Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,533cataloged exploits
35,607CVEs with public exploitation
24,695lab-tested
22,407 exploits
Referência
CVE-2012-6081
Multiple unrestricted file upload vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action
50RISK
open
Referência
CVE-2016-2385
Heap-based buffer overflow in the encode_msg function in encode_msg.c in the SEAS module in Kamailio (formerly OpenSER a
35RISK
open
Referência
CVE-2014-4141
Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service
35RISK
open
ReferênciaVexDay Proof
virtue news - SQL Injection / Cross-Site Scripting
CVE-2009-2020webappsphp
Cross-site scripting (XSS) vulnerability in news_detail.php in Virtue News Manager allows remote attackers to inject arb
23RISK
open
Referência
CVE-2009-4597
Multiple SQL injection vulnerabilities in index.php in PHP Inventory 1.2 allow (1) remote authenticated users to execute
23RISK
open
Referência
CVE-2015-0065
Microsoft Word 2007 SP3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruptio
35RISK
open
ReferênciaVexDay Proof
GuppY 4.5.16 - Remote Command Execution
CVE-2007-5845webappsphp
Directory traversal vulnerability in error.php in GuppY 4.6.3, 4.5.16, and earlier allows remote attackers to include an
23RISK
open
ReferênciaVexDay Proof
WorkSimple 1.2.1 - Remote File Inclusion / Sensitive Data Disclosure
CVE-2008-5764webappsphp
PHP remote file inclusion vulnerability in calendar.php in WorkSimple 1.2.1, when register_globals is enabled, allows re
35RISK
open
Referência
CVE-2011-5052
Stack-based buffer overflow in CoCSoft Stream Down 6.8.0 allows remote web servers to execute arbitrary code via a long
50RISK
open
Referência
CVE-2017-16995
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RISK
open
Referência
CVE-2017-16995
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RISK
open
Referência
CVE-2017-16995
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RISK
open
Referência
CVE-2015-0040
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory co
35RISK
open
Referência
CVE-2017-0561
A remote code execution vulnerability in the Broadcom Wi-Fi firmware could enable a remote attacker to execute arbitrary
28RISK
open
Referência
CVE-2017-0561
A remote code execution vulnerability in the Broadcom Wi-Fi firmware could enable a remote attacker to execute arbitrary
28RISK
open
Referência
CVE-2019-15715
MantisBT before 1.3.20 and 2.22.1 allows Post Authentication Command Injection, leading to Remote Code Execution.
35RISK
open
ReferênciaVexDay Proof
Joomla! Component flash fun! 1.0 - Remote File Inclusion
CVE-2007-4955webappsphp
PHP remote file inclusion vulnerability in admin.joomlaflashfun.php in the Flash Fun! (com_joomlaflashfun) 1.0 component
28RISK
open
Referência
CVE-2015-8046
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and
28RISK
open
Referência
CVE-2018-6396
SQL Injection exists in the Google Map Landkarten through 4.2.3 component for Joomla! via the cid or id parameter in a l
28RISK
open
ReferênciaVexDay Proof
Joomla! Component Feederator 1.0.5 - Multiple Remote File Inclusions
CVE-2008-5789webappsphp
Multiple PHP remote file inclusion vulnerabilities in the Recly Interactive Feederator (com_feederator) component 1.0.5
35RISK
open
ReferênciaVexDay Proof
campus virtual-lms - Cross-Site Scripting / SQL Injection
CVE-2009-2150webappsphp
Multiple cross-site request forgery (CSRF) vulnerabilities in Campus Virtual-LMS allow (1) remote attackers to hijack th
23RISK
open
Referência
CVE-2009-4598
SQL injection vulnerability in the JPhoto (com_jphoto) component 1.0 for Joomla! allows remote attackers to execute arbi
23RISK
open
Referência
CVE-2009-1699
The XSL stylesheet implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for i
28RISK
open
Referência
CVE-2017-11517
Stack-based buffer overflow in GCoreServer.exe in the server in Geutebrueck Gcore 1.3.8.42 and 1.4.2.37 allows remote at
43RISK
open
Referência
CVE-2019-1150
Microsoft Graphics Remote Code Execution Vulnerability
46RISK
open
Referência
CVE-2019-1150
Microsoft Graphics Remote Code Execution Vulnerability
46RISK
open
Referência
CVE-2019-7274
Optergy Proton/Enterprise devices allow Authenticated File Upload with Code Execution as root.
28RISK
open
Referência
CVE-2018-12327
Stack-based buffer overflow in ntpq and ntpdc of NTP version 4.2.8p11 allows an attacker to achieve code execution or es
28RISK
open
Referência
CVE-2024-6366
User Profile Builder < 3.11.8 - Unauthenticated Media Upload
68RISK
open
Referência
CVE-2024-12847
NETGEAR DGN setup.cgi OS Command Injection
68RISK
open
previouspage 534 / 747next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.