Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,900cataloged exploits
35,840CVEs with public exploitation
24,695lab-tested
22,600 exploits
Referência
CVE-2026-78145
CTFd __init__.py _is_safe_url redirect
30RISK
open
Referência
CVE-2012-4901
Cross-site scripting (XSS) vulnerability in Template CMS 2.1.1 and earlier allows remote attackers to inject arbitrary w
23RISK
open
ReferênciaVexDay Proof
PowerClan 1.14a - Authentication Bypass
CVE-2009-0707webappsphp
SQL injection vulnerability in admin/index.php in PowerClan 1.14a allows remote attackers to execute arbitrary SQL comma
23RISK
open
Referência
CVE-2009-5102
SQL injection vulnerability in default.asp in ATCOM Netvolution 1.0 ASP allows remote attackers to execute arbitrary SQL
23RISK
open
Referência
CVE-2015-5754
Race condition in runner in Install.framework in the Install Framework Legacy component in Apple OS X before 10.10.5 all
23RISK
open
Referência
CVE-2010-2133
SQL injection vulnerability in contact.php in My Little Forum allows remote attackers to execute arbitrary SQL commands
23RISK
open
Referência
CVE-2010-2133
SQL injection vulnerability in contact.php in My Little Forum allows remote attackers to execute arbitrary SQL commands
23RISK
open
Referência
CVE-2026-78144
code-projects Barangay Resident Profiling Management System Boarder Management boarders.php authorization
30RISK
open
ReferênciaVexDay Proof
Realty Web-Base 1.0 - Authentication Bypass
CVE-2009-1658webappsphp
Multiple SQL injection vulnerabilities in admin/admin.php in Realty Webware Technologies Realty Web-Base 1.0 allow remot
23RISK
open
Referência
CVE-2009-3181
Directory traversal vulnerability in Anantasoft Gazelle CMS 1.0 allows remote attackers to overwrite arbitrary files via
23RISK
open
Referência
CVE-2026-78143
code-projects Barangay Resident Profiling Management System Resident Search Functionality residents.php sql injection
30RISK
open
ReferênciaVexDay Proof
PHP Blue Dragon CMS 2.9 - Remote File Inclusion
CVE-2006-2392webappsphp
PHP remote file inclusion vulnerability in public_includes/pub_popup/popup_finduser.php in PHP Blue Dragon Platinum 2.8.
23RISK
open
Referência
CVE-2016-5809
An issue was discovered on Schneider Electric IONXXXX series power meters ION73XX series, ION75XX series, ION76XX series
23RISK
open
Referência
CVE-2016-9950
An issue was discovered in Apport before 2.20.4. There is a path traversal issue in the Apport crash file "Package" and
28RISK
open
Referência
CVE-2026-78142
code-projects Barangay Resident Profiling Management System Restore/Delete archived_records.php authorization
30RISK
open
Referência
CVE-2010-1583
SQL injection vulnerability in the loadByKey function in the TznDbConnection class in tzn_mysql.php in Tirzen (aka TZN)
23RISK
open
Referência
CVE-2026-10053
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab
41RISK
open
Referência
CVE-2010-3154
Untrusted search path vulnerability in Adobe Extension Manager CS5 5.0.298 allows local users, and possibly remote attac
28RISK
open
ReferênciaVexDay Proof
CMS NetCat 3.12 - Multiple Vulnerabilities
CVE-2008-5742webappsphp
Multiple open redirect vulnerabilities in AIST NetCat 3.12 and earlier allow remote attackers to redirect users to arbit
23RISK
open
Referência
CVE-2026-78112
itsourcecode Hospital Management System Project in PHP viewservicetype.php sql injection
33RISK
open
ReferênciaVexDay Proof
PHPfan 3.3.4 - 'init.php' Remote File Inclusion
CVE-2008-6251webappsphp
PHP remote file inclusion vulnerability in includes/init.php in phpFan 3.3.4 allows remote attackers to execute arbitrar
23RISK
open
Referência
CVE-2012-10044
MobileCartly 1.0 savepage.php Arbitrary File Creation
63RISK
open
Referência
CVE-2012-10044
MobileCartly 1.0 savepage.php Arbitrary File Creation
63RISK
open
Referência
CVE-2012-10044
MobileCartly 1.0 savepage.php Arbitrary File Creation
63RISK
open
Referência
CVE-2010-2909
SQL injection vulnerability in ttvideo.php in the TTVideo (com_ttvideo) component 1.0 for Joomla! allows remote attacker
23RISK
open
ReferênciaVexDay Proof
Intel 2200BG 802.11 - disassociation packet Kernel Memory Corruption
CVE-2007-0686doswindows
The Intel 2200BG 802.11 Wireless Mini-PCI driver 9.0.3.9 (w29n51.sys) allows remote attackers to cause a denial of servi
23RISK
open
Referência
CVE-2026-77116
Brave Popup Builder < 0.8.6 - Subscriber+ Unpublished Popup Disclosure via Preview
33RISK
open
Referência
CVE-2026-77115
Brave Popup Builder < 0.8.6 - Unauthenticated Reflected XSS via UTM Parameters
41RISK
open
ReferênciaVexDay Proof
OpenInvoice 0.9 - Arbitrary Change User Password
CVE-2008-6524webappsphp
resetpass.php in openInvoice 0.90 beta and earlier allows remote authenticated users to change the passwords of arbitrar
23RISK
open
Referência
CVE-2015-5736
The Fortishield.sys driver in Fortinet FortiClient before 5.2.4 allows local users to execute arbitrary code with kernel
23RISK
open
previouspage 639 / 754next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.