Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
19,967 exploits
Referência
CVE-2023-37569
OS Command Injection Vulnerability in Emagic Data Center Management Suite
46RISK
open
Referência
CVE-2018-20221
Secure/SAService.rem in Deltek Ajera Timesheets 9.10.16 and prior are vulnerable to remote code execution via deserializ
28RISK
open
Referência
CVE-2018-20221
Secure/SAService.rem in Deltek Ajera Timesheets 9.10.16 and prior are vulnerable to remote code execution via deserializ
28RISK
open
Referência
CVE-2014-5081
sphider prior to 1.3.6, sphider-pro prior to 3.2, and sphider-plus prior to 3.2 allow authentication bypass
28RISK
open
Referência
Sphider Search Engine - Multiple Vulnerabilities
sphider prior to 1.3.6, sphider-pro prior to 3.2, and sphider-plus prior to 3.2 allow authentication bypass
28RISK
open
Referência
Linux Kernel 2.6.21.1 - IPv6 Jumbo Bug Remote Denial of Service
The Linux kernel 2.6.20 through 2.6.21.1 allows remote attackers to cause a denial of service (panic) via a certain IPv6
28RISK
open
Referência
CVE-2020-36911
Covenant 0.5 - Remote Code Execution (RCE)
53RISK
open
Referência
CVE-2020-36911
Covenant 0.5 - Remote Code Execution (RCE)
53RISK
open
Referência
CVE-2020-36911
Covenant 0.5 - Remote Code Execution (RCE)
53RISK
open
Referência
CVE-2013-1596
An Authentication Bypass Vulnerability exists in Vivotek PT7135 IP Camera 0300a and 0400a via specially crafted RTSP pac
28RISK
open
Referência
CVE-2022-29593
relay_cgi.cgi on Dingtian DT-R002 2CH relay devices with firmware 3.1.276A allows an attacker to replay HTTP post reques
38RISK
open
Referência
CVE-2018-9118
exports/download.php in the 99 Robots WP Background Takeover Advertisements plugin before 4.1.5 for WordPress has Direct
50RISK
open
Referência
Apple QuickTime - 'rtsp URL Handler' Remote Stack Buffer Overflow
Buffer overflow in Apple QuickTime 7.1.3 allows remote attackers to execute arbitrary code via a long rtsp:// URI.
50RISK
open
Referência
CVE-2014-2424
Unspecified vulnerability in the Oracle Event Processing component in Oracle Fusion Middleware 11.1.1.7.0 allows remote
50RISK
open
Referência
CVE-2014-2424
Unspecified vulnerability in the Oracle Event Processing component in Oracle Fusion Middleware 11.1.1.7.0 allows remote
50RISK
open
Referência
CVE-2017-11855
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Window
35RISK
open
Referência
CVE-2013-0232
includes/functions.php in ZoneMinder Video Server 1.24.0, 1.25.0, and earlier allows remote attackers to execute arbitra
50RISK
open
Referência
Libxine 1.14 - MPEG Stream Buffer Overflow (PoC)
Buffer overflow in demuxers/demux_asf.c (aka the ASF demuxer) in the xineplug_dmx_asf.so plugin in xine-lib before 1.1.1
28RISK
open
Referência
CVE-2010-2931
Stack-based buffer overflow in SigPlus Pro 3.74 ActiveX control allows remote attackers to execute arbitrary code via a
23RISK
open
Referência
CVE-2014-9013
The ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin 2.4.0 for WordPress allows remote auth
35RISK
open
Referência
acute control panel 1.0.0 - SQL Injection / Remote File Inclusion
SQL injection vulnerability in login.php in Acute Control Panel 1.0.0 allows remote attackers to execute arbitrary SQL c
28RISK
open
Referência
Java SE Runtime Environment JRE 6 Update 13 - Multiple Vulnerabilities
Multiple buffer overflows in the Deployment Toolkit ActiveX control in deploytk.dll 6.0.130.3 in Sun Java SE Runtime Env
28RISK
open
Referência
CVE-2020-27932
CVE-2020-27932HIGHunder attack
A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.0.1, watchOS
76RISK
open
Referência
CVE-2012-3814
Unrestricted file upload vulnerability in font-upload.php in the Font Uploader plugin 1.2.4 for WordPress allows remote
28RISK
open
Referência
QnECMS 2.5.6 - 'adminfolderpath' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in QnECMS 2.5.6 and earlier allow remote attackers to execute arbitra
28RISK
open
Referência
SolidState 0.4 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in SolidState 0.4 and earlier allow remote attackers to execute arbit
28RISK
open
Referência
CVE-2010-4701
Heap-based buffer overflow in the CDrawPoly::Serialize function in fxscover.exe in Microsoft Windows Fax Services Cover
35RISK
open
Referência
CVE-2011-3981
PHP remote file inclusion vulnerability in actions.php in the Allwebmenus plugin 1.1.3 for WordPress allows remote attac
28RISK
open
Referência
CVE-2019-16692
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter-result.php table parameter when action=add is us
28RISK
open
Referência
CVE-2012-1008
OfficeSIP Server 3.1 allows remote attackers to cause a denial of service (daemon crash) via a crafted To header in a SI
28RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.