Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,449cataloged exploits
35,552CVEs with public exploitation
24,695lab-tested
22,367 exploits
Referência
CVE-2022-31854
Codoforum v5.1 was discovered to contain an arbitrary file upload vulnerability via the logo change option in the admin
50RISK
open
Referência
CVE-2009-4855
SQL injection vulnerability in index.php in TYPO3 4.0 allows remote attackers to execute arbitrary SQL commands via the
23RISK
open
Referência
CVE-2009-4860
SQL injection vulnerability in demo.php in Typing Pal 1.0 and earlier allows remote attackers to execute arbitrary SQL c
23RISK
open
ReferênciaVexDay Proof
Web-MeetMe 3.0.3 - 'play.php' Remote File Disclosure
CVE-2007-6215webappsphp
Multiple directory traversal vulnerabilities in play.php in Web-MeetMe 3.0.3 allow remote attackers to read arbitrary fi
23RISK
open
Referência
CVE-2018-19864
NUUO NVRmini2 Network Video Recorder firmware through 3.9.1 allows remote attackers to execute arbitrary code or cause a
28RISK
open
Referência
CVE-2022-3038
CVE-2022-3038HIGHunder attack
Use after free in Network Service in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially explo
76RISK
open
Referência
CVE-2017-3061
Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability in the SWF parser
28RISK
open
Referência
CVE-2017-3076
Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the MPEG-4 AVC
28RISK
open
Referência
CVE-2009-4870
Multiple SQL injection vulnerabilities in login.php in PHPCityPortal allow remote attackers to execute arbitrary SQL com
23RISK
open
Referência
CVE-2019-13577
SnmpAdm.exe in MAPLE WBT SNMP Administrator v2.0.195.15 has an Unauthenticated Remote Buffer Overflow via a long string
28RISK
open
Referência
CVE-2017-15367
Bacula-web before 8.0.0-rc2 is affected by multiple SQL Injection vulnerabilities that could allow an attacker to access
28RISK
open
ReferênciaVexDay Proof
Joomla! Component Recly!Competitions 1.0.0 - Multiple Remote File Inclusions
CVE-2008-5790webappsphp
Multiple PHP remote file inclusion vulnerabilities in the Recly!Competitions (com_competitions) component 1.0 for Joomla
35RISK
open
ReferênciaVexDay Proof
Rayzz Script 2.0 - Local/Remote File Inclusion
CVE-2007-6229webappsphp
PHP remote file inclusion vulnerability in common/classes/class_HeaderHandler.lib.php in Rayzz Script 2.0 allows remote
23RISK
open
ReferênciaVexDay Proof
tellmatic 1.0.7 - Multiple Remote File Inclusions
CVE-2007-6231webappsphp
Multiple PHP remote file inclusion vulnerabilities in tellmatic 1.0.7 allow remote attackers to execute arbitrary PHP co
23RISK
open
ReferênciaVexDay Proof
Surgemail 39e-1 - (Authenticated) IMAP Remote Buffer Overflow (Denial of Service) (PoC)
CVE-2008-7182doswindows
Buffer overflow in the IMAP service in NetWin Surgemail 3.9e, and possibly other versions before 3.9g2, allows remote au
28RISK
open
Referência
CVE-2021-46418
An unauthorized file creation vulnerability in Telesquare TLR-2855KS6 via PUT method can allow creation of CGI scripts.
43RISK
open
Referência
CVE-2013-3961
SQL injection vulnerability in edit_event.php in Simple PHP Agenda before 2.2.9 allows remote authenticated users to exe
23RISK
open
Referência
CVE-2013-3961
SQL injection vulnerability in edit_event.php in Simple PHP Agenda before 2.2.9 allows remote authenticated users to exe
23RISK
open
ReferênciaVexDay Proof
Joomla! Component OnlineFlashQuiz 1.0.2 - Remote File Inclusion
CVE-2008-1682webappsphp
PHP remote file inclusion vulnerability in quiz/common/db_config.inc.php in the Online FlashQuiz (com_onlineflashquiz) 1
28RISK
open
Referência
CVE-2009-4872
Multiple SQL injection vulnerabilities in globepersonnel_login.asp in Logoshows BBS 2.0 allow remote attackers to execut
23RISK
open
ReferênciaVexDay Proof
VMware - COM API ActiveX Remote Buffer Overflow (PoC)
CVE-2008-3892doswindows
Buffer overflow in a certain ActiveX control in the COM API in VMware Workstation 5.5.x before 5.5.8 build 108000, VMwar
28RISK
open
Referência
CVE-2021-40380
An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. cameralist.cgi and set
28RISK
open
Referência
CVE-2013-1360
An Authentication Bypass vulnerability exists in DELL SonicWALL Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7
28RISK
open
Referência
CVE-2016-9565
MagpieRSS, as used in the front-end component in Nagios Core before 4.2.2 might allow remote attackers to read or write
28RISK
open
Referência
CVE-2016-9565
MagpieRSS, as used in the front-end component in Nagios Core before 4.2.2 might allow remote attackers to read or write
28RISK
open
Referência
CVE-2014-7864
Multiple SQL injection vulnerabilities in the FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine OpMan
28RISK
open
Referência
CVE-2009-2311
SQL injection vulnerability in the rGallery plugin 1.2.3 for WoltLab Burning Board (WBB3) allows remote attackers to exe
23RISK
open
Referência
CVE-2009-2313
Directory traversal vulnerability in index.php in Jinzora Media Jukebox 2.8 and earlier allows remote attackers to inclu
23RISK
open
Referência
CVE-2013-1592
A Buffer Overflow vulnerability exists in the Message Server service _MsJ2EE_AddStatistics() function when sending speci
28RISK
open
Referência
CVE-2016-6367
CVE-2016-6367HIGHunder attack
Cisco Adaptive Security Appliance (ASA) Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices allows loc
76RISK
open
previouspage 514 / 746next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.