Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
75,445cataloged exploits
34,432CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,497GitHub PoC 13,627VulnCheck XDB 8,198Nuclei 4,217Metasploit 3,463✓ verified onlyrecentpopularrisk
21,497 exploits
Referência
CVE-2017-14702
ERS Data System 1.8.1.0 allows remote attackers to execute arbitrary code, related to "com.branaghgroup.ecers.update.Upd
23RISK
open ↗Referência
CVE-2018-15172
TP-Link WR840N devices have a buffer overflow via a long Authorization HTTP header.
23RISK
open ↗Referência
CVE-2015-4624
Hak5 WiFi Pineapple 2.0 through 2.3 uses predictable CSRF tokens.
50RISK
open ↗Referência✓ VexDay Proof
Bitweaver 1.3 - 'tmpImagePath' Attachment mod_mime
Race condition in articles/BitArticle.php in Bitweaver 1.3, when run on Apache with the mod_mime extension, allows remot
23RISK
open ↗Referência
CVE-2018-14336
TP-Link WR840N devices allow remote attackers to cause a denial of service (connectivity loss) via a series of packets w
23RISK
open ↗Referência
CVE-2010-2126
Multiple PHP remote file inclusion vulnerabilities in Snipe Gallery 3.1.5 allow remote attackers to execute arbitrary PH
23RISK
open ↗Referência
CVE-2010-1982
Directory traversal vulnerability in the JA Voice (com_javoice) component 2.0 for Joomla! allows remote attackers to rea
38RISK
open ↗Referência
CVE-2010-1982
Directory traversal vulnerability in the JA Voice (com_javoice) component 2.0 for Joomla! allows remote attackers to rea
38RISK
open ↗Referência
CVE-2018-5752
The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev4
23RISK
open ↗Referência
CVE-2018-5752
The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev4
23RISK
open ↗Referência
CVE-2021-46424
Telesquare TLR-2005KSH 1.0.0 is affected by an arbitrary file deletion vulnerability that allows a remote attacker to de
50RISK
open ↗Referência✓ VexDay Proof
TWiki 4.2.0 - 'configure' Remote File Disclosure
Directory traversal vulnerability in bin/configure in TWiki before 4.2.3, when a certain step in the installation guide
23RISK
open ↗Referência✓ VexDay Proof
Pligg CMS 9.9.0 - Cross-Site Scripting / Local File Inclusion / SQL Injection
Multiple directory traversal vulnerabilities in Pligg 9.9 and earlier allow remote attackers to (1) determine the existe
23RISK
open ↗Referência
Joomla! Component Jimtawl 2.1.6 - Arbitrary File Upload
Arbitrary file upload exists in the Jimtawl 2.1.6 and 2.2.5 component for Joomla! via a view=upload&task=upload&pop=true
35RISK
open ↗Referência
CVE-2008-1436
Microsoft Windows XP Professional SP2, Vista, and Server 2003 and 2008 does not properly assign activities to the (1) Ne
35RISK
open ↗Referência
CVE-2020-27930
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, wat
76RISK
open ↗Referência
CVE-2014-8835
The xpc_data_get_bytes function in libxpc in Apple OS X before 10.10.2 does not verify that a dictionary's Attributes ke
23RISK
open ↗Referência
CVE-2014-8835
The xpc_data_get_bytes function in libxpc in Apple OS X before 10.10.2 does not verify that a dictionary's Attributes ke
23RISK
open ↗Referência
CVE-2016-10504
Heap-based buffer overflow vulnerability in the opj_mqc_byteout function in mqc.c in OpenJPEG before 2.2.0 allows remote
23RISK
open ↗Referência
WordPress Plugin WooCommerce CardGate Payment Gateway 3.1.15 - Payment Process Bypass
An issue was discovered in the CardGate Payments plugin through 3.1.15 for WooCommerce. Lack of origin authentication in
23RISK
open ↗Referência
CVE-2022-24263
Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-m
23RISK
open ↗Referência
CVE-2018-8533
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing malicious X
28RISK
open ↗Referência
CVE-2010-3135
Untrusted search path vulnerability in Cisco Packet Tracer 5.2 allows local users, and possibly remote attackers, to exe
23RISK
open ↗Referência
CVE-2017-10682
SQL injection vulnerability in the administrative backend in Piwigo through 2.9.1 allows remote users to execute arbitra
23RISK
open ↗Referência
CVE-2016-9332
An issue was discovered in Moxa SoftCMS versions prior to Version 1.6. Moxa SoftCMS Webserver does not properly validate
23RISK
open ↗Referência
CVE-2010-1540
Directory traversal vulnerability in index.php in the MyBlog (com_myblog) component 3.0.329 for Joomla! allows remote at
38RISK
open ↗Referência✓ VexDay Proof
Vivvo Article Manager 3.2 - 'classified_path' File Inclusion
PHP remote file inclusion vulnerability in index.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) 3.2 an
23RISK
open ↗Referência✓ VexDay Proof
LinkedIn Toolbar 3.0.2.1098 - Remote Buffer Overflow
Buffer overflow in the IEToolbar.IEContextMenu.1 ActiveX control in LinkedInIEToolbar.dll in the LinkedIn Toolbar 3.0.2.
23RISK
open ↗Referência✓ VexDay Proof
SkaDate Online 5.0/6.0 - Remote File Disclosure
Multiple directory traversal vulnerabilities in SkaDate 5.0 and 6.0, and possibly later versions such as 6.482, allow re
23RISK
open ↗Referência
CVE-2019-17080
mintinstall (aka Software Manager) 7.9.9 for Linux Mint allows code execution if a REVIEWS_CACHE file is controlled by a
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.