Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
72,018cataloged exploits
32,219CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 20,023GitHub PoC 13,334VulnCheck XDB 8,195Nuclei 4,217Metasploit 3,463✓ verified onlyrecentpopularrisk
20,023 exploits
Referência
CVE-2019-8928
An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in /netflow/jspui/userMan
23RISK
open ↗Referência
CVE-2019-8928
An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in /netflow/jspui/userMan
23RISK
open ↗Referência
CVE-2018-1185
An issue was discovered in EMC RecoverPoint for Virtual Machines versions prior to 5.1.1, EMC RecoverPoint version 5.1.0
23RISK
open ↗Referência
samPHPweb 4.2.2 - 'db.php' Remote File Inclusion
PHP remote file inclusion vulnerability in common/db.php in samPHPweb, possibly 4.2.2 and others, as provided with SAM B
23RISK
open ↗Referência
ActualAnalyzer Lite (free) 2.78 - Local File Inclusion
Directory traversal vulnerability in admin.php in ActualScripts ActualAnalyzer Lite 2.78 allows remote attackers to incl
23RISK
open ↗Referência
phosheezy 2.0 - Remote Command Execution
Ryneezy phoSheezy 0.2 stores sensitive information under the web root with insufficient access control, which allows rem
23RISK
open ↗Referência
CVE-2023-0962
SourceCodester Music Gallery Site GET Request Master.php sql injection
33RISK
open ↗Referência
CVE-2020-25453
An issue was discovered in BlackCat CMS before 1.4. There is a CSRF vulnerability (bypass csrf_token) that allows remote
23RISK
open ↗Referência
Yoxel 1.23beta - 'itpm_estimate.php' Remote Code Execution
Multiple eval injection vulnerabilities in itpm_estimate.php in Yoxel 1.23beta and earlier allow remote authenticated us
23RISK
open ↗Referência
PHP-Update 2.7 - 'extract()' Authentication Bypass / Shell Injection
Variable overwrite vulnerability in blog.php in PHP-Update 2.7 and earlier allows remote attackers to overwrite arbitrar
23RISK
open ↗Referência
CVE-2012-4865
Buffer overflow in Oreans Themida 2.1.8.0 allows remote attackers to execute arbitrary code via a crafted .TMD file.
23RISK
open ↗Referência
CVE-2012-4865
Buffer overflow in Oreans Themida 2.1.8.0 allows remote attackers to execute arbitrary code via a crafted .TMD file.
23RISK
open ↗Referência
ASPired2Quote - Remote Database Disclosure
The Net Guys ASPired2Quote stores sensitive information under the web root with insufficient access control, which allow
23RISK
open ↗Referência
CVE-2012-5324
Multiple buffer overflows in the Pdf Printer Preferences ActiveX Control in pdfxctrl.dll in Tracker Software PDF-XChange
23RISK
open ↗Referência
Jaws 0.8.8 - Multiple Local File Inclusions
Directory traversal vulnerability in index.php in Jaws 0.8.8 allows remote authenticated users to read arbitrary files v
23RISK
open ↗Referência
CVE-2019-3859
An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the _libssh2_packet_require and _libssh2_packet_req
48RISK
open ↗Referência
LightNEasy 1.2 - no database Remote Hash Retrieve
LightNEasy/lightneasy.php in LightNEasy No database version 1.2 allows remote attackers to obtain the hash of the admini
23RISK
open ↗Referência
QNX Neutrino 0.8.4 Atomic Edition - Remote Code Execution
Directory traversal vulnerability in index.php in Neutrino Atomic Edition 0.8.4 allows remote attackers to read and modi
23RISK
open ↗Referência
CVE-2018-10018
The GDASPAMLib.AntiSpam ActiveX control ASK\GDASpam.dll in G DATA Total Security 25.4.0.3 has a buffer overflow via a lo
23RISK
open ↗Referência
CVE-2014-10037
Directory traversal vulnerability in DomPHP 0.83 and earlier allows remote attackers to have unspecified impact via a ..
43RISK
open ↗Referência
Kusaba 1.0.4 - Remote Code Execution (1)
Multiple unrestricted file upload vulnerabilities in Kusaba 1.0.4 and earlier allow remote authenticated users to execut
23RISK
open ↗Referência
Kusaba 1.0.4 - Remote Code Execution (2)
Multiple unrestricted file upload vulnerabilities in Kusaba 1.0.4 and earlier allow remote authenticated users to execut
23RISK
open ↗Referência
ZZ FlashChat 3.1 - 'help.php' Local File Inclusion
Directory traversal vulnerability in admin/inc/help.php in ZZ:FlashChat 3.1 and earlier allows remote attackers to inclu
23RISK
open ↗Referência
CVE-2017-2470
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RISK
open ↗Referência
CVE-2017-2469
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RISK
open ↗Referência
CVE-2014-2579
Multiple cross-site request forgery (CSRF) vulnerabilities in XCloner Standalone 3.5 and earlier allow remote attackers
23RISK
open ↗Referência
PortalApp 4.0 - SQL Injection / Cross-Site Scripting / Authentication Bypass
PortalApp 4.0 does not require authentication for (1) forums.asp and (2) content.asp, which allows remote attackers to c
23RISK
open ↗Referência
CVE-2015-1723
Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista S
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.