Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,449cataloged exploits
35,552CVEs with public exploitation
24,695lab-tested
22,367 exploits
Referência
CVE-2012-0391
CVE-2012-0391CRITICALunder attack
The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during
100RISK
open
ReferênciaVexDay Proof
Mumbo Jumbo Media OP4 - Blind SQL Injection
CVE-2008-6477webappsphp
SQL injection vulnerability in Mumbo Jumbo Media OP4 allows remote attackers to execute arbitrary SQL commands via the i
23RISK
open
ReferênciaVexDay Proof
Joomla! Component versioning 1.0.2 - 'id' SQL Injection
CVE-2008-6481webappsphp
SQL injection vulnerability in the Versioning component (com_versioning) 1.0.2 in Joomla! and Mambo allows remote attack
23RISK
open
Referência
TSPlus 16.0.0.0 - Remote Work Insecure Credential storage
CVE-2023-31069remotewindows
An issue was discovered in TSplus Remote Access through 16.0.2.14. Credentials are stored as cleartext within the HTML s
23RISK
open
Referência
CVE-2023-31468
An issue was discovered in Inosoft VisiWin 7 through 2022-2.1 (Runtime RT7.3 RC3 20221209.5). The "%PROGRAMFILES(X86)%\I
41RISK
open
Referência
CVE-2017-12629
Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction wi
60RISK
open
ReferênciaVexDay Proof
Joomla! Component Flash Tree Gallery 1.0 - Remote File Inclusion
CVE-2008-6482webappsphp
PHP remote file inclusion vulnerability in admin.treeg.php in the Flash Tree Gallery (com_treeg) component 1.0 for Jooml
28RISK
open
Referência
CVE-2015-8556
Local privilege escalation vulnerability in the Gentoo QEMU package before 2.5.0-r1.
28RISK
open
ReferênciaVexDay Proof
Geeklog 2 - 'BaseView.php' Remote File Inclusion
CVE-2007-0810webappsphp
PHP remote file inclusion vulnerability in MVCnPHP/BaseView.php in GeekLog 2 and earlier allows remote attackers to exec
23RISK
open
ReferênciaVexDay Proof
Woltlab Burning Board Lite 1.0.2pl3e - 'pms.php' SQL Injection
CVE-2007-0812webappsphp
SQL injection vulnerability in pms.php in Woltlab Burning Board (wBB) Lite 1.0.2pl3e and earlier allows remote authentic
23RISK
open
ReferênciaVexDay Proof
Mole Group Taxi Calc Dist Script - Authentication Bypass
CVE-2008-6484webappsphp
SQL injection vulnerability in login.php in Mole Group Taxi Map Script (aka Taxi Calc Dist Script) allows remote attacke
23RISK
open
Referência
CVE-2012-1775
Stack-based buffer overflow in VideoLAN VLC media player before 2.0.1 allows remote attackers to execute arbitrary code
50RISK
open
ReferênciaVexDay Proof
VidiScript (Avatar) - Arbitrary File Upload
CVE-2008-6518webappsphp
Unrestricted file upload vulnerability in the profile feature in VidiScript allows registered remote authenticated users
23RISK
open
ReferênciaVexDay Proof
Xitami Web Server 2.5c2 - LRWP Processing Format String (PoC)
CVE-2008-6519doswindows
Format string vulnerability in Xitami Web Server 2.2a through 2.5c2, and possibly other versions, allows remote attacker
23RISK
open
Referência
CVE-2023-40044
CVE-2023-40044CRITICALunder attackransomware
WS_FTP Server Ad Hoc Transfer Module .NET Deserialization Vulnerability
100RISK
open
Referência
CVE-2020-17463
CVE-2020-17463CRITICALunder attack
FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.
100RISK
open
Referência
CVE-2017-8464
CVE-2017-8464HIGHunder attack
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 201
100RISK
open
Referência
CVE-2017-8464
CVE-2017-8464HIGHunder attack
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 201
100RISK
open
ReferênciaVexDay Proof
μTorrent (uTorrent) 1.6 build 474 - 'announce' Key Remote Heap Overflow
CVE-2007-0927remotewindows
Heap-based buffer overflow in uTorrent 1.6 allows remote attackers to execute arbitrary code via a torrent file with a c
35RISK
open
ReferênciaVexDay Proof
OpenInvoice 0.9 - Arbitrary Change User Password
CVE-2008-6523webappsphp
auth.php in openInvoice 0.90 beta and earlier allows remote attackers to bypass authentication and gain privileges by se
23RISK
open
ReferênciaVexDay Proof
Total Video Player 1.20 - '.m3u' File Local Stack Buffer Overflow
CVE-2007-0949localwindows
Stack-based buffer overflow in iTinySoft Studio Total Video Player 1.03, and possibly earlier, allows remote attackers t
28RISK
open
ReferênciaVexDay Proof
BosClassifieds - 'cat_id' SQL Injection
CVE-2008-6526webappsphp
SQL injection vulnerability in index.php in BosDev BosClassifieds allows remote attackers to execute arbitrary SQL comma
23RISK
open
ReferênciaVexDay Proof
GO4I.NET ASP Forum 1.0 - SQL Injection
CVE-2008-6527webappsphp
SQL injection vulnerability in forum.asp in GO4I.NET ASP Forum 1.0 allows remote attackers to execute arbitrary SQL comm
23RISK
open
Referência
CVE-2019-12725
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RISK
open
ReferênciaVexDay Proof
Jupiter CMS 1.1.5 - Arbitrary File Upload
CVE-2007-0972webappsphp
Unrestricted file upload vulnerability in modules/emoticons.php in Jupiter CMS 1.1.5 allows remote attackers to upload a
23RISK
open
ReferênciaVexDay Proof
TmaxSoft JEUS - Alternate Data Streams File Disclosure
CVE-2008-6528remotewindows
NTFS TmaxSoft JEUS 5 before Fix 26 allows remote attackers to read the source code for scripts by appending ::$DATA to t
23RISK
open
ReferênciaVexDay Proof
PayPal eStore - Admin Password Change
CVE-2008-6535webappsphp
admin/settings.php in PayPal eStores allows remote attackers to bypass intended access restrictions and change the admin
23RISK
open
ReferênciaVexDay Proof
ActSoft DVD-Tools - 'dvdtools.ocx' Remote Buffer Overflow
CVE-2007-0976remotewindows
Buffer overflow in the ActSoft DVD-Tools ActiveX control (dvdtools.ocx) allows remote attackers to execute arbitrary cod
23RISK
open
ReferênciaVexDay Proof
WEBBDOMAIN Quiz 1.02 - Authentication Bypass
CVE-2008-6626webappsphp
SQL injection vulnerability in getin.php in WEBBDOMAIN Quiz 1.02 and earlier allows remote attackers to execute arbitrar
23RISK
open
Referência
Thruk Monitoring Web Interface 3.06 - Path Traversal
CVE-2023-34096MEDIUMwebappsperl
Thruk has Path Traversal Vulnerability in panorama.pm
45RISK
open
previouspage 504 / 746next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.