Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,724cataloged exploits
35,724CVEs with public exploitation
24,695lab-tested
22,492 exploits
Referência
CVE-2010-0972
Directory traversal vulnerability in the GCalendar (com_gcalendar) component 2.1.5 for Joomla! allows remote attackers t
43RISK
open
Referência
CVE-2010-2439
Stack-based buffer overflow in MoreAmp allows remote attackers to execute arbitrary code via a long line in a song list
23RISK
open
Referência
CVE-2025-32463
CVE-2025-32463CRITICALunder attack
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
ReferênciaVexDay Proof
MLdonkey 2.9.7 - Arbitrary File Disclosure
CVE-2009-0753remotemultiple
Absolute path traversal vulnerability in MLDonkey 2.8.4 through 2.9.7 allows remote attackers to read arbitrary files vi
23RISK
open
Referência
CVE-2014-0556
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS
60RISK
open
Referência
CVE-2009-3221
Stack-based buffer overflow in Audio Lib Player (ALP) allows remote attackers to execute arbitrary code via a long URL i
23RISK
open
Referência
CVE-2020-5509
PHPGurukul Car Rental Project v1.0 allows Remote Code Execution via an executable file in an upload of a new profile ima
23RISK
open
Referência
CVE-2010-3125
Untrusted search path vulnerability in TeamMate Audit Management Software Suite 8.0 patch 2 allows local users, and poss
23RISK
open
ReferênciaVexDay Proof
PHPLibrary 1.5.3 - 'grid3.lib.php' Remote File Inclusion
CVE-2006-5471webappsphp
PHP remote file inclusion vulnerability in example/lib/grid3.lib.php in Softerra PHP Developer Library 1.5.3 and earlier
23RISK
open
ReferênciaVexDay Proof
FipsCMS 2.1 - 'print.asp' SQL Injection
CVE-2008-2124webappsasp
SQL injection vulnerability in modules/print.asp in fipsASP fipsCMS allows remote attackers to execute arbitrary SQL com
23RISK
open
Referência
CVE-2026-4585
Tiandy Easy7 Integrated Management Platform Configuration ImportSystemConfiguration.jsp os command injection
48RISK
open
Referência
CVE-2010-1044
SQL injection vulnerability in Login.do in ManageEngine OpUtils 5.0 allows remote attackers to execute arbitrary SQL com
23RISK
open
Referência
CVE-2012-2210
The Sony Bravia TV KDL-32CX525 allows remote attackers to cause a denial of service (configuration outage or device cras
23RISK
open
Referência
CVE-2018-17441
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'username' parameter of the addUser
23RISK
open
Referência
CVE-2021-24862
RegistrationMagic < 5.0.1.6 - Admin+ SQL Injection
60RISK
open
Referência
CVE-2018-17443
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'sitename' parameter of the UpdateS
23RISK
open
Referência
CVE-2014-0980
Buffer overflow in Poster Software PUBLISH-iT 3.6d allows remote attackers to execute arbitrary code via a crafted PUI f
50RISK
open
Referência
CVE-2017-14085
Information disclosure vulnerabilities in Trend Micro OfficeScan 11.0 and XG may allow unauthenticated users who can acc
23RISK
open
Referência
CVE-2017-14085
Information disclosure vulnerabilities in Trend Micro OfficeScan 11.0 and XG may allow unauthenticated users who can acc
23RISK
open
Referência
CVE-2026-28517
openDCIM <= 23.04 OS Command Injection via dot Configuration Parameter
63RISK
open
Referência
CVE-2026-28517
openDCIM <= 23.04 OS Command Injection via dot Configuration Parameter
63RISK
open
Referência
CVE-2008-4157
SQL injection vulnerability in groups.php in Vastal I-Tech phpVID 1.1 allows remote attackers to execute arbitrary SQL c
23RISK
open
Referência
CVE-2008-4157
SQL injection vulnerability in groups.php in Vastal I-Tech phpVID 1.1 allows remote attackers to execute arbitrary SQL c
23RISK
open
Referência
CVE-2017-6095
A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/list
23RISK
open
Referência
CVE-2020-6318
A Remote Code Execution vulnerability exists in the SAP NetWeaver (ABAP Server, up to release 7.40) and ABAP Platform (>
48RISK
open
Referência
CVE-2017-2483
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS b
23RISK
open
ReferênciaVexDay Proof
MikroTik RouterOS 3.13 - SNMP write (Set request)
CVE-2008-6976remotehardware
MikroTik RouterOS 3.x through 3.13 and 2.x through 2.9.51 allows remote attackers to modify Network Management System (N
23RISK
open
ReferênciaVexDay Proof
RSSonate - 'xml2rss.php' Remote File Inclusion
CVE-2006-5518webappsphp
Multiple PHP remote file inclusion vulnerabilities in Christopher Fowler (Rhode Island) RSSonate allow remote attackers
23RISK
open
Referência
CVE-2011-0885
A certain Comcast Business Gateway configuration of the SMC SMCD3G-CCR with firmware before 1.4.0.49.2 has a default pas
28RISK
open
Referência
CVE-2018-11505
The Werewolf Online application 0.8.8 for Android allows attackers to discover the Firebase token by reading logcat outp
23RISK
open
previouspage 564 / 750next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.