Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,056cataloged exploits
35,925CVEs with public exploitation
24,695lab-tested
22,640 exploits
Referência
TP-Link Router AX50 firmware 210730 - Remote Code Execution (RCE) (Authenticated)
CVE-2022-30075remotehardware
In TP-Link Router AX50 firmware 210730 and older, import of a malicious backup file via web interface can lead to remote
35RISK
open
Referência
CVE-2012-1604
Cross-site scripting (XSS) vulnerability in NextBBS 0.6 allows remote attackers to inject arbitrary web script or HTML v
23RISK
open
Referência
CVE-2011-10011
WeBid 1.0.2 converter.php Remote PHP Code Injection
63RISK
open
Referência
CVE-2011-10011
WeBid 1.0.2 converter.php Remote PHP Code Injection
63RISK
open
Referência
CVE-2011-10011
WeBid 1.0.2 converter.php Remote PHP Code Injection
63RISK
open
Referência
CVE-2010-1855
SQL injection vulnerability in auktion.php in Pay Per Watch & Bid Auktions System allows remote attackers to execute arb
23RISK
open
Referência
CVE-2010-1855
SQL injection vulnerability in auktion.php in Pay Per Watch & Bid Auktions System allows remote attackers to execute arb
23RISK
open
Referência
CVE-2026-78145
CTFd __init__.py _is_safe_url redirect
33RISK
open
Referência
CVE-2012-4901
Cross-site scripting (XSS) vulnerability in Template CMS 2.1.1 and earlier allows remote attackers to inject arbitrary w
23RISK
open
ReferênciaVexDay Proof
PowerClan 1.14a - Authentication Bypass
CVE-2009-0707webappsphp
SQL injection vulnerability in admin/index.php in PowerClan 1.14a allows remote attackers to execute arbitrary SQL comma
23RISK
open
Referência
CVE-2009-5102
SQL injection vulnerability in default.asp in ATCOM Netvolution 1.0 ASP allows remote attackers to execute arbitrary SQL
23RISK
open
Referência
CVE-2015-5754
Race condition in runner in Install.framework in the Install Framework Legacy component in Apple OS X before 10.10.5 all
23RISK
open
Referência
CVE-2010-2133
SQL injection vulnerability in contact.php in My Little Forum allows remote attackers to execute arbitrary SQL commands
23RISK
open
Referência
CVE-2010-2133
SQL injection vulnerability in contact.php in My Little Forum allows remote attackers to execute arbitrary SQL commands
23RISK
open
ReferênciaVexDay Proof
Realty Web-Base 1.0 - Authentication Bypass
CVE-2009-1658webappsphp
Multiple SQL injection vulnerabilities in admin/admin.php in Realty Webware Technologies Realty Web-Base 1.0 allow remot
23RISK
open
Referência
CVE-2009-3181
Directory traversal vulnerability in Anantasoft Gazelle CMS 1.0 allows remote attackers to overwrite arbitrary files via
23RISK
open
ReferênciaVexDay Proof
PHP Blue Dragon CMS 2.9 - Remote File Inclusion
CVE-2006-2392webappsphp
PHP remote file inclusion vulnerability in public_includes/pub_popup/popup_finduser.php in PHP Blue Dragon Platinum 2.8.
23RISK
open
Referência
CVE-2016-5809
An issue was discovered on Schneider Electric IONXXXX series power meters ION73XX series, ION75XX series, ION76XX series
23RISK
open
Referência
CVE-2016-9950
An issue was discovered in Apport before 2.20.4. There is a path traversal issue in the Apport crash file "Package" and
23RISK
open
Referência
CVE-2017-15971
Same Sex Dating Software Pro 1.0 allows SQL Injection via the viewprofile.php profid parameter, the viewmessage.php send
23RISK
open
Referência
CVE-2022-4953
Elementor < 3.5.5 - Iframe Injection
23RISK
open
ReferênciaVexDay Proof
PHP121 Instant Messenger 1.4 - Remote Code Execution
CVE-2006-1828webappsphp
SQL injection vulnerability in php121language.php in PHP121 1.4 allows remote attackers to execute arbitrary SQL command
23RISK
open
Referência
CVE-2017-2528
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The
23RISK
open
ReferênciaVexDay Proof
OLIB 7 WebView 2.5.1.1 - 'infile' Local File Inclusion
CVE-2008-5678webappsphp
Fretwell-Downing Informatics (FDI) OLIB7 WebView 2.5.1.1 allows remote authenticated users to obtain sensitive informati
23RISK
open
Referência
CVE-2019-19493
Kentico before 12.0.50 allows file uploads in which the Content-Type header is inconsistent with the file extension, lea
23RISK
open
ReferênciaVexDay Proof
Ktools Photostore 3.5.2 - Multiple SQL Injections
CVE-2008-6649webappsphp
SQL injection vulnerability in manager/image_details_editor.php in Ktools PhotoStore 2.5, 2.9.8, 3.1.0, and other versio
23RISK
open
ReferênciaVexDay Proof
Star Articles 6.0 - Blind SQL Injection (1)
CVE-2008-7075webappsphp
Multiple SQL injection vulnerabilities in Kalptaru Infotech Ltd. Star Articles 6.0 allow remote attackers to inject arbi
23RISK
open
Referência
CVE-2010-1077
Directory traversal vulnerability in vbseo.php in Crawlability vBSEO plugin 3.1.0 for vBulletin allows remote attackers
23RISK
open
Referência
CVE-2010-1077
Directory traversal vulnerability in vbseo.php in Crawlability vBSEO plugin 3.1.0 for vBulletin allows remote attackers
23RISK
open
Referência
CVE-2015-3443
Cross-site scripting (XSS) vulnerability in the basic dashboard in Thycotic Secret Server 8.6.x, 8.7.x, and 8.8.x before
23RISK
open
previouspage 643 / 755next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.