Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,772cataloged exploits
35,760CVEs with public exploitation
24,695lab-tested
22,492 exploits
Referência
CVE-2009-3811
Stack-based buffer overflow in Music Tag Editor 1.61 build 212 allows remote attackers to execute arbitrary code via an
23RISK
open
Referência
CVE-2023-0455
Unrestricted Upload of File with Dangerous Type in unilogies/bumsys
41RISK
open
Referência
CVE-2011-0498
Stack-based buffer overflow in Nokia Multimedia Player 1.00.55.5010, and possibly other versions, allows user-assisted r
23RISK
open
Referência
CVE-2017-2479
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud b
23RISK
open
ReferênciaVexDay Proof
Devalcms 1.4a - Cross-Site Scripting / Remote Code Execution
CVE-2008-6982webappsphp
Cross-site scripting (XSS) vulnerability in index.php in devalcms 1.4a allows remote attackers to inject arbitrary web s
38RISK
open
ReferênciaVexDay Proof
SubEdit Player build 4066 - subtitle Buffer Overflow (PoC)
CVE-2008-1973doswindows
Heap-based buffer overflow in SubEdit Player build 4056 and 4066 allows remote attackers to cause a denial of service (c
23RISK
open
Referência
CVE-2014-0780
CVE-2014-0780CRITICALunder attack
InduSoft Web Studio Path Traversal
100RISK
open
ReferênciaVexDay Proof
WinAsm Studio 5.1.5.0 - Local Heap Overflow (PoC)
CVE-2009-1040doswindows
Buffer overflow in WinAsm Studio 5.1.5.0 allows user-assisted remote attackers to execute arbitrary code via a crafted p
23RISK
open
Referência
CVE-2010-2920
Directory traversal vulnerability in the Foobla Suggestions (com_foobla_suggestions) component 1.5.1.2 for Joomla! allow
38RISK
open
Referência
CVE-2016-4997
The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux
38RISK
open
Referência
CVE-2016-4997
The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux
38RISK
open
ReferênciaVexDay Proof
DoSePa 1.0.4 - 'textview.php' Information Disclosure
CVE-2006-6028webappsphp
Directory traversal vulnerability in textview.php in Anton Vlasov DoSePa 1.0.4 allows remote attackers to read arbitrary
23RISK
open
Referência
CVE-2019-8924
XAMPP through 5.6.8 allows XSS via the cds-fpdf.php interpret or titel parameter. NOTE: This product is discontinued.
23RISK
open
Referência
CVE-2019-8924
XAMPP through 5.6.8 allows XSS via the cds-fpdf.php interpret or titel parameter. NOTE: This product is discontinued.
23RISK
open
Referência
CVE-2010-4230
Stack-based buffer overflow in a certain ActiveX control for the Camtron CMNC-200 Full HD IP Camera and TecVoz CMNC-200
23RISK
open
Referência
CVE-2015-3673
Admin Framework in Apple OS X before 10.10.4 does not properly restrict the location of writeconfig clients, which allow
38RISK
open
Referência
CVE-2007-6478
Stack-based buffer overflow in Rosoft Media Player 4.1.7, 4.1.8, and possibly earlier versions allows remote attackers t
23RISK
open
Referência
CVE-2014-0871
RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allows remote att
23RISK
open
ReferênciaVexDay Proof
WordPress Plugin dmsguestbook 1.7.0 - Multiple Vulnerabilities
CVE-2008-0616webappsphp
SQL injection vulnerability in the administration panel in the DMSGuestbook 1.7.0 plugin for WordPress allows remote aut
23RISK
open
ReferênciaVexDay Proof
AS-GasTracker 1.0.0 - Insecure Cookie Handling
CVE-2008-2269webappsphp
AustinSmoke GasTracker (AS-GasTracker) 1.0.0 allows remote attackers to bypass authentication and gain privileges by set
23RISK
open
ReferênciaVexDay Proof
Feedback and Rating Script 1.0 - 'detail.php' SQL Injection
CVE-2008-2277webappsphp
SQL injection vulnerability in detail.php in Feedback and Rating Script 1.0 allows remote attackers to execute arbitrary
23RISK
open
Referência
CVE-2018-10655
DLPnpAuditor.exe in DeviceLock Plug and Play Auditor (freeware) 5.72 has a Unicode Buffer Overflow (SEH).
28RISK
open
Referência
CVE-2018-10655
DLPnpAuditor.exe in DeviceLock Plug and Play Auditor (freeware) 5.72 has a Unicode Buffer Overflow (SEH).
28RISK
open
Referência
CVE-2010-1046
Multiple SQL injection vulnerabilities in index.php in Rostermain 1.1 and earlier allow remote attackers to execute arbi
23RISK
open
Referência
CVE-2009-3484
Stack-based buffer overflow in Core FTP 2.1 build 1612 allows user-assisted remote attackers to execute arbitrary code v
23RISK
open
Referência
CVE-2014-0995
The Standalone Enqueue Server in SAP Netweaver 7.20, 7.01, and earlier allows remote attackers to cause a denial of serv
28RISK
open
Referência
CVE-2012-4864
Oreans WinLicense 2.1.8.0 allows remote attackers to cause a denial of service (memory corruption and crash) and possibl
23RISK
open
Referência
CVE-2012-4864
Oreans WinLicense 2.1.8.0 allows remote attackers to cause a denial of service (memory corruption and crash) and possibl
23RISK
open
Referência
CVE-2015-7250
Absolute path traversal vulnerability in cgi-bin/webproc on ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE
28RISK
open
Referência
CVE-2012-1933
Multiple PHP remote file inclusion vulnerabilities in Newscoop 3.5.x before 3.5.5 and 4 before RC4, when register_global
23RISK
open
previouspage 570 / 750next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.