Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,449cataloged exploits
35,552CVEs with public exploitation
24,695lab-tested
22,367 exploits
Referência
CVE-2020-16040
Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially explo
60RISK
open
Referência
CVE-2017-13209
In the ServiceManager::add function in the hardware service manager, there is an insecure permissions check based on the
23RISK
open
Referência
CVE-2020-16040
Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially explo
60RISK
open
Referência
CVE-2017-13216
In ashmem_ioctl of ashmem.c, there is an out-of-bounds write due to insufficient locking when accessing asma. This could
23RISK
open
Referência
CVE-2020-17456
SEOWON INTECH SLC-130 And SLR-120S devices allow Remote Code Execution via the ipAddr parameter to the system_log.cgi pa
60RISK
open
Referência
CVE-2017-13258
In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead
23RISK
open
Referência
CVE-2017-13258
In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead
23RISK
open
Referência
CVE-2017-13794
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RISK
open
Referência
CVE-2011-5283
Cross-site scripting (XSS) vulnerability in the web management interface in httpd/cgi-bin/ipinfo.cgi in Smoothwall Expre
23RISK
open
Referência
CVE-2011-5283
Cross-site scripting (XSS) vulnerability in the web management interface in httpd/cgi-bin/ipinfo.cgi in Smoothwall Expre
23RISK
open
Referência
CVE-2026-16070
Brizy - Page Builder < 2.8.19 - Contributor+ Template Type Update via IDOR
28RISK
open
Referência
CVE-2026-16069
Brizy - Page Builder < 2.8.19 - Contributor+ Stored XSS via Featured Image Focal Point
33RISK
open
Referência
CVE-2026-16068
Brizy - Page Builder < 2.8.19 - Author+ Stored XSS via brizy_set_project Global Project Code Asset
28RISK
open
Referência
CVE-2020-25762
An issue was discovered in SourceCodester Seat Reservation System 1.0. The file admin_class.php does not perform input v
28RISK
open
Referência
CVE-2020-25762
An issue was discovered in SourceCodester Seat Reservation System 1.0. The file admin_class.php does not perform input v
28RISK
open
Referência
CVE-2020-26567
An issue was discovered on D-Link DSR-250N before 3.17B devices. The CGI script upgradeStatusReboot.cgi can be accessed
28RISK
open
ReferênciaVexDay Proof
Xcode OpenBase 10.0.0 (OSX) - Symlink Privilege Escalation
CVE-2006-5851localosx
openexec in OpenBase SQL before 10.0.1 allows local users to create arbitrary files via a symlink attack on the /tmp/out
23RISK
open
ReferênciaVexDay Proof
Xcode OpenBase 10.0.0 (OSX) - Unsafe System Call Privilege Escalation
CVE-2006-5852localosx
Untrusted search path vulnerability in openexec in OpenBase SQL before 10.0.1 allows local users to gain privileges via
23RISK
open
Referência
Genexis Platinum 4410 Router 2.1 - UPnP Credential Exposure
CVE-2020-25988remotehardware
UPNP Service listening on port 5555 in Genexis Platinum 4410 Router V2.1 (P4410-V2–1.34H) has an action 'X_GetAccess' wh
23RISK
open
ReferênciaVexDay Proof
UPublisher 1.0 - 'viewarticle.asp' SQL Injection
CVE-2006-5888webappsasp
SQL injection vulnerability in viewarticle.asp in Superfreaker Studios UPublisher 1.0 allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
BrewBlogger 1.3.1 - 'printLog.php' SQL Injection
CVE-2006-5889webappsphp
SQL injection vulnerability in printLog.php in BrewBlogger (BB) 1.3.1 allows remote attackers to execute arbitrary SQL c
23RISK
open
ReferênciaVexDay Proof
AspPired2Poll 1.0 - 'MoreInfo.asp' SQL Injection
CVE-2006-5892webappsasp
SQL injection vulnerability in MoreInfo.asp in The Net Guys ASPired2Poll 1.0 and earlier allows remote attackers to exec
23RISK
open
ReferênciaVexDay Proof
StoryStream 4.0 - 'baseDir' Remote File Inclusion
CVE-2006-5893webappsphp
Multiple PHP remote file inclusion vulnerabilities in iWonder Designs Storystream 0.4.0.0 allow remote attackers to exec
23RISK
open
ReferênciaVexDay Proof
Rama CMS 0.68 - Cookie: lang Local File Inclusion
CVE-2006-5894webappsphp
Directory traversal vulnerability in lang.php in Rama CMS 0.68 and earlier, when register_globals is enabled, allows rem
23RISK
open
ReferênciaVexDay Proof
EncapsCMS 0.3.6 - '/core/core.php' Remote File Inclusion
CVE-2006-5895webappsphp
PHP remote file inclusion vulnerability in core/core.php in EncapsCMS 0.3.6 allows remote attackers to execute arbitrary
23RISK
open
Referência
CVE-2026-14820
Quiz And Survey Master < 11.1.3 - Unauthenticated User Enumeration and Password Oracle via Quiz Login
33RISK
open
ReferênciaVexDay Proof
Helix Server 11.0.1 (Windows 2000 SP4) - Remote Heap Overflow
CVE-2006-6026remotewindows
Heap-based buffer overflow in Real Networks Helix Server and Helix Mobile Server before 11.1.3, and Helix DNA Server 11.
28RISK
open
ReferênciaVexDay Proof
Powies pForum 1.29a - 'editpoll.php' SQL Injection
CVE-2006-6038webappsphp
SQL injection vulnerability in editpoll.php in Powie's PHP Forum (pForum) 1.29a and earlier allows remote attackers to e
23RISK
open
ReferênciaVexDay Proof
XMPlay 3.3.0.4 - '.M3U' Filename Local Buffer Overflow
CVE-2006-6063localwindows
Stack-based buffer overflow in Un4seen XMPlay 3.3.0.5 and earlier allows remote attackers to execute arbitrary code via
50RISK
open
Referência
CVE-2026-12979
FunnelKit < 3.15.0.6 - Admin+ Arbitrary File Deletion via Path Traversal in Template Importer
33RISK
open
previouspage 519 / 746next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.