Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,533cataloged exploits
35,607CVEs with public exploitation
24,695lab-tested
22,407 exploits
ReferênciaVexDay Proof
ZeroCMS 1.0 Alpha - Arbitrary File Upload / SQL Injection
CVE-2008-0233webappsphp
Unrestricted file upload vulnerability in Zero CMS 1.0 Alpha and earlier allows remote attackers to bypass intended acce
23RISK
open
ReferênciaVexDay Proof
QuickTime Player 7.3.1.70 - 'RTSP' Buffer Overflow (PoC)
CVE-2008-0234doswindows
Buffer overflow in Apple Quicktime Player 7.3.1.70 and other versions before 7.4.1, when RTSP tunneling is enabled, allo
28RISK
open
Referência
CVE-2016-8581
A persistent XSS vulnerability exists in the User-Agent header of the login process of AlienVault OSSIM and USM before 5
43RISK
open
Referência
CVE-2010-0763
SQL injection vulnerability in index.php in CommodityRentals Vacation Rental Software allows remote attackers to execute
23RISK
open
Referência
CVE-2012-4284
A Privilege Escalation vulnerability exists in Viscosity 1.4.1 on Mac OS X due to a path name validation issue in the se
50RISK
open
Referência
CVE-2012-4284
A Privilege Escalation vulnerability exists in Viscosity 1.4.1 on Mac OS X due to a path name validation issue in the se
50RISK
open
Referência
CVE-2017-15049
The ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 does not properly sanitize user input when c
28RISK
open
Referência
CVE-2017-15049
The ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 does not properly sanitize user input when c
28RISK
open
Referência
CVE-2019-1912
Cisco Small Business 220 Series Smart Switches Authentication Bypass Vulnerability
53RISK
open
Referência
CVE-2019-5722
An issue was discovered in portier vision 4.4.4.2 and 4.4.4.6. Due to a lack of user input validation in parameter handl
23RISK
open
Referência
CVE-2010-5278
Directory traversal vulnerability in manager/controllers/default/resource/tvs.php in MODx Revolution 2.0.2-pl, and possi
43RISK
open
Referência
CVE-2009-2574
index.php in MiniTwitter 0.2 beta allows remote authenticated users to modify certain options of arbitrary accounts via
23RISK
open
Referência
CVE-2013-6810
The server in Brocade Network Advisor before 12.1.0, as used in EMC Connectrix Manager Converged Network Edition (CMCNE)
28RISK
open
Referência
CVE-2013-6810
The server in Brocade Network Advisor before 12.1.0, as used in EMC Connectrix Manager Converged Network Edition (CMCNE)
28RISK
open
Referência
CVE-2010-0764
SQL injection vulnerability in index.php in KuwaitPHP eSmile allows remote attackers to execute arbitrary SQL commands v
23RISK
open
Referência
CVE-2010-0765
fipsForum 2.6 stores sensitive information under the web root with insufficient access control, which allows remote atta
23RISK
open
Referência
CVE-2017-3730
Bad (EC)DHE parameters cause a client crash
35RISK
open
Referência
CVE-2019-25224
WP Database Backup < 5.2 - Unauthenticated OS Command Injection
68RISK
open
Referência
CVE-2018-15140
Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authent
28RISK
open
Referência
CVE-2018-13784
PrestaShop before 1.6.1.20 and 1.7.x before 1.7.3.4 mishandles cookie encryption in Cookie.php, Rinjdael.php, and Blowfi
28RISK
open
Referência
CVE-2018-13784
PrestaShop before 1.6.1.20 and 1.7.x before 1.7.3.4 mishandles cookie encryption in Cookie.php, Rinjdael.php, and Blowfi
28RISK
open
Referência
CVE-2012-4412
Integer overflow in string/strcoll_l.c in the GNU C Library (aka glibc or libc6) 2.17 and earlier allows context-depende
28RISK
open
Referência
CVE-2009-4615
SQL injection vulnerability in review.php in MYRE Holiday Rental Manager allows remote attackers to execute arbitrary SQ
23RISK
open
Referência
CVE-2020-15492
An issue was discovered in INNEO Startup TOOLS 2017 M021 12.0.66.3784 through 2018 M040 13.0.70.3804. The sut_srv.exe we
28RISK
open
Referência
CVE-2017-6315
Astaro Security Gateway (aka ASG) 7 allows remote attackers to execute arbitrary code via a crafted request to index.plx
28RISK
open
Referência
CVE-2016-1713
Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger
43RISK
open
Referência
CVE-2010-0951
SQL injection vulnerability in go_target.php in dev4u CMS allows remote attackers to execute arbitrary SQL commands via
23RISK
open
ReferênciaVexDay Proof
Agares phpAutoVideo 2.21 - 'articlecat' SQL Injection (1)
CVE-2008-0262webappsphp
SQL injection vulnerability in includes/articleblock.php in Agares PhpAutoVideo 2.21 allows remote attackers to execute
23RISK
open
Referência
CVE-2017-6971
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow remote authenticated users to execute arbitrary comma
28RISK
open
Referência
RPi-Jukebox-RFID 2.8.0 - Remote Command Execution
CVE-2025-10327MEDIUMwebappsmultiple
MiczFlor RPi-Jukebox-RFID shuffle.php os command injection
38RISK
open
previouspage 537 / 747next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.