Referência
CVE-2015-8556
Local privilege escalation vulnerability in the Gentoo QEMU package before 2.5.0-r1.
28RISK
open
Referência
CVE-2017-15222
Buffer Overflow vulnerability in Ayukov NFTPD 2.0 and earlier allows remote attackers to execute arbitrary code.
50RISK
open
ReferênciaVexDay Proof
Nortel SSL VPN Linux Client 6.0.3 - Local Privilege Escalation
CVE-2007-1057locallinux
The Net Direct client for Linux before 6.0.5 in Nortel Application Switch 2424, VPN 3050 and 3070, and SSL VPN Module 10
23RISK
open
ReferênciaVexDay Proof
PHP-Nuke 8.0 Final - HTTP Referers SQL Injection
CVE-2007-1061webappsphp
SQL injection vulnerability in index.php in Francisco Burzi PHP-Nuke 8.0 Final and earlier, when the "HTTP Referers" blo
35RISK
open
ReferênciaVexDay Proof
News Bin Pro 5.33 - '.nbi' Local Buffer Overflow
CVE-2007-1074localwindows
Multiple buffer overflows in NewsBin Pro 5.33 and NewsBin Pro 4.x allow user-assisted remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
TurboFTP Server 5.30 Build 572 - 'newline/LIST' Multiple Remote Denial of Service Vulnerabilities
CVE-2007-1075doswindows
TurboFTP 5.30 Build 572 allows remote servers to cause a denial of service (CPU consumption) via a response with a large
23RISK
open
ReferênciaVexDay Proof
TurboFTP Server 5.30 Build 572 - 'newline/LIST' Multiple Remote Denial of Service Vulnerabilities
CVE-2007-1080doswindows
Multiple heap-based buffer overflows in TurboFTP 5.30 Build 572 allow remote servers to cause a denial of service via (1
23RISK
open
ReferênciaVexDay Proof
PHP-MIP 0.1 - 'top.php?laypath' Remote File Inclusion
CVE-2007-1104webappsphp
PHP remote file inclusion vulnerability in top.php in PHP Module Implementation (PHP-MIP) 0.1 allows remote attackers to
23RISK
open
Referência
CVE-2024-7954
SPIP porte_plume Plugin Arbitrary PHP Execution
85RISK
open
Referência
CVE-2024-13160
CVE-2024-13160CRITICALunder attack
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up
100RISK
open
Referência
CVE-2025-37164
CVE-2025-37164CRITICALunder attack
A remote code execution issue exists in HPE OneView.
100RISK
open
Referência
CVE-2019-7195
CVE-2019-7195CRITICALunder attackransomware
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fi
100RISK
open
Referência
CVE-2019-17621
CVE-2019-17621CRITICALunder attack
The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated rem
100RISK
open
Referência
CVE-2018-4878
CVE-2018-4878HIGHunder attackransomware
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RISK
open
Referência
CVE-2018-14417
A command injection vulnerability was found in the web administration console in SoftNAS Cloud before 4.0.3. In particul
45RISK
open
ReferênciaVexDay Proof
Angel Lms 7.1 - 'default.asp?id' SQL Injection
CVE-2007-1250webappsasp
SQL injection vulnerability in section/default.asp in ANGEL Learning Management Suite (LMS) 7.1 allows remote attackers
23RISK
open
ReferênciaVexDay Proof
Connectix Boards 0.7 - 'p_skin' Multiple Vulnerabilities
CVE-2007-1255webappsphp
Unrestricted file upload vulnerability in admin.bbcode.php in Connectix Boards 0.7 and earlier allows remote authenticat
23RISK
open
ReferênciaVexDay Proof
WebMod 0.48 - Content-Length Remote Buffer Overflow
CVE-2007-1260remotewindows
Stack-based buffer overflow in the connectHandle function in server.cpp in WebMod 0.48 allows remote attackers to execut
23RISK
open
ReferênciaVexDay Proof
AJ Dating 1.0 - 'view_profile.php' SQL Injection
CVE-2007-1297webappsphp
SQL injection vulnerability in view_profile.php in AJDating 1.0 allows remote attackers to execute arbitrary SQL command
23RISK
open
ReferênciaVexDay Proof
AJ Auction Pro - 'subcat.php' SQL Injection
CVE-2007-1298webappsphp
SQL injection vulnerability in subcat.php in AJ Auction 1.0 allows remote attackers to execute arbitrary SQL commands vi
23RISK
open
ReferênciaVexDay Proof
Mani Stats Reader 1.2 - 'ipath' Remote File Inclusion
CVE-2007-1299webappsphp
PHP remote file inclusion vulnerability in index.php in Mani Stats Reader 1.2 and earlier allows remote attackers to exe
23RISK
open
previouspage 463 / 743next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.