Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,813cataloged exploits
35,788CVEs with public exploitation
24,695lab-tested
22,549 exploits
ReferênciaVexDay Proof
Simple CMS 1.0.3 - 'area' SQL Injection
CVE-2008-0835webappsphp
SQL injection vulnerability in indexen.php in Simple CMS 1.0.3 and earlier allows remote attackers to execute arbitrary
23RISK
open
Referência
CVE-2023-28771
CVE-2023-28771CRITICALunder attack
Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware vers
100RISK
open
Referência
CVE-2014-6332
CVE-2014-6332HIGHunder attack
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RISK
open
Referência
CVE-2014-6332
CVE-2014-6332HIGHunder attack
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RISK
open
Referência
CVE-2010-2334
Directory traversal vulnerability in themes/default/download.php in Yamamah Photo Gallery 1.00, as distributed before 20
23RISK
open
Referência
CVE-2010-2358
PHP remote file inclusion vulnerability in modules/catalog/upload_photo.php in Nakid CMS 0.5.2, when magic_quotes_gpc is
23RISK
open
Referência
CVE-2010-2458
Cross-site scripting (XSS) vulnerability in video.php in 2daybiz Video Community Portal Script 1.0 allows remote attacke
23RISK
open
Referência
CVE-2010-2461
SQL injection vulnerability in storecat.php in JCE-Tech Overstock 1 allows remote attackers to execute arbitrary SQL com
23RISK
open
Referência
CVE-2010-2461
SQL injection vulnerability in storecat.php in JCE-Tech Overstock 1 allows remote attackers to execute arbitrary SQL com
23RISK
open
Referência
CVE-2010-2464
Multiple cross-site scripting (XSS) vulnerabilities in the RSComments (com_rscomments) component 1.0.0 Rev 2 for Joomla!
23RISK
open
ReferênciaVexDay Proof
PHPWebThings 1.4 - 'msg'/'forum' SQL Injection
CVE-2005-4218webappsphp
SQL injection vulnerability in forum.php in PHPWebThings 1.4 allows remote attackers to execute arbitrary SQL commands v
23RISK
open
Referência
CVE-2010-4151
SQL injection vulnerability in misc.php in DeluxeBB 1.3, and possibly earlier, when magic_quotes_gpc is disabled, allows
23RISK
open
Referência
CVE-2022-30333
CVE-2022-30333HIGHunder attackransomware
RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) o
100RISK
open
Referência
CVE-2026-15105
davenardella snap7 ReadVar Request s7_server.cpp PerformFunctionRead out-of-bounds write
33RISK
open
Referência
CVE-2025-12506
Use of Incorrectly-Resolved Name or Reference in GitLab
28RISK
open
Referência
CVE-2026-7492
Missing Authorization in GitLab
33RISK
open
Referência
CVE-2026-12375
Uncanny Automator Pro 7.3.0.5 - Backdoor via Compromised Vendor Update Server
48RISK
open
Referência
CVE-2026-12277
Frontend File Manager Plugin <= 23.6 - Unauthenticated Arbitrary File Deletion via Saved File Metadata Path Traversal
41RISK
open
Referência
CVE-2020-7247
CVE-2020-7247CRITICALunder attack
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISK
open
Referência
CVE-2020-7247
CVE-2020-7247CRITICALunder attack
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISK
open
Referência
CVE-2014-8393
DLL Hijacking vulnerability in CorelDRAW X7, Corel Photo-Paint X7, Corel PaintShop Pro X7, Corel Painter 2015, and Corel
23RISK
open
Referência
CVE-2014-8469
Cross-site scripting (XSS) vulnerability in Guests/Boots in AdminCP in Moxi9 PHPFox before 4 Beta allows remote attacker
23RISK
open
Referência
CVE-2014-8493
ZTE ZXHN H108L with firmware 4.0.0d_ZRQ_GR4 allows remote attackers to modify the CWMP configuration via a crafted reque
23RISK
open
Referência
CVE-2026-11855
Simple Membership < 4.7.5 - Unauthenticated Stored XSS via Stripe Webhook API Version
41RISK
open
Referência
CVE-2026-10830
AllCoach < 1.0.2 - Unauthenticated Account Takeover
41RISK
open
Referência
CVE-2023-32560
An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disrup
78RISK
open
Referência
CVE-2023-32560
An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disrup
78RISK
open
Referência
CVE-2024-6228
WANotifier < 2.6 - Subscriber+ LFI
41RISK
open
Referência
CVE-2026-14789
radareorg radare2 Memory64ListStream mdmp.c stack-based overflow
33RISK
open
Referência
CVE-2020-7209
LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2.
60RISK
open
previouspage 606 / 752next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.