Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
75,526cataloged exploits
34,478CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,534GitHub PoC 13,654VulnCheck XDB 8,213Nuclei 4,218Metasploit 3,464✓ verified onlyrecentpopularrisk
21,534 exploits
Referência
CVE-2017-7047
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS
23RISK
open ↗Referência
CVE-2017-2524
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS
23RISK
open ↗Referência
CVE-2017-7237
The Spiceworks TFTP Server, as distributed with Spiceworks Inventory 7.5, allows remote attackers to access the Spicewor
23RISK
open ↗Referência
CVE-2017-10688
In LibTIFF 4.0.8, there is a assertion abort in the TIFFWriteDirectoryTagCheckedLong8Array function in tif_dirwrite.c. A
23RISK
open ↗Referência
CVE-2015-4668
Open redirect vulnerability in Xsuite 2.4.4.5 and earlier allows remote attackers to redirect users to arbitrary web sit
38RISK
open ↗Referência
CVE-2017-13794
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component mosmedia 1.0.8 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in the Avant-Garde Solutions MOSMedia (com_mosmedia) 1.08 and earlier
23RISK
open ↗Referência✓ VexDay Proof
FreshView 7.15 - '.psp' Local Buffer Overflow
Buffer overflow in Fresh View 7.15 allows user-assisted remote attackers to execute arbitrary code via a crafted .PSP fi
23RISK
open ↗Referência✓ VexDay Proof
TalkBack 2.2.7 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in TalkBack 2.2.7 allow remote attackers to execute arbitrary PHP cod
23RISK
open ↗Referência✓ VexDay Proof
Joovili 3.0.6 - 'joovili.images.php' Remote File Disclosure
Directory traversal vulnerability in include/images.inc.php in Joovili 2.x allows remote attackers to read arbitrary fil
23RISK
open ↗Referência✓ VexDay Proof
Hedgehog-CMS 1.21 - 'header.php' Local File Inclusion
Directory traversal vulnerability in includes/header.php in Hedgehog-CMS 1.21 allows remote attackers to include and exe
23RISK
open ↗Referência✓ VexDay Proof
Autodesk DWF Viewer Control / LiveUpdate Module - Remote Code Execution
Directory traversal vulnerability in the CExpressViewerControl class in the DWF Viewer ActiveX control (AdView.dll 9.0.0
23RISK
open ↗Referência✓ VexDay Proof
mini-pub 0.3 - File Disclosure / Code Execution
mini-pub.php/front-end/cat.php in mini-pub 0.3 allows remote attackers to execute arbitrary commands via shell metachara
23RISK
open ↗Referência✓ VexDay Proof
LoveCMS 1.6.2 Final (Download Manager 1.0) - Arbitrary File Upload
Unrestricted file upload vulnerability in admin/index.php in Download Manager module 1.0 for LoveCMS 1.6.2 Final allows
23RISK
open ↗Referência✓ VexDay Proof
ASP.NET w3wp - COM Components Remote Crash
Microsoft w3wp (aka w3wp.exe) does not properly handle when the AspCompat directive is not used when referencing COM com
35RISK
open ↗Referência
CVE-2010-0691
SQL injection vulnerability in druckansicht.php in JTL-Shop 2 allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗Referência
CVE-2015-7257
ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated non-administrato
23RISK
open ↗Referência
CVE-2015-7257
ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated non-administrato
23RISK
open ↗Referência✓ VexDay Proof
k_shoutbox 4.4 - Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in Knusperleicht Shoutbox 4.4 and earlier allows remote attackers t
23RISK
open ↗Referência
CVE-2013-6234
Unrestricted file upload vulnerability in the Worksheet designer in SpagoBI before 4.1 allows remote authenticated users
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component com_jim 1.0.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in install.jim.php in the JIM 1.0.1 component for Joomla or Mambo allows remote
23RISK
open ↗Referência
CVE-2017-7005
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS
23RISK
open ↗Referência
CVE-2015-1560
SQL injection vulnerability in the isUserAdmin function in include/common/common-Func.php in Centreon (formerly Merethis
23RISK
open ↗Referência
CVE-2009-2258
Directory traversal vulnerability in cgi-bin/webcm in the administrative web interface on the Netgear DG632 with firmwar
23RISK
open ↗Referência✓ VexDay Proof
Joomla! / Mambo Component Taskhopper 1.1 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in the Taskhopper 1.1 component for Mambo and Joomla! allow remote at
23RISK
open ↗Referência✓ VexDay Proof
phpAtm 1.30 - 'downloadfile' Remote File Disclosure
Directory traversal vulnerability in index.php in PHP Advanced Transfer Manager (phpATM) 1.30 allows remote attackers to
23RISK
open ↗Referência
CVE-2017-6191
Buffer overflow in APNGDis 2.8 and below allows a remote attacker to execute arbitrary code via a crafted filename.
23RISK
open ↗Referência✓ VexDay Proof
Ad Management Java - Authentication Bypass
SQL injection vulnerability in logon.jsp in Ad Server Solutions Ad Management Software Java allows remote attackers to e
23RISK
open ↗Referência
CVE-2016-9951
An issue was discovered in Apport before 2.20.4. A malicious Apport crash file can contain a restart command in `Respawn
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.