Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
75,445cataloged exploits
34,432CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,497GitHub PoC 13,627VulnCheck XDB 8,198Nuclei 4,217Metasploit 3,463✓ verified onlyrecentpopularrisk
21,497 exploits
Referência✓ VexDay Proof
Microsoft Internet Explorer - Print Table of Links Cross-Zone Scripting
Cross-zone scripting vulnerability in the Print Table of Links feature in Internet Explorer 6.0, 7.0, and 8.0b allows us
28RISK
open ↗Referência
CVE-2010-3126
Untrusted search path vulnerability in avast! Free Antivirus version 5.0.594 and earlier allows local users, and possibl
23RISK
open ↗Referência
CVE-2025-34027
Versa Concerto Authentication Bypass File Write Remote Code Execution
75RISK
open ↗Referência
CVE-2013-6227
Unrestricted file upload vulnerability in plugins/editor.zoho/agent/save_zoho.php in the Zoho plugin in Pydio (formerly
23RISK
open ↗Referência
CVE-2016-3986
Avast allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a
23RISK
open ↗Referência
CVE-2016-6256
SAP Business One for Android 1.2.3 allows remote attackers to conduct XML External Entity (XXE) attacks via crafted XML
23RISK
open ↗Referência
CVE-2015-1376
pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not validate hostnames, which allows remot
50RISK
open ↗Referência
CVE-2016-6256
SAP Business One for Android 1.2.3 allows remote attackers to conduct XML External Entity (XXE) attacks via crafted XML
23RISK
open ↗Referência
CVE-2013-5223
Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2760U Gateway (Rev. E1) allow remote authenticated use
75RISK
open ↗Referência
CVE-2023-0386
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISK
open ↗Referência
CVE-2016-9349
An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. An attacker could traverse the file system
23RISK
open ↗Referência
CVE-2016-9349
An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. An attacker could traverse the file system
23RISK
open ↗Referência
CVE-2018-6871
LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read arbitrary files via =WEBSERVICE calls in a
28RISK
open ↗Referência
CVE-2018-12979
An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. Weak permissions
23RISK
open ↗Referência✓ VexDay Proof
Collabtive 0.4.8 - Cross-Site Scripting / Authentication Bypass / Arbitrary File Upload
Unrestricted file upload vulnerability in Collabtive 0.4.8 allows remote authenticated users to execute arbitrary code b
23RISK
open ↗Referência
CVE-2017-6193
Buffer overflow in APNGDis 2.8 and earlier allows remote attackers to cause a denial of service and possibly execute arb
23RISK
open ↗Referência
CVE-2017-6193
Buffer overflow in APNGDis 2.8 and earlier allows remote attackers to cause a denial of service and possibly execute arb
23RISK
open ↗Referência
CVE-2020-10387
Path Traversal in admin/download.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to download files
23RISK
open ↗Referência
CVE-2020-12712
A vulnerability based on insecure user/password encryption in the JOE (job editor) component of SOS JobScheduler 1.12 an
23RISK
open ↗Referência
CVE-2013-1806
Multiple directory traversal vulnerabilities in PHP-Fusion before 7.02.06 allow remote authenticated users to include an
23RISK
open ↗Referência
CVE-2026-11453
Tiobon Employee Self-Service System Login Endpoint BlogSearch.aspx sql injection
33RISK
open ↗Referência
CVE-2011-4644
Splunk 4.2.5 and earlier, when a Free license is selected, enables potentially undesirable functionality within an envir
23RISK
open ↗Referência
CVE-2011-4106
TimThumb (timthumb.php) before 2.0 does not validate the entire source with the domain white list, which allows remote a
28RISK
open ↗Referência
CVE-2012-2271
Buffer overflow in the InitLicenKeys function in a certain ActiveX control in SkinCrafter3_vs2005.dll in SkinCrafter 3.0
23RISK
open ↗Referência
CVE-2026-11447
GL.iNet GL-MT3000 MTK Backend iwinfo.so iwinfo_backend command injection
33RISK
open ↗Referência
CVE-2026-11437
perfree go-fastdfs-web Installation Endpoint checkServer server-side request forgery
33RISK
open ↗Referência
CVE-2018-10608
SEL AcSELerator Architect version 2.2.24.0 and prior can be exploited when the AcSELerator Architect FTP client connects
23RISK
open ↗Referência✓ VexDay Proof
Quicksilver Forums 1.2.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in lib/activeutil.php in Quicksilver Forums (QSF) 1.2.1 and earlier allows remot
23RISK
open ↗Referência✓ VexDay Proof
Shadows Rising RPG 0.0.5b - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Shadows Rising RPG (Pre-Alpha) 0.0.5b and earlier allow remote att
23RISK
open ↗Referência✓ VexDay Proof
SendStudio 2004.14 - 'ROOTDIR' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Interspire SendStudio 2004.14 and earlier, when register_globals a
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.