Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,528cataloged exploits
35,606CVEs with public exploitation
24,695lab-tested
22,407 exploits
Referência
CVE-2018-6396
SQL Injection exists in the Google Map Landkarten through 4.2.3 component for Joomla! via the cid or id parameter in a l
28RISK
open
ReferênciaVexDay Proof
Joomla! Component Feederator 1.0.5 - Multiple Remote File Inclusions
CVE-2008-5789webappsphp
Multiple PHP remote file inclusion vulnerabilities in the Recly Interactive Feederator (com_feederator) component 1.0.5
35RISK
open
ReferênciaVexDay Proof
campus virtual-lms - Cross-Site Scripting / SQL Injection
CVE-2009-2150webappsphp
Multiple cross-site request forgery (CSRF) vulnerabilities in Campus Virtual-LMS allow (1) remote attackers to hijack th
23RISK
open
Referência
CVE-2009-4598
SQL injection vulnerability in the JPhoto (com_jphoto) component 1.0 for Joomla! allows remote attackers to execute arbi
23RISK
open
Referência
CVE-2016-0998
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows
28RISK
open
Referência
CVE-2016-0998
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows
28RISK
open
Referência
CVE-2017-5173
An Improper Neutralization of Special Elements (in an OS command) issue was discovered in Geutebruck IP Camera G-Cam/EFD
28RISK
open
Referência
CVE-2018-6794
Suricata before 4.0.4 is prone to an HTTP detection bypass vulnerability in detect.c and stream-tcp.c. If a malicious se
28RISK
open
Referência
CVE-2015-7648
Adobe Flash Player before 18.0.0.255 and 19.x before 19.0.0.226 on Windows and OS X and before 11.2.202.540 on Linux all
28RISK
open
Referência
CVE-2019-9810
Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check
28RISK
open
Referência
CVE-2009-4686
Cross-site scripting (XSS) vulnerability in account.php in phplemon AdQuick 2.2.1 allows remote attackers to inject arbi
23RISK
open
Referência
CVE-2020-14011
Lansweeper 6.0.x through 7.2.x has a default installation in which the admin password is configured for the admin accoun
28RISK
open
ReferênciaVexDay Proof
Distinct TFTP 3.10 - Writable Directory Traversal Execution (Metasploit)
CVE-2012-6664CRITICALwebappswindows
Multiple directory traversal vulnerabilities in the TFTP Server in Distinct Intranet Servers 3.10 and earlier allow remo
68RISK
open
Referência
CVE-2017-0901
RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potenti
28RISK
open
Referência
CVE-2015-1730
Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory cor
28RISK
open
Referência
CVE-2022-4101
Images Optimize and Upload CF7 <= 2.1.4 - Unauthenticated Arbitrary File Deletion
53RISK
open
Referência
CVE-2014-6363
vbscript.dll in Microsoft VBScript 5.6 through 5.8, as used with Internet Explorer 6 through 11 and other products, allo
28RISK
open
Referência
CVE-2013-6720
Directory traversal vulnerability in download.php in the Passive Capture Application (PCA) web console in IBM Tealeaf CX
28RISK
open
Referência
CVE-2016-3324
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service
28RISK
open
Referência
CVE-2014-1912
Buffer overflow in the socket.recvfrom_into function in Modules/socketmodule.c in Python 2.5 before 2.7.7, 3.x before 3.
28RISK
open
Referência
CVE-2020-3153
CVE-2020-3153MEDIUMunder attackransomware
Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability
83RISK
open
Referência
CVE-2020-3153
CVE-2020-3153MEDIUMunder attackransomware
Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability
83RISK
open
Referência
CVE-2022-28079
College Management System v1.0 was discovered to contain a SQL injection vulnerability via the course_code parameter.
43RISK
open
Referência
CVE-2009-3976
Buffer overflow in Labtam ProFTP 2.9 allows remote FTP servers to cause a denial of service (application crash) or execu
43RISK
open
Referência
CVE-2016-6897
Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.
43RISK
open
Referência
CVE-2018-7171
Directory traversal vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to share the contents of a
28RISK
open
Referência
CVE-2018-7171
Directory traversal vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to share the contents of a
28RISK
open
ReferênciaVexDay Proof
Fuzzylime CMS 3.03a - Local Inclusion / Arbitrary File Corruption
CVE-2009-2177webappsphp
code/display.php in fuzzylime (cms) 3.03a and earlier, when magic_quotes_gpc is disabled, allows remote attackers to con
23RISK
open
Referência
CVE-2015-2467
Microsoft Office 2007 SP3 allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Offic
28RISK
open
Referência
CVE-2009-2233
The admin interface in AWScripts.com Gallery Search Engine 1.5 allows remote attackers to bypass authentication and gain
23RISK
open
previouspage 526 / 747next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.