Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
72,018cataloged exploits
32,219CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 20,023GitHub PoC 13,334VulnCheck XDB 8,195Nuclei 4,217Metasploit 3,463✓ verified onlyrecentpopularrisk
20,023 exploits
Referência
Simplog 0.9.2 - 's' Remote Command Execution
Directory traversal vulnerability in doc/index.php in Jeremy Ashcraft Simplog 0.9.2 and earlier allows remote attackers
23RISK
open ↗Referência
OWL Intranet Engine 0.82 - 'xrms_file_root' Code Execution
PHP remote file inclusion vulnerability in lib/OWL_API.php in OWL Intranet Engine 0.82, when register_globals is enabled
23RISK
open ↗Referência
CVE-2018-9010
Intelbras TELEFONE IP TIP200/200 LITE 60.0.75.29 devices allow remote authenticated admins to read arbitrary files via t
23RISK
open ↗Referência
4Images 1.7.1 - Local File Inclusion / Remote Code Execution
Directory traversal vulnerability in index.php in 4Images 1.7.1 and earlier allows remote attackers to read and include
23RISK
open ↗Referência
CVE-2011-5167
Heap-based buffer overflow in the SetDevNames method of the Tidestone Formula One ActiveX control (TTF16.ocx) 6.3.5 Buil
23RISK
open ↗Referência
CVE-2019-6215
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, Safa
23RISK
open ↗Referência
Najdi.si Toolbar - ActiveX Remote Buffer Overflow (PoC)
Stack-based buffer overflow in an ActiveX control in najdisitoolbar.dll in Najdi.si Toolbar 2.0.4.1 allows remote attack
23RISK
open ↗Referência
CVE-2016-4535
Integer signedness error in the AV engine before DAT 8145, as used in McAfee LiveSafe 14.0, allows remote attackers to c
23RISK
open ↗Referência
CVE-2016-4535
Integer signedness error in the AV engine before DAT 8145, as used in McAfee LiveSafe 14.0, allows remote attackers to c
23RISK
open ↗Referência
CVE-2014-4663
TimThumb 2.8.13 and WordThumb 1.07, when Webshot (aka Webshots) is enabled, allows remote attackers to execute arbitrary
23RISK
open ↗Referência
CVE-2014-4663
TimThumb 2.8.13 and WordThumb 1.07, when Webshot (aka Webshots) is enabled, allows remote attackers to execute arbitrary
23RISK
open ↗Referência
Download Accelerator Plus DAP 8.6 - 'AniGIF.ocx' Buffer Overflow (PoC)
Multiple stack-based buffer overflows in the Animation GIF ActiveX control in JComSoft AniGIF.ocx 1.12 and 2.47, as used
23RISK
open ↗Referência
PHPLojaFacil 0.1.5 - 'path_local' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Crie seu PHPLojaFacil 0.1.5 allow remote attackers to execute arbi
23RISK
open ↗Referência
CVE-2014-2647
Cross-site scripting (XSS) vulnerability in HP Operations Agent in HP Operations Manager (formerly OpenView Communicatio
23RISK
open ↗Referência
CVE-2010-0279
Unrestricted file upload vulnerability in upload.php in BTS-GI Read excel 1.1 allows remote attackers to execute arbitra
23RISK
open ↗Referência
Phoenician Casino FlashAX - ActiveX Remote Code Execution
Heap-based buffer overflow in the Phoenician Casino FlashAX ActiveX control 1.0.0.7 allows remote attackers to execute a
23RISK
open ↗Referência
Apple iTunes 8.0.2.20/QuickTime 7.5.5 - '.mov' Multiple Off By Overflows (PoC)
Stack-based buffer overflow in Apple QuickTime Player 7.5.5 and iTunes 8.0.2.20 allows remote attackers to cause a denia
23RISK
open ↗Referência
CVE-2018-16299
The Localize My Post plugin 1.0 for WordPress allows Directory Traversal via the ajax/include.php file parameter.
50RISK
open ↗Referência
CVE-2018-16299
The Localize My Post plugin 1.0 for WordPress allows Directory Traversal via the ajax/include.php file parameter.
50RISK
open ↗Referência
CVE-2021-40352
OpenEMR 6.0.0 has a pnotes_print.php?noteid= Insecure Direct Object Reference vulnerability via which an attacker can re
23RISK
open ↗Referência
CVE-2014-5074
Siemens SIMATIC S7-1500 CPU devices with firmware before 1.6 allow remote attackers to cause a denial of service (device
23RISK
open ↗Referência
XAMPP for Windows 1.6.0a - 'mssql_connect()' Remote Buffer Overflow
The ADONewConnection Connect function in adodb.php in XAMPP 1.6.0a and earlier for Windows uses untrusted input for the
23RISK
open ↗Referência
Google Chrome 0.2.149.27 - A HREF Denial of Service
Stack-based buffer overflow in chrome/common/gfx/url_elider.cc in Google Chrome 0.2.149.27 and other versions before 0.2
23RISK
open ↗Referência
Neostrada Livebox Router - Remote Network Down (PoC)
The Neostrada Livebox ADSL Router allows remote attackers to cause a denial of service (network outage) via multiple HTT
23RISK
open ↗Referência
GNUEDU 1.3b2 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in gnuedu 1.3b2 allow remote attackers to execute arbitrary PHP code
23RISK
open ↗Referência
CVE-2018-15576
An issue was discovered in EasyLogin Pro through 1.3.0. Encryptor.php contains an unserialize call that can be exploited
23RISK
open ↗Referência
CVE-2018-15576
An issue was discovered in EasyLogin Pro through 1.3.0. Encryptor.php contains an unserialize call that can be exploited
23RISK
open ↗Referência
OpenDock FullCore 4.4 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in OpenDock FullCore 4.4 and earlier allow remote attackers to execut
23RISK
open ↗Referência
CVE-2014-0995
The Standalone Enqueue Server in SAP Netweaver 7.20, 7.01, and earlier allows remote attackers to cause a denial of serv
23RISK
open ↗Referência
CVE-2008-3408
Stack-based buffer overflow in CoolPlayer 2.18, and possibly other versions, allows user-assisted remote attackers to ex
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.