Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,772cataloged exploits
35,760CVEs with public exploitation
24,695lab-tested
22,523 exploits
ReferênciaVexDay Proof
AllMyGuests 0.3.0 - 'AMG_serverpath' Remote File Inclusion
CVE-2007-0172webappsphp
Multiple PHP remote file inclusion vulnerabilities in AllMyGuests 0.3.0 and earlier allow remote attackers to execute ar
23RISK
open
ReferênciaVexDay Proof
Gravity Board X 2.0 Beta - SQL Injection / Cross-Site Scripting
CVE-2008-2997webappsphp
Cross-site scripting (XSS) vulnerability in index.php in Gravity Board X (GBX) 2.0 Beta allows remote attackers to injec
23RISK
open
ReferênciaVexDay Proof
Foxmail 5.0 - 'PunyLib.dll' Remote Stack Overflow
CVE-2004-2719remotewindows
Buffer overflow in the UrlToLocal function in PunyLib.dll of Foxmail 5.0.300 allows remote attackers to execute arbitrar
23RISK
open
Referência
CVE-2021-42325
Froxlor through 0.10.29.1 allows SQL injection in Database/Manager/DbManagerMySQL.php via a custom DB name.
28RISK
open
Referência
CVE-2010-1296
Multiple buffer overflows in Adobe Photoshop CS4 before 11.0.2 allow user-assisted remote attackers to execute arbitrary
28RISK
open
Referência
CVE-2017-8490
The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2,
23RISK
open
Referência
CVE-2026-18615
GL-iNet GL-MT3000 wg-server.so Native Plugin glc wg-server.generate_publickey command injection
48RISK
open
Referência
CVE-2018-5315
The Wachipi WP Events Calendar plugin 1.0 for WordPress has SQL Injection via the event_id parameter to event.php.
23RISK
open
Referência
CVE-2018-5315
The Wachipi WP Events Calendar plugin 1.0 for WordPress has SQL Injection via the event_id parameter to event.php.
23RISK
open
Referência
CVE-2015-3314
SQL injection vulnerability in WordPress Tune Library plugin before 1.5.5.
23RISK
open
Referência
CVE-2015-3314
SQL injection vulnerability in WordPress Tune Library plugin before 1.5.5.
23RISK
open
Referência
CVE-2013-4092
The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows context-dependent att
23RISK
open
Referência
CVE-2016-1247
The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages before 1.4.6-1ubuntu3.6 on Ubuntu 14.04 LTS
23RISK
open
Referência
CVE-2016-1247
The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages before 1.4.6-1ubuntu3.6 on Ubuntu 14.04 LTS
23RISK
open
Referência
CVE-2014-2559
Multiple cross-site request forgery (CSRF) vulnerabilities in twitget.php in the Twitget plugin before 3.3.3 for WordPre
23RISK
open
Referência
CVE-2012-3414
Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before
23RISK
open
Referência
CVE-2021-47964
Schlix CMS 2.2.6-6 Remote Code Execution via core.blockmanager
41RISK
open
Referência
CVE-2014-9412
Multiple cross-site scripting (XSS) vulnerabilities in NetIQ Access Manager (NAM) 4.x before 4.1 allow remote attackers
23RISK
open
ReferênciaVexDay Proof
East Wind Software - 'advdaudio.ocx 1.5.1.1' Local Buffer Overflow
CVE-2007-2576localwindows
Buffer overflow in the East Wind Software advdaudio.ocx 1.5.1.1 ActiveX control allows user-assisted remote attackers to
23RISK
open
ReferênciaVexDay Proof
March Networks DVR 3204 - Logfile Information Disclosure
CVE-2007-6638remotehardware
March Networks DVR 3204 stores sensitive information under the web root with insufficient access control, which allows r
28RISK
open
ReferênciaVexDay Proof
Joomla! Component beamospetition - SQL Injection
CVE-2008-3132webappsphp
SQL injection vulnerability in the beamospetition (com_beamospetition) component for Joomla! allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
BareNuked CMS 1.1.0 - Arbitrary Add Admin
CVE-2008-3133webappsphp
SQL injection vulnerability in admin/index.php in BareNuked CMS 1.1.0, when magic_quotes_gpc is disabled, allows remote
23RISK
open
Referência
CVE-2009-2852
WP-Syntax plugin 0.9.1 and earlier for Wordpress, with register_globals enabled, allows remote attackers to execute arbi
23RISK
open
Referência
CVE-2010-2349
H264WebCam 3.7 allows remote attackers to cause a denial of service (crash) via a long URI in a GET request, which trigg
23RISK
open
Referência
CVE-2009-3574
Tuniac 090517c allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a lon
23RISK
open
Referência
CVE-2018-16071
A use after free in WebRTC in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap
23RISK
open
Referência
CVE-2010-4170
The staprun runtime tool in SystemTap 1.3 does not properly clear the environment before executing modprobe, which allow
38RISK
open
Referência
CVE-2010-4170
The staprun runtime tool in SystemTap 1.3 does not properly clear the environment before executing modprobe, which allow
38RISK
open
Referência
CVE-2022-4447
Fontsy <= 1.8.6 - Multiple Unauthenticated SQLi
63RISK
open
Referência
CVE-2017-0299
The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2,
23RISK
open
previouspage 581 / 751next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.