Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,794cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
22,573 exploits
Referência
CVE-2012-1125
Unrestricted file upload vulnerability in uploadify/scripts/uploadify.php in the Kish Guest Posting plugin before 1.2 fo
28RISK
open
Referência
CVE-2020-17530
CVE-2020-17530CRITICALunder attack
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISK
open
Referência
CVE-2020-5847
CVE-2020-5847CRITICALunder attack
Unraid through 6.8.0 allows Remote Code Execution.
100RISK
open
ReferênciaVexDay Proof
Joomla! Component Rapid Recipe 1.6.6/1.6.7 - SQL Injection
CVE-2008-2697webappsphp
SQL injection vulnerability in the Rapid Recipe (com_rapidrecipe) component 1.6.6 and 1.6.7 for Joomla! allows remote at
23RISK
open
Referência
CVE-2012-1153
Unrestricted file upload vulnerability in addons/uploadify/uploadify.php in appRain CMF 0.1.5 and earlier allows remote
50RISK
open
Referência
CVE-2023-23956
A user can supply malicious HTML and JavaScript code that will be executed in the client browser
33RISK
open
ReferênciaVexDay Proof
Galatolo Web Manager 1.0 - Cross-Site Scripting / Local File Inclusion
CVE-2008-2699webappsphp
Multiple directory traversal vulnerabilities in Galatolo WebManager (GWM) 1.0 allow remote attackers to include and exec
23RISK
open
ReferênciaVexDay Proof
Black Ice Software Annotation Plugin - 'BiAnno.ocx' Remote Buffer Overflow (2)
CVE-2008-2745remotewindows
Stack-based buffer overflow in BiAnno ActiveX Control (BiAnno.ocx) in Black Ice Software Annotation Plugin 10.95 allows
28RISK
open
Referência
CVE-2020-11530
A blind SQL injection vulnerability is present in Chop Slider 3, a WordPress plugin. The vulnerability is introduced in
60RISK
open
Referência
CVE-2020-11530
A blind SQL injection vulnerability is present in Chop Slider 3, a WordPress plugin. The vulnerability is introduced in
60RISK
open
ReferênciaVexDay Proof
JAMM CMS - 'id' Blind SQL Injection
CVE-2008-2755webappsphp
SQL injection vulnerability in index.php in JAMM CMS allows remote attackers to execute arbitrary SQL commands via the i
23RISK
open
ReferênciaVexDay Proof
PreProject Multi-Vendor Shopping Malls - Multiple Vulnerabilities
CVE-2008-6227webappsphp
SQL injection vulnerability in buyer_detail.php in Pre Multi-Vendor Shopping Malls allows remote attackers to execute ar
23RISK
open
Referência
CVE-2009-2219
Multiple cross-site scripting (XSS) vulnerabilities in phpCollegeExchange 0.1.5c allow remote attackers to inject arbitr
23RISK
open
Referência
CVE-2009-2220
Multiple directory traversal vulnerabilities in Tribiq CMS 5.0.12c, when register_globals is enabled and magic_quotes_gp
23RISK
open
Referência
CVE-2026-7222
code-projects Coaching Management System Complaint Form complaint.php cross site scripting
33RISK
open
ReferênciaVexDay Proof
CKGold Shopping Cart 2.5 - 'category_id' SQL Injection
CVE-2008-2774webappsphp
SQL injection vulnerability in item.php in CartKeeper CKGold Shopping Cart 2.5 and 2.7 allows remote attackers to execut
23RISK
open
Referência
CVE-2022-41352
CVE-2022-41352CRITICALunder attack
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through ama
100RISK
open
ReferênciaVexDay Proof
RevokeBB 1.0 RC11 - 'Search' SQL Injection
CVE-2008-2778webappsphp
SQL injection vulnerability in inc/class_search.php in the Search System in RevokeBB 1.0 RC11 allows remote attackers to
23RISK
open
Referência
CVE-2019-11580
CVE-2019-11580CRITICALunder attackransomware
Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attac
100RISK
open
ReferênciaVexDay Proof
MyMarket 1.72 - Blind SQL Injection
CVE-2008-2815webappsphp
SQL injection vulnerability in shopping/index.php in MyMarket 1.72 allows remote attackers to execute arbitrary SQL comm
23RISK
open
ReferênciaVexDay Proof
Nitro Web Gallery 1.4.3 - 'section' SQL Injection
CVE-2008-2817webappsphp
SQL injection vulnerability in albums.php in NiTrO Web Gallery 1.4.3 and earlier allows remote attackers to execute arbi
23RISK
open
ReferênciaVexDay Proof
LE.CMS 1.4 - Arbitrary File Upload
CVE-2008-2833webappsphp
admin/upload.php in le.cms 1.4 and earlier allows remote attackers to bypass administrative authentication, and upload a
23RISK
open
Referência
CVE-2019-7609
CVE-2019-7609CRITICALunder attack
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISK
open
ReferênciaVexDay Proof
IGSuite 3.2.4 - Reverse Shell / Blind SQL Injection
CVE-2008-2835webappsphp
SQL injection vulnerability in cgi-bin/igsuite in IGSuite 3.2.4 allows remote attackers to execute arbitrary SQL command
23RISK
open
ReferênciaVexDay Proof
traindepot 0.1 - Local File Inclusion / Cross-Site Scripting
CVE-2008-2838webappsphp
Directory traversal vulnerability in index.php in Traindepot 0.1 allows remote attackers to read arbitrary files via a .
23RISK
open
ReferênciaVexDay Proof
traindepot 0.1 - Local File Inclusion / Cross-Site Scripting
CVE-2008-2839webappsphp
Cross-site scripting (XSS) vulnerability in the search module in Traindepot 0.1 allows remote attackers to inject arbitr
23RISK
open
ReferênciaVexDay Proof
SFS EZ Webstore - 'where' SQL Injection
CVE-2008-6242webappsphp
SQL injection vulnerability in SearchResults.php in Scripts For Sites (SFS) EZ e-store allows remote attackers to execut
23RISK
open
Referência
CVE-2026-17434
nanocoai NanoClaw add_mcp_server request.ts handleAddMcpServer improper authorization
33RISK
open
Referência
CVE-2026-65711
sysPass 3.2.11 Authenticated OS Command Injection via Backup Path
41RISK
open
Referência
CVE-2009-2235
SQL injection vulnerability in page.php in Your Articles Directory allows remote attackers to execute arbitrary SQL comm
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.