Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,620cataloged exploits
35,647CVEs with public exploitation
24,695lab-tested
22,429 exploits
Referência
CVE-2026-6590
ComfyUI Model Preview Endpoint model_manager.py get_model_preview path traversal
33RISK
open
Referência
CVE-2010-3132
Untrusted search path vulnerability in Adobe Dreamweaver CS5 11.0 build 4916, build 4909, and probably other versions, a
28RISK
open
Referência
CVE-2010-3139
Untrusted search path vulnerability in Microsoft Windows Progman Group Converter (grpconv.exe) allows local users, and p
28RISK
open
Referência
CVE-2010-3141
Untrusted search path vulnerability in Microsoft PowerPoint 2010 allows local users, and possibly remote attackers, to e
28RISK
open
Referência
CVE-2023-27100
Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22
48RISK
open
Referência
CVE-2023-27100
Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22
48RISK
open
Referência
CVE-2016-5399
The bzread function in ext/bz2/bz2.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attac
23RISK
open
Referência
CVE-2009-4974
Directory traversal vulnerability in box_display.php in TotalCalendar 2.4 allows remote attackers to read arbitrary file
23RISK
open
Referência
CVE-2019-16294
SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execution or denial of service via Unicode ch
23RISK
open
Referência
CVE-2014-1982
The administrative interface in Allied Telesis AT-RG634A ADSL Broadband router 3.3+, iMG624A firmware 3.5, iMG616LH firm
23RISK
open
ReferênciaVexDay Proof
SunOS Release 5.11 snv_101b - Remote IPv6 Crash
CVE-2009-0304dossolaris
The kernel in Sun Solaris 10 and 11 snv_101b, and OpenSolaris before snv_108, allows remote attackers to cause a denial
23RISK
open
Referência
CVE-2016-8526
Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to an XML external entities (XXE). XXEs are a
23RISK
open
Referência
CVE-2018-9038
Monstra CMS 3.0.4 allows remote attackers to delete files via an admin/index.php?id=filesmanager&delete_dir=./&path=uplo
23RISK
open
Referência
CVE-2018-8813
Open redirect vulnerability in the login[redirect] parameter login functionality in WolfCMS 0.8.3.1 allows remote attack
23RISK
open
Referência
CVE-2019-13358
lib/DocumentToText.php in OpenCats before 0.9.4-3 has XXE that allows remote users to read files on the underlying opera
28RISK
open
Referência
CVE-2022-38840
cgi-bin/xmlstatus.cgi in Güralp MAN-EAM-0003 3.2.4 is vulnerable to an XML External Entity (XXE) issue via XML file uplo
56RISK
open
ReferênciaVexDay Proof
WiClear 0.10 - 'path' Remote File Inclusion
CVE-2006-5506webappsphp
Multiple PHP remote file inclusion vulnerabilities in WiClear 0.10 allow remote attackers to execute arbitrary PHP code
28RISK
open
Referência
CVE-2019-7181
Buffer Overflow vulnerability in myQNAPcloud Connect 1.3.3.0925 and earlier could allow remote attackers to crash the pr
23RISK
open
Referência
CVE-2019-7181
Buffer Overflow vulnerability in myQNAPcloud Connect 1.3.3.0925 and earlier could allow remote attackers to crash the pr
23RISK
open
Referência
CVE-2017-9872
The III_dequantize_sample function in layer3.c in mpglib, as used in libmpgdecoder.a in LAME 3.99.5 and other products,
23RISK
open
Referência
CVE-2010-3146
Multiple untrusted search path vulnerabilities in Microsoft Groove 2007 SP2 allow local users to gain privileges via a T
28RISK
open
ReferênciaVexDay Proof
PHPProfiles 4.5.2 Beta - 'body_comm.inc.php' Remote File Inclusion
CVE-2008-1051webappsphp
PHP remote file inclusion vulnerability in include/body_comm.inc.php in phpProfiles 4.5.2 BETA allows remote attackers t
28RISK
open
ReferênciaVexDay Proof
PHP-Nuke Module Kose_Yazilari - 'artid' SQL Injection
CVE-2008-1053webappsphp
Multiple SQL injection vulnerabilities in the Kose_Yazilari module for PHP-Nuke allow remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
GoodTech SSH - 'SSH_FXP_OPEN' Remote Buffer Overflow
CVE-2008-4726remotewindows
Stack-based buffer overflow in the SFTP subsystem in GoodTech SSH 6.4 allows remote authenticated users to execute arbit
35RISK
open
Referência
CVE-2009-4983
Multiple cross-site scripting (XSS) vulnerabilities in Silurus Classifieds 1.0 allow remote attackers to inject arbitrar
23RISK
open
Referência
CVE-2018-15576
An issue was discovered in EasyLogin Pro through 1.3.0. Encryptor.php contains an unserialize call that can be exploited
23RISK
open
Referência
CVE-2018-15576
An issue was discovered in EasyLogin Pro through 1.3.0. Encryptor.php contains an unserialize call that can be exploited
23RISK
open
ReferênciaVexDay Proof
Neostrada Livebox Router - Remote Network Down (PoC)
CVE-2008-6497doswindows
The Neostrada Livebox ADSL Router allows remote attackers to cause a denial of service (network outage) via multiple HTT
23RISK
open
Referência
CVE-2008-3408
Stack-based buffer overflow in CoolPlayer 2.18, and possibly other versions, allows user-assisted remote attackers to ex
23RISK
open
Referência
CVE-2017-0259
The Windows kernel in Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703,
23RISK
open
previouspage 548 / 748next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.