Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,533cataloged exploits
35,607CVEs with public exploitation
24,695lab-tested
22,407 exploits
Referência
CVE-2016-9722
IBM QRadar 7.2 and 7.3 specifies permissions for a security-critical resource in a way that allows that resource to be r
43RISK
open
Referência
CVE-2014-9241
Multiple cross-site scripting (XSS) vulnerabilities in MyBB (aka MyBulletinBoard) 1.8.x before 1.8.2 allow remote attack
23RISK
open
Referência
CVE-2019-9053
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISK
open
Referência
CVE-2014-5289
Buffer overflow in Senkas Kolibri 2.0 allows remote attackers to execute arbitrary code via a long URI in a POST request
28RISK
open
Referência
CVE-2010-3894
Stack-based buffer overflow in the Java_com_ibm_es_oss_CryptionNative_ESEncrypt function in /opt/IBM/es/lib/libffq.crypt
28RISK
open
ReferênciaVexDay Proof
xeCMS 1.0.0 RC2 - Insecure Cookie Handling
CVE-2008-6714webappsphp
admin.php in xeCMS 1.0.0 RC2 and earlier allows remote attackers to bypass authentication and access the admin panel by
28RISK
open
Referência
CVE-2022-1768
RSVPMaker <= 9.3.2 - Unauthenticated SQL Injection
68RISK
open
ReferênciaVexDay Proof
Online Fantasy Football League (OFFL) 0.2.6 - Remote File Inclusion
CVE-2007-4809webappsphp
Multiple PHP remote file inclusion vulnerabilities in Online Fantasy Football League (OFFL) 0.2.6 allow remote attackers
35RISK
open
Referência
CVE-2016-5677
NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.
28RISK
open
Referência
CVE-2012-5862
Sinapsi eSolar Hard-Coded Password
53RISK
open
ReferênciaVexDay Proof
Hannon Hill Cascade Server - (Authenticated) Command Execution
CVE-2009-1088webappscgi
Hannon Hill Cascade Server 5.7 and other versions allows remote authenticated users to execute arbitrary programs or Jav
28RISK
open
ReferênciaVexDay Proof
Citadel SMTP 7.10 - Remote Overflow
CVE-2008-0394remotewindows
Buffer overflow in Citadel SMTP server 7.10 and earlier allows remote attackers to execute arbitrary code via a long RCP
28RISK
open
ReferênciaVexDay Proof
MySpace Uploader - 'MySpaceUploader.ocx 1.0.0.4' Remote Buffer Overflow
CVE-2008-0659remotewindows
Stack-based buffer overflow in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.5.70 and earlier, as used i
35RISK
open
ReferênciaVexDay Proof
LoveCMS 1.6.2 Final - Remote Code Execution
CVE-2008-3509webappsphp
LoveCMS 1.6.2 does not require administrative authentication for (1) addblock.php, (2) blocks.php, and (3) themes.php in
23RISK
open
ReferênciaVexDay Proof
Solaris 9 PortBind - XDR-DECODE 'taddr2uaddr()' Remote Denial of Service
CVE-2008-4619dossolaris
The RPC subsystem in Sun Solaris 9 allows remote attackers to cause a denial of service (daemon crash) via a crafted req
28RISK
open
ReferênciaVexDay Proof
WordPress MU < 1.3.2 - 'active_plugins' Code Execution
CVE-2008-5695webappsphp
wp-admin/options.php in WordPress MU before 1.3.2, and WordPress 2.3.2 and earlier, does not properly validate requests
28RISK
open
Referência
CVE-2017-17739
The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) has directory traversal via the /storage.html
28RISK
open
Referência
WIMAX SWC-5100W Firmware V(1.11.0.1 :1.9.9.4) - Authenticated RCE
CVE-2023-27826HIGHremotehardware
SeowonIntech SWC 5100W WIMAX Bootloader 1.18.19.0, HW 0.0.7.0, and FW 1.11.0.1, 1.9.9.4 are vulnerable to OS Command Inj
46RISK
open
Referência
CVE-2010-1981
Directory traversal vulnerability in the Fabrik (com_fabrik) component 2.0 for Joomla! allows remote attackers to read a
43RISK
open
Referência
CVE-2010-1981
Directory traversal vulnerability in the Fabrik (com_fabrik) component 2.0 for Joomla! allows remote attackers to read a
43RISK
open
Referência
CVE-2023-0159
Extensive VC Addons for WPBakery page builder < 1.9.1 - Unauthenticated RCE
50RISK
open
Referência
CVE-2013-10069
D-Link Devices Unauthenticated RCE
68RISK
open
Referência
CVE-2013-10069
D-Link Devices Unauthenticated RCE
68RISK
open
Referência
CVE-2013-10069
D-Link Devices Unauthenticated RCE
68RISK
open
ReferênciaVexDay Proof
EgyPlus 7ml 1.0.1 - Authentication Bypass
CVE-2009-2168CRITICALwebappsphp
cpanel/login.php in EgyPlus 7ammel (aka 7ml) 1.0.1 and earlier sends a redirect to the web browser but does not exit whe
53RISK
open
Referência
CVE-2020-3118
CVE-2020-3118HIGHunder attack
Cisco IOS XR Software Cisco Discovery Protocol Format String Vulnerability
76RISK
open
Referência
CVE-2015-6912
Synology Video Station before 1.5-0763 allows remote attackers to execute arbitrary shell commands via shell metacharact
28RISK
open
Referência
CVE-2019-17132
vBulletin through 5.5.4 mishandles custom avatars.
28RISK
open
ReferênciaVexDay Proof
Pixaria Gallery 1.x - 'class.Smarty.php' Remote File Inclusion
CVE-2007-2457webappsphp
PHP remote file inclusion vulnerability in resources/includes/class.Smarty.php in Pixaria Gallery before 1.4.3 allows re
28RISK
open
Referência
CVE-2018-8468
An elevation of privilege vulnerability exists when Windows, allowing a sandbox escape, aka "Windows Elevation of Privil
28RISK
open
previouspage 540 / 747next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.