Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,533cataloged exploits
35,607CVEs with public exploitation
24,695lab-tested
22,407 exploits
Referência
CVE-2021-29003
Genexis PLATINUM 4410 2.1 P4410-V2-1.28 devices allow remote attackers to execute arbitrary code via shell metacharacter
35RISK
open
Referência
CVE-2014-9312
Unrestricted File Upload vulnerability in Photo Gallery 1.2.5.
50RISK
open
Referência
CVE-2020-1147
CVE-2020-1147HIGHunder attack
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the softwar
100RISK
open
Referência
CVE-2020-1147
CVE-2020-1147HIGHunder attack
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the softwar
100RISK
open
ReferênciaVexDay Proof
PHPSlash 0.8.1.1 - Remote Code Execution
CVE-2009-0517webappsphp
Eval injection vulnerability in index.php in phpSlash 0.8.1.1 and earlier allows remote attackers to execute arbitrary P
35RISK
open
Referência
CVE-2018-15535
/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 uses external input to construct a pathname
50RISK
open
Referência
CVE-2019-0803
CVE-2019-0803HIGHunder attackransomware
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
83RISK
open
Referência
CVE-2011-2386
VisiWaveReport.exe in AZO Technologies, Inc. VisiWave Site Survey before 2.1.9 allows user-assisted remote attackers to
50RISK
open
Referência
CVE-2017-0145
CVE-2017-0145HIGHunder attackransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Referência
CVE-2019-13344
An authentication bypass vulnerability in the CRUDLab WP Like Button plugin through 1.6.0 for WordPress allows unauthent
35RISK
open
Referência
CVE-2015-8426
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RISK
open
Referência
CVE-2023-36844
CVE-2023-36844MEDIUMunder attack
Junos OS: EX Series: A PHP vulnerability in J-Web allows an unauthenticated attacker to control important environment variables
100RISK
open
ReferênciaVexDay Proof
VIDEOSCRIPT.us - Authentication Bypass
CVE-2009-1804webappsphp
Multiple SQL injection vulnerabilities in admin/index.php in VideoScript.us YouTube Video Script allow remote attackers
23RISK
open
ReferênciaVexDay Proof
PicoFlat CMS 0.4.14 - 'index.php' Remote File Inclusion
CVE-2007-5390webappsphp
PHP remote file inclusion vulnerability in index.php in PicoFlat CMS 0.4.14 and earlier allows remote attackers to execu
23RISK
open
ReferênciaVexDay Proof
CuteNews 1.1.1 - 'html.php' Remote Code Execution
CVE-2008-4557webappsphp
plugins/wacko/highlight/html.php in Strawberry in CuteNews.ru 1.1.1 (aka Strawberry) allows remote attackers to execute
35RISK
open
Referência
CVE-2017-11155
An information exposure vulnerability in index.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remot
35RISK
open
Referência
CVE-2022-29298
SolarView Compact ver.6.00 allows attackers to access sensitive files via directory traversal.
50RISK
open
Referência
CVE-2009-3503
Multiple SQL injection vulnerabilities in search.aspx in BPowerHouse BPHolidayLettings 1.0 allow remote attackers to exe
23RISK
open
Referência
CVE-2009-3510
SQL injection vulnerability in viewListing.php in linkSpheric 0.74 Beta 6 allows remote attackers to execute arbitrary S
23RISK
open
Referência
CVE-2009-3514
Multiple SQL injection vulnerabilities in d.net CMS allow remote attackers to execute arbitrary SQL commands via (1) the
23RISK
open
Referência
CVE-2009-3528
SQL injection vulnerability in Profile.php in MyMsg 1.0.3 allows remote authenticated users to execute arbitrary SQL com
23RISK
open
Referência
CVE-2009-3534
Directory traversal vulnerability in index.php in LionWiki 3.0.3, when magic_quotes_gpc is disabled, allows remote attac
23RISK
open
ReferênciaVexDay Proof
PBEmail 7 - ActiveX Edition Insecure Method
CVE-2007-5446remotewindows
Absolute path traversal vulnerability in a certain ActiveX control in PBEmail7Ax.dll in PBEmail 7 ActiveX Edition allows
23RISK
open
Referência
CVE-2020-11698
An issue was discovered in Titan SpamTitan 7.07. Improper input sanitization of the parameter community on the page snmp
60RISK
open
Referência
CVE-2016-0111
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a
35RISK
open
Referência
CVE-2017-8558
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on 32-bit versions of Micr
35RISK
open
Referência
CVE-2016-3225
The SMB server component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
50RISK
open
Referência
CVE-2017-10366
Vulnerability in the PeopleSoft Enterprise PT PeopleTools component of Oracle PeopleSoft Products (subcomponent: Perform
35RISK
open
Referência
CVE-2015-2468
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Office for Mac 2011, Office fo
28RISK
open
Referência
CVE-2016-0108
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory co
35RISK
open
previouspage 529 / 747next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.