Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,794cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
22,573 exploits
ReferênciaVexDay Proof
Absolute Poll Manager XE 4.1 - 'xlacomments.asp' SQL Injection
CVE-2008-4569webappsasp
SQL injection vulnerability in xlacomments.asp in XIGLA Software Absolute Poll Manager XE 4.1 allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
Ayco Okul Portali - 'linkid' SQL Injection
CVE-2008-4574webappsasp
SQL injection vulnerability in default.asp in Ayco Okul Portali allows remote attackers to execute arbitrary SQL command
23RISK
open
ReferênciaVexDay Proof
Microsoft HTML Workshop 4.74 - Universal Buffer Overflow
CVE-2009-0133localwindows
Buffer overflow in Microsoft HTML Help Workshop 4.74 and earlier allows context-dependent attackers to execute arbitrary
50RISK
open
Referência
CVE-2017-14493
Stack-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execu
45RISK
open
Referência
CVE-2019-3010
CVE-2019-3010HIGHunder attack
Vulnerability in the Oracle Solaris product of Oracle Systems (component: XScreenSaver). The supported version that is a
91RISK
open
Referência
CVE-2016-10073
The from method in library/core/class.email.php in Vanilla Forums before 2.3.1 allows remote attackers to spoof the emai
60RISK
open
Referência
CVE-2016-10073
The from method in library/core/class.email.php in Vanilla Forums before 2.3.1 allows remote attackers to spoof the emai
60RISK
open
ReferênciaVexDay Proof
miniBloggie 1.0 - 'del.php' Blind SQL Injection
CVE-2008-4628webappsphp
SQL injection vulnerability in del.php in myWebland miniBloggie 1.0 allows remote attackers to execute arbitrary SQL com
23RISK
open
ReferênciaVexDay Proof
mystats - 'hits.php' Multiple Vulnerabilities
CVE-2008-4643webappsphp
SQL injection vulnerability in hits.php in myWebland myStats allows remote attackers to execute arbitrary SQL commands v
23RISK
open
Referência
CVE-2021-25094
Tatsu < 3.3.12 - Unauthenticated RCE
60RISK
open
Referência
CVE-2010-2075
UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally
60RISK
open
Referência
CVE-2013-5311
Multiple SQL injection vulnerabilities in Vastal I-Tech phpVID 1.2.3 allow remote attackers to execute arbitrary SQL com
23RISK
open
ReferênciaVexDay Proof
PHPWebGallery 1.7.2 - Session Hijacking / Code Execution
CVE-2008-4645webappsphp
plugins/event_tracer/event_list.php in PhpWebGallery 1.7.2 and earlier allows remote authenticated administrators to exe
23RISK
open
ReferênciaVexDay Proof
phpdaily - SQL Injection / Cross-Site Scripting / Local File Download
CVE-2008-4758webappsphp
Directory traversal vulnerability in download_file.php in PHP-Daily allows remote attackers to read arbitrary local file
23RISK
open
Referência
CVE-2019-5420
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RISK
open
ReferênciaVexDay Proof
freeSSHd 1.2.1 - (Authenticated) SFTP 'realpath' Remote Buffer Overflow (PoC)
CVE-2008-4762doswindows
Stack-based buffer overflow in freeSSHd 1.2.1 allows remote authenticated users to cause a denial of service (service cr
28RISK
open
ReferênciaVexDay Proof
Joomla! Component com_extplorer 2.0.0 RC2 - Local Directory Traversal
CVE-2008-4764webappsphp
Directory traversal vulnerability in the eXtplorer module (com_extplorer) 2.0.0 RC2 and earlier in Joomla! allows remote
43RISK
open
Referência
CVE-2008-4765
SQL injection vulnerability in pollBooth.php in osCommerce Poll Booth Add-On 2.0 allows remote attackers to execute arbi
23RISK
open
ReferênciaVexDay Proof
QuestCMS - Cross-Site Scripting / Directory Traversal / SQL Injection
CVE-2008-4773webappsphp
Directory traversal vulnerability in main/main.php in QuestCMS allows remote attackers to read arbitrary local files via
23RISK
open
ReferênciaVexDay Proof
Dream4 Koobi Pro 6.25 Showimages - 'galid' SQL Injection
CVE-2008-4778webappsphp
SQL injection vulnerability in the gallery module in Koobi CMS 4.3.0 allows remote attackers to execute arbitrary SQL co
23RISK
open
Referência
CVE-2017-11317
CVE-2017-11317CRITICALunder attack
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload
100RISK
open
Referência
CVE-2017-17587
FS Indiamart Clone 1.0 has SQL Injection via the catcompany.php token parameter, buyleads-details.php id parameter, or c
23RISK
open
ReferênciaVexDay Proof
TugZip 3.00 Archiver - '.zip' Local Buffer Overflow
CVE-2008-4779localwindows
Stack-based buffer overflow in TUGzip 3.5.0.0 allows remote attackers to denial of service (crash) or execute arbitrary
50RISK
open
ReferênciaVexDay Proof
e107 Plugin alternate_profiles - 'id' SQL Injection
CVE-2008-4785webappsphp
SQL injection vulnerability in newuser.php in the alternate_profiles plugin, possibly 0.2, for e107 allows remote attack
23RISK
open
ReferênciaVexDay Proof
e107 Plugin EasyShop - 'category_id' Blind SQL Injection
CVE-2008-4786webappsphp
SQL injection vulnerability in easyshop.php in the EasyShop plugin for e107 allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
ITLPoll 2.7 Stable2 - Blind SQL Injection
CVE-2009-0295webappsphp
SQL injection vulnerability in index.php in Information Technology Light Poll Information (ITLPoll) 2.7 Stable 2, when m
23RISK
open
Referência
CVE-2016-10174
CVE-2016-10174CRITICALunder attack
The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cg
100RISK
open
Referência
CVE-2016-10174
CVE-2016-10174CRITICALunder attack
The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cg
100RISK
open
ReferênciaVexDay Proof
Microsoft Windows Wordpad - '.doc' File Local Denial of Service (PoC)
CVE-2008-4841doswindows
The WordPad Text Converter for Word 97 files in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2 allows r
35RISK
open
Referência
CVE-2019-1935
Cisco Integrated Management Controller Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data SCP User Default Credentials Vulnerability
85RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.