Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,056cataloged exploits
35,925CVEs with public exploitation
24,695lab-tested
22,640 exploits
Referência
CVE-2017-16513
Ipswitch WS_FTP Professional before 12.6.0.3 has buffer overflows in the local search field and the backup locations fie
23RISK
open
ReferênciaVexDay Proof
DreamPics Builder - 'page' SQL Injection
CVE-2008-3119webappsphp
SQL injection vulnerability in index.php in DreamPics Builder allows remote attackers to execute arbitrary SQL commands
23RISK
open
Referência
CVE-2017-16570
KeystoneJS before 4.0.0-beta.7 allows application-wide CSRF bypass by removing the CSRF parameter and value, aka SecureL
23RISK
open
Referência
CVE-2008-0233
Unrestricted file upload vulnerability in Zero CMS 1.0 Alpha and earlier allows remote attackers to bypass intended acce
23RISK
open
Referência
CVE-2010-5053
SQL injection vulnerability in the XOBBIX (com_xobbix) component 1.0.1 for Joomla! allows remote attackers to execute ar
23RISK
open
Referência
CVE-2010-5053
SQL injection vulnerability in the XOBBIX (com_xobbix) component 1.0.1 for Joomla! allows remote attackers to execute ar
23RISK
open
Referência
SPBAS Business Automation Software 2012 - Multiple Vulnerabilities
CVE-2013-4664webappsphp
SPBAS Business Automation Software 2012 has XSS.
23RISK
open
ReferênciaVexDay Proof
TopList 1.3.8 - 'phpBB Hack' Remote File Inclusion (1)
CVE-2006-2151webappsphp
PHP remote file inclusion vulnerability in toplist.php in phpBB TopList 1.3.8 and earlier, when register_globals is enab
28RISK
open
ReferênciaVexDay Proof
TopList 1.3.8 - 'phpBB Hack' Remote File Inclusion (2)
CVE-2006-2151webappsphp
PHP remote file inclusion vulnerability in toplist.php in phpBB TopList 1.3.8 and earlier, when register_globals is enab
28RISK
open
Referência
CVE-2010-1983
Directory traversal vulnerability in the redTWITTER (com_redtwitter) component 1.0.x including 1.0b11 for Joomla! allows
43RISK
open
Referência
CVE-2010-1983
Directory traversal vulnerability in the redTWITTER (com_redtwitter) component 1.0.x including 1.0b11 for Joomla! allows
43RISK
open
Referência
CVE-2013-2748
Belkin Wemo Switch before WeMo_US_2.00.2176.PVT could allow remote attackers to upload arbitrary files onto the system.
28RISK
open
Referência
CVE-2009-3545
DataWizard Technologies FtpXQ FTP Server 3.0 allows remote authenticated users to cause a denial of service (crash) via
23RISK
open
Referência
CVE-2021-33353
Directory Traversal vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows at
48RISK
open
Referência
CVE-2007-6191
Multiple PHP remote file inclusion vulnerabilities in Armin Burger p.mapper 3.2.0 beta3 allow remote attackers to execut
23RISK
open
Referência
CVE-2012-1613
Cross-site scripting (XSS) vulnerability in edit_one_pic.php in Coppermine Photo Gallery before 1.5.20 allows remote aut
23RISK
open
Referência
CVE-2012-1613
Cross-site scripting (XSS) vulnerability in edit_one_pic.php in Coppermine Photo Gallery before 1.5.20 allows remote aut
23RISK
open
Referência
CVE-2017-16962
The WebMail components (Crystal, pronto, and pronto4) in CommuniGate Pro before 6.2.1 have stored XSS vulnerabilities vi
23RISK
open
Referência
CVE-2017-16962
The WebMail components (Crystal, pronto, and pronto4) in CommuniGate Pro before 6.2.1 have stored XSS vulnerabilities vi
23RISK
open
Referência
CVE-2011-4673
SQL injection vulnerability in modules/sharedaddy.php in the Jetpack plugin for WordPress allows remote attackers to exe
23RISK
open
Referência
CVE-2026-10230
Assimp Half-Life 1 MDL Loader HL1MDLLoader.cpp read_animations heap-based overflow
33RISK
open
Referência
CVE-2019-7004
Avaya IP Office XSS Vulnerability
33RISK
open
Referência
CVE-2010-0665
JAG (Just Another Guestbook) 1.14 stores sensitive information under the web root with insufficient access control, whic
23RISK
open
Referência
CVE-2015-5287
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain perm
38RISK
open
ReferênciaVexDay Proof
CcMail 1.0.1 - Insecure Cookie Handling
CVE-2008-1904webappsphp
Cicoandcico CcMail 1.0.1 and earlier does not verify that the this_cookie cookie corresponds to an authenticated session
23RISK
open
ReferênciaVexDay Proof
Download Accelerator Plus DAP 8.x - '.m3u' File Buffer Overflow
CVE-2008-3182localwindows
Stack-based buffer overflow in DAP.exe in Download Accelerator Plus (DAP) 7.0.1.3, 8.6.6.3, and other 8.x versions allow
23RISK
open
Referência
MyT Project Management 1.5.1 - User[username] Persistent Cross-Site Scripting
CVE-2019-13346webappsphp
In MyT 1.5.1, the User[username] parameter has XSS.
23RISK
open
ReferênciaVexDay Proof
CCLeague Pro 1.2 - Insecure Cookie Authentication
CVE-2008-5125webappsphp
admin.php in CCleague Pro 1.2 allows remote attackers to bypass authentication by setting the type cookie value to admin
23RISK
open
ReferênciaVexDay Proof
TxtBlog 1.0 Alpha - Local File Inclusion
CVE-2008-5639webappsphp
Directory traversal vulnerability in index.php in TxtBlog 1.0 Alpha allows remote attackers to read arbitrary files via
23RISK
open
ReferênciaVexDay Proof
4Images 1.7.7 - Filter Bypass HTML Injection / Cross-Site Scripting
CVE-2009-2131webappsphp
Cross-site scripting (XSS) vulnerability in 4images 1.7.7 and earlier allows remote authenticated users to inject arbitr
23RISK
open
previouspage 645 / 755next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.