Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,794cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
22,721 exploits
Referência
CVE-2015-8556
Local privilege escalation vulnerability in the Gentoo QEMU package before 2.5.0-r1.
23RISK
open
ReferênciaVexDay Proof
XOOPS Module resmanager 1.21 - Blind SQL Injection
CVE-2007-2735webappsphp
SQL injection vulnerability in edit_day.php in the ResManager 1.2.1 and earlier module for Xoops allows remote attackers
23RISK
open
ReferênciaVexDay Proof
Achievo 1.1.0 - 'config_atkroot' Remote File Inclusion
CVE-2007-2736webappsphp
PHP remote file inclusion vulnerability in index.php in Achievo 1.1.0 allows remote attackers to execute arbitrary PHP c
23RISK
open
Referência
CVE-2018-16509
An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handlin
60RISK
open
Referência
CVE-2018-3810
Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unau
60RISK
open
Referência
CVE-2009-3023
Buffer overflow in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 6.0 allows remote authen
60RISK
open
ReferênciaVexDay Proof
IMGallery 2.5 - Multiple SQL Injections
CVE-2008-2337webappsphp
Multiple SQL injection vulnerabilities in IMGallery 2.5, when magic_quotes_gpc is disabled, allow remote attackers to ex
23RISK
open
Referência
CVE-2015-8556
Local privilege escalation vulnerability in the Gentoo QEMU package before 2.5.0-r1.
23RISK
open
Referência
CVE-2017-15222
Buffer Overflow vulnerability in Ayukov NFTPD 2.0 and earlier allows remote attackers to execute arbitrary code.
50RISK
open
Referência
CVE-2012-1784
SQL injection vulnerability in MyJobList 0.1.3 allows remote attackers to execute arbitrary SQL commands via the eid par
23RISK
open
Referência
CVE-2017-3599
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Pluggable Auth). Supported versions t
45RISK
open
Referência
CVE-2018-11776
CVE-2018-11776HIGHunder attack
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISK
open
Referência
CVE-2017-0146
CVE-2017-0146HIGHunder attackransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
ReferênciaVexDay Proof
PHPRaider 1.0.7 - 'PHPbb3.functions.php' Remote File Inclusion
CVE-2008-2481webappsphp
PHP remote file inclusion vulnerability in authentication/phpbb3/phpbb3.functions.php in phpRaider 1.0.7 and 1.0.7a, whe
23RISK
open
Referência
CVE-2022-44268
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RISK
open
ReferênciaVexDay Proof
Xomol CMS 1.2 - Authentication Bypass / Local File Inclusion
CVE-2008-2484webappsphp
SQL injection vulnerability in index.php in Xomol CMS 1.20071213, when magic_quotes_gpc is disabled, allows remote attac
23RISK
open
Referência
Ericsson Network Location MPS GMPC21 - Remote Code Execution (RCE) (Metasploit)
CVE-2021-43339webappsmultiple
In Ericsson Network Location before 2021-07-31, it is possible for an authenticated attacker to inject commands via file
23RISK
open
Referência
CVE-2023-33592
Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lf
23RISK
open
Referência
CVE-2019-1821
Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities
78RISK
open
ReferênciaVexDay Proof
Battle.net Clan Script 1.5.x - SQL Injection
CVE-2008-2522webappsphp
SQL injection vulnerability in members.php in Battle.net Clan Script for PHP 1.5.3 and earlier, when magic_quotes_gpc is
23RISK
open
ReferênciaVexDay Proof
QuickUpCMS - Multiple SQL Injections Vulnerabilities
CVE-2008-2530webappsphp
Multiple SQL injection vulnerabilities in Concepts & Solutions QuickUpCMS allow remote attackers to execute arbitrary SQ
23RISK
open
ReferênciaVexDay Proof
Extreme phpBB 3.0.1 - 'functions.php' Remote File Inclusion
CVE-2007-1105webappsphp
PHP remote file inclusion vulnerability in functions.php in Extreme phpBB (aka phpBB Extreme) 3.0.1 allows remote attack
23RISK
open
ReferênciaVexDay Proof
Advanced Image Hosting (AIH) 2.1 - SQL Injection
CVE-2008-2536webappsphp
SQL injection vulnerability in out.php in YABSoft Advanced Image Hosting (AIH) Script 2.1 and earlier allows remote atta
23RISK
open
ReferênciaVexDay Proof
SCO UnixWare Reliant HA 1.1.4 - Local Privilege Escalation
CVE-2008-6558localsco
Untrusted search path vulnerability in (1) hvdisp and (2) rcvm in ReliantHA 1.1.4 in SCO UnixWare 7.1.4 allows local use
23RISK
open
Referência
CVE-2008-2566
Multiple cross-site scripting (XSS) vulnerabilities in PHP Address Book 3.1.5 and earlier allow remote attackers to inje
23RISK
open
ReferênciaVexDay Proof
PHP-Address Book 3.1.5 - SQL Injection / Cross-Site Scripting
CVE-2008-2566webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in PHP Address Book 3.1.5 and earlier allow remote attackers to inje
23RISK
open
ReferênciaVexDay Proof
Joomla! Component SimpleShop 3.4 - SQL Injection
CVE-2008-2568webappsphp
SQL injection vulnerability in the Simple Shop Galore (com_simpleshop) component 3.4 and earlier for Joomla! allows remo
23RISK
open
ReferênciaVexDay Proof
freeSSHd 1.2.1 - (Authenticated) Remote Stack Overflow (PoC)
CVE-2008-2573doswindows
Stack-based buffer overflow in SFTP in freeSSHd 1.2.1 allows remote authenticated users to execute arbitrary code via a
23RISK
open
ReferênciaVexDay Proof
freeSSHd 1.2.1 - (Authenticated) Remote Overflow (SEH)
CVE-2008-2573remotewindows
Stack-based buffer overflow in SFTP in freeSSHd 1.2.1 allows remote authenticated users to execute arbitrary code via a
23RISK
open
ReferênciaVexDay Proof
Joomla! Component JooBlog 0.1.1 - Blind SQL Injection
CVE-2008-2630webappsphp
SQL injection vulnerability in the JooBlog (com_jb2) component 0.1.1 for Joomla! allows remote attackers to execute arbi
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.