Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,620cataloged exploits
35,647CVEs with public exploitation
24,695lab-tested
22,429 exploits
Referência
CVE-2010-1469
Directory traversal vulnerability in the Ternaria Informatica JProject Manager (com_jprojectmanager) component 1.0 for J
38RISK
open
Referência
CVE-2013-5528
Directory traversal vulnerability in the Tomcat administrative web interface in Cisco Unified Communications Manager all
43RISK
open
Referência
CVE-2014-0112
ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which all
60RISK
open
Referência
CVE-2020-25495
A reflected Cross-site scripting (XSS) vulnerability in Xinuo (formerly SCO) Openserver version 5 and 6 allows remote at
38RISK
open
ReferênciaVexDay Proof
Pluxml 0.3.1 - Remote Code Execution
CVE-2007-3432webappsphp
Unrestricted file upload vulnerability in admin/images.php in Pluxml 0.3.1 allows remote attackers to upload and execute
23RISK
open
ReferênciaVexDay Proof
CA BrightStor ARCserve Backup r11.5 - ActiveX Remote Buffer Overflow
CVE-2008-1472remotewindows
Stack-based buffer overflow in the ListCtrl ActiveX Control (ListCtrl.ocx), as used in multiple CA products including Br
50RISK
open
Referência
CVE-2010-4401
languages.inc.php in DynPG CMS 4.2.0 allows remote attackers to obtain sensitive information via a direct request, which
23RISK
open
Referência
CVE-2009-3185
SQL injection vulnerability in plugin.php in the Crazy Star plugin 2.0 for Discuz! allows remote authenticated users to
23RISK
open
Referência
CVE-2020-9372
The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or
23RISK
open
Referência
CVE-2016-9682
The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to two Remote Command Injection vulnerabi
28RISK
open
Referência
CVE-2014-9633
The bdisk.sys driver in COMODO Backup before 4.4.1.23 allows remote attackers to gain privileges via a crafted device ha
23RISK
open
Referência
CVE-2017-9742
The score_opcodes function in opcodes/score7-dis.c in GNU Binutils 2.28 allows remote attackers to cause a denial of ser
23RISK
open
Referência
CVE-2017-9756
The aarch64_ext_ldst_reglist function in opcodes/aarch64-dis.c in GNU Binutils 2.28 allows remote attackers to cause a d
23RISK
open
ReferênciaVexDay Proof
mcGalleryPRO 2006 - 'path_to_folder' Remote File Inclusion
CVE-2006-4720webappsphp
PHP remote file inclusion vulnerability in random2.php in mcGalleryPRO 2006 allows remote attackers to execute arbitrary
23RISK
open
Referência
CVE-2018-19287
XSS in the Ninja Forms plugin before 3.3.18 for WordPress allows Remote Attackers to execute JavaScript via the includes
38RISK
open
Referência
CVE-2010-4557
Buffer overflow in the lm_tcp service in Invensys Wonderware InBatch 8.1 and 9.0, as used in Invensys Foxboro I/A Series
28RISK
open
ReferênciaVexDay Proof
RaidenHTTPD 1.1.49 - 'SoftParserFileXml' Remote Code Execution
CVE-2006-4723remotewindows
PHP remote file inclusion vulnerability in raidenhttpd-admin/slice/check.php in RaidenHTTPD 1.1.49, when register_global
23RISK
open
ReferênciaVexDay Proof
Jasmine CMS 1.0 - SQL Injection / Remote Code Execution
CVE-2007-3313webappsphp
Multiple SQL injection vulnerabilities in Jasmine CMS 1.0 allow remote attackers to execute arbitrary SQL commands via (
23RISK
open
ReferênciaVexDay Proof
BitDefender Online Scanner 8 - ActiveX Heap Overflow
CVE-2007-6189remotewindows
A certain ActiveX control in (1) OScan8.ocx and (2) Oscan81.ocx in BitDefender Online Anti-Virus Scanner 8.0 allows remo
23RISK
open
ReferênciaVexDay Proof
Yahoo! JukeBox MediaGrid - 'AddBitmap()' ActiveX Buffer Overflow
CVE-2008-0625remotewindows
Buffer overflow in the MediaGrid ActiveX control (mediagrid.dll) in Yahoo! Music Jukebox 2.2.2.56 allows remote attacker
23RISK
open
ReferênciaVexDay Proof
Maian Weblog 4.0 - Insecure Cookie Handling
CVE-2008-3318webappsphp
admin/index.php in Maian Weblog 4.0 and earlier allows remote attackers to bypass authentication and gain administrative
23RISK
open
Referência
CVE-2008-4178
SQL injection vulnerability in tr.php in DownlineGoldmine Special Category Addon, Downline Builder Pro, New Addon, and D
23RISK
open
Referência
CVE-2017-14086
Pre-authorization Start Remote Process vulnerabilities in Trend Micro OfficeScan 11.0 and XG may allow unauthenticated u
23RISK
open
Referência
CVE-2017-14086
Pre-authorization Start Remote Process vulnerabilities in Trend Micro OfficeScan 11.0 and XG may allow unauthenticated u
23RISK
open
Referência
CVE-2016-9813
The _parse_pat function in the mpegts parser in GStreamer before 1.10.2 allows remote attackers to cause a denial of ser
23RISK
open
Referência
CVE-2009-3226
SQL injection vulnerability in index.php in AlmondSoft Almond Classifieds Ads Enterprise and Almond Affiliate Network Cl
23RISK
open
Referência
CVE-2018-13042
The 1Password application 6.8 for Android is affected by a Denial Of Service vulnerability. By starting the activity com
23RISK
open
Referência
CVE-2004-1720
The (1) address.html and possibly (2) calendar.html pages in Merak Mail Server 5.2.7 allow remote attackers to gain sens
23RISK
open
Referência
CVE-2014-7910
Multiple unspecified vulnerabilities in Google Chrome before 39.0.2171.65 allow attackers to cause a denial of service o
23RISK
open
ReferênciaVexDay Proof
RunCMS 1.5.2 - 'debug_show.php' SQL Injection
CVE-2007-2539webappsphp
The show_files function in RunCms 1.5.2 and earlier allows remote attackers to obtain sensitive information (file existe
23RISK
open
previouspage 552 / 748next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.