Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,401cataloged exploits
35,511CVEs with public exploitation
24,695lab-tested
22,332 exploits
ReferênciaVexDay Proof
VidiScript (Avatar) - Arbitrary File Upload
CVE-2008-6518webappsphp
Unrestricted file upload vulnerability in the profile feature in VidiScript allows registered remote authenticated users
23RISK
open
ReferênciaVexDay Proof
Xitami Web Server 2.5c2 - LRWP Processing Format String (PoC)
CVE-2008-6519doswindows
Format string vulnerability in Xitami Web Server 2.2a through 2.5c2, and possibly other versions, allows remote attacker
23RISK
open
Referência
CVE-2023-40044
CVE-2023-40044CRITICALunder attackransomware
WS_FTP Server Ad Hoc Transfer Module .NET Deserialization Vulnerability
100RISK
open
Referência
CVE-2020-17463
CVE-2020-17463CRITICALunder attack
FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.
100RISK
open
Referência
CVE-2017-8464
CVE-2017-8464HIGHunder attack
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 201
100RISK
open
Referência
CVE-2017-8464
CVE-2017-8464HIGHunder attack
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 201
100RISK
open
ReferênciaVexDay Proof
μTorrent (uTorrent) 1.6 build 474 - 'announce' Key Remote Heap Overflow
CVE-2007-0927remotewindows
Heap-based buffer overflow in uTorrent 1.6 allows remote attackers to execute arbitrary code via a torrent file with a c
35RISK
open
ReferênciaVexDay Proof
OpenInvoice 0.9 - Arbitrary Change User Password
CVE-2008-6523webappsphp
auth.php in openInvoice 0.90 beta and earlier allows remote attackers to bypass authentication and gain privileges by se
23RISK
open
ReferênciaVexDay Proof
Total Video Player 1.20 - '.m3u' File Local Stack Buffer Overflow
CVE-2007-0949localwindows
Stack-based buffer overflow in iTinySoft Studio Total Video Player 1.03, and possibly earlier, allows remote attackers t
28RISK
open
ReferênciaVexDay Proof
BosClassifieds - 'cat_id' SQL Injection
CVE-2008-6526webappsphp
SQL injection vulnerability in index.php in BosDev BosClassifieds allows remote attackers to execute arbitrary SQL comma
23RISK
open
ReferênciaVexDay Proof
GO4I.NET ASP Forum 1.0 - SQL Injection
CVE-2008-6527webappsphp
SQL injection vulnerability in forum.asp in GO4I.NET ASP Forum 1.0 allows remote attackers to execute arbitrary SQL comm
23RISK
open
Referência
CVE-2019-12725
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RISK
open
ReferênciaVexDay Proof
Jupiter CMS 1.1.5 - Arbitrary File Upload
CVE-2007-0972webappsphp
Unrestricted file upload vulnerability in modules/emoticons.php in Jupiter CMS 1.1.5 allows remote attackers to upload a
23RISK
open
ReferênciaVexDay Proof
TmaxSoft JEUS - Alternate Data Streams File Disclosure
CVE-2008-6528remotewindows
NTFS TmaxSoft JEUS 5 before Fix 26 allows remote attackers to read the source code for scripts by appending ::$DATA to t
23RISK
open
ReferênciaVexDay Proof
PayPal eStore - Admin Password Change
CVE-2008-6535webappsphp
admin/settings.php in PayPal eStores allows remote attackers to bypass intended access restrictions and change the admin
23RISK
open
ReferênciaVexDay Proof
ActSoft DVD-Tools - 'dvdtools.ocx' Remote Buffer Overflow
CVE-2007-0976remotewindows
Buffer overflow in the ActSoft DVD-Tools ActiveX control (dvdtools.ocx) allows remote attackers to execute arbitrary cod
23RISK
open
Referência
CVE-2019-19781
CVE-2019-19781CRITICALunder attackransomware
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open
ReferênciaVexDay Proof
OxYProject 0.85 - 'edithistory.php' Remote Code Execution
CVE-2008-6651webappsphp
Static code injection vulnerability in edithistory.php in OxYProject OxYBox 0.85 allows remote attackers to inject arbit
23RISK
open
Referência
CVE-2022-24716
Path traversal in Icinga Web 2
78RISK
open
Referência
CVE-2018-15708
Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP r
60RISK
open
Referência
CVE-2018-15708
Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP r
60RISK
open
ReferênciaVexDay Proof
OneCMS 2.5 - Blind SQL Injection
CVE-2008-6652webappsphp
SQL injection vulnerability in asd.php in OneCMS 2.5 allows remote attackers to execute arbitrary SQL commands via the s
23RISK
open
Referência
CVE-2017-5521
CVE-2017-5521HIGHunder attack
An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R
100RISK
open
Referência
CVE-2014-4977
Multiple SQL injection vulnerabilities in Dell SonicWall Scrutinizer 11.0.1 allow remote authenticated users to execute
60RISK
open
ReferênciaVexDay Proof
SFS EZ Adult Directory - 'directory.php' SQL Injection
CVE-2008-6784webappsphp
SQL injection vulnerability in directory.php in Scripts For Sites (SFS) EZ Adult Directory allows remote attackers to ex
23RISK
open
ReferênciaVexDay Proof
Mini File Host 1.x - Arbitrary '.PHP' File Upload
CVE-2008-6785webappsphp
Unrestricted file upload vulnerability in Mini File Host 1.5 allows remote attackers to execute arbitrary code by upload
23RISK
open
ReferênciaVexDay Proof
Lizardware CMS 0.6.0 - Blind SQL Injection
CVE-2008-6787webappsphp
SQL injection vulnerability in administrator/index.php in Lizardware CMS 0.6.0 and earlier allows remote attackers to ex
23RISK
open
ReferênciaVexDay Proof
XOOPS Module eCal 2.24 - 'display.php' SQL Injection
CVE-2007-1813webappsphp
SQL injection vulnerability in display.php in the eCal 2.24 and earlier module for Xoops allows remote attackers to exec
23RISK
open
ReferênciaVexDay Proof
MindDezign Photo Gallery 2.2 - SQL Injection
CVE-2008-6788webappsphp
SQL injection vulnerability in MindDezign Photo Gallery 2.2, when magic_quotes_gpc is disabled, allows remote attackers
23RISK
open
ReferênciaVexDay Proof
XOOPS Module Core - 'viewcat.php' SQL Injection
CVE-2007-1814webappsphp
SQL injection vulnerability in viewcat.php in the Core module for Xoops allows remote attackers to execute arbitrary SQL
23RISK
open
previouspage 493 / 745next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.