Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,533cataloged exploits
35,607CVEs with public exploitation
24,695lab-tested
22,407 exploits
Referência
CVE-2019-6706
Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example, a crash outcome might be achieved by an attack
28RISK
open
Referência
CVE-2018-18065
_set_key in agent/helpers/table_container.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by
28RISK
open
Referência
CVE-2016-3237
Kerberos in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server
28RISK
open
Referência
CVE-2010-0761
SQL injection vulnerability in index.php in CommodityRentals Books/eBooks Rentals Script allows remote attackers to exec
23RISK
open
Referência
CVE-2018-19908
An issue was discovered in MISP 2.4.9x before 2.4.99. In app/Model/Event.php (the STIX 1 import code), an unescaped file
28RISK
open
Referência
CVE-2010-0761
SQL injection vulnerability in index.php in CommodityRentals Books/eBooks Rentals Script allows remote attackers to exec
23RISK
open
Referência
CVE-2017-14244
An authentication bypass vulnerability on iBall Baton ADSL2+ Home Router FW_iB-LR7011A_1.0.2 devices potentially allows
28RISK
open
Referência
CVE-2017-2361
An issue was discovered in certain Apple products. macOS before 10.12.3 is affected. The issue involves the "Help Viewer
28RISK
open
Referência
CVE-2020-10770
A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using
50RISK
open
Referência
CVE-2009-0695
hagent.exe in Wyse Device Manager (WDM) 4.7.x does not require authentication for commands, which allows remote attacker
50RISK
open
Referência
CVE-2013-0008
win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7
43RISK
open
ReferênciaVexDay Proof
Microsoft Internet Explorer 6 - 'mshtml.dll' Null Pointer Dereference
CVE-2007-0811doswindows
Microsoft Internet Explorer 6.0 SP1 on Windows 2000, and 6.0 SP2 on Windows XP, allows remote attackers to cause a denia
28RISK
open
ReferênciaVexDay Proof
QuickTime Player 7.3.1.70 - 'RTSP' Remote Buffer Overflow
CVE-2008-0234remotewindows
Buffer overflow in Apple Quicktime Player 7.3.1.70 and other versions before 7.4.1, when RTSP tunneling is enabled, allo
28RISK
open
Referência
CVE-2015-2993
SysAid Help Desk before 15.2 does not properly restrict access to certain functionality, which allows remote attackers t
50RISK
open
Referência
CVE-2017-8535
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Serve
28RISK
open
Referência
CVE-2010-4227
The xdrDecodeString function in XNFS.NLM in Novell Netware 6.5 before SP8 allows remote attackers to cause a denial of s
28RISK
open
Referência
CVE-2010-0803
SQL injection vulnerability in the jVideoDirect (com_jvideodirect) component 1.1 RC3b for Joomla! allows remote attacker
23RISK
open
Referência
CVE-2015-8396
Integer overflow in the ImageRegionReader::ReadIntoBuffer function in MediaStorageAndFileFormat/gdcmImageRegionReader.cx
28RISK
open
Referência
CVE-2015-8396
Integer overflow in the ImageRegionReader::ReadIntoBuffer function in MediaStorageAndFileFormat/gdcmImageRegionReader.cx
28RISK
open
Referência
CVE-2016-1768
QuickTime in Apple OS X before 10.11.4 allows remote attackers to execute arbitrary code or cause a denial of service (m
28RISK
open
Referência
CVE-2020-0938
CVE-2020-0938HIGHunder attack
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly
83RISK
open
Referência
CVE-2018-5234
The Norton Core router prior to v237 may be susceptible to a command injection exploit. This is a type of attack in whic
28RISK
open
Referência
CVE-2012-6554
functions/html_to_text.php in the Chat module before 1.5.2 for activeCollab allows remote authenticated users to execute
43RISK
open
Referência
CVE-2018-11220
Bitmain Antminer D3, L3+, and S9 devices allow Remote Command Execution via the system restore function.
28RISK
open
Referência
CVE-2010-4931
Directory traversal vulnerability in maincore.php in PHP-Fusion allows remote attackers to include and execute arbitrary
28RISK
open
Referência
CVE-2016-4136
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsof
28RISK
open
ReferênciaVexDay Proof
TaskFreak! 0.6.1 - SQL Injection
CVE-2008-0270webappsphp
SQL injection vulnerability in index.php in TaskFreak! 0.6.1 and earlier allows remote authenticated users to execute ar
23RISK
open
Referência
CVE-2010-0943
Directory traversal vulnerability in the JA Showcase (com_jashowcase) component for Joomla! allows remote attackers to r
43RISK
open
Referência
CVE-2010-0943
Directory traversal vulnerability in the JA Showcase (com_jashowcase) component for Joomla! allows remote attackers to r
43RISK
open
Referência
CVE-2018-11412
In the Linux kernel 4.13 through 4.16.11, ext4_read_inline_data() in fs/ext4/inline.c performs a memcpy with an untruste
28RISK
open
previouspage 541 / 747next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.