Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
75,589cataloged exploits
34,508CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,554GitHub PoC 13,689VulnCheck XDB 8,216Nuclei 4,223Metasploit 3,464✓ verified onlyrecentpopularrisk
21,534 exploits
Referência
CVE-2017-15662
In Flexense VX Search Enterprise v10.1.12, the Control Protocol suffers from a denial of service vulnerability. The atta
23RISK
open ↗Referência
CVE-2015-6970
The web interface in Bosch Security Systems NBN-498 Dinion2X Day/Night IP Cameras with H.264 Firmware 4.54.0026 allows r
23RISK
open ↗Referência
CVE-2006-1595
Cross-site scripting (XSS) vulnerability in document/rqmkhtml.php in Claroline 1.7.4 and earlier allows remote attackers
23RISK
open ↗Referência
CVE-2023-30350
FS S3900-24T4S devices allow authenticated attackers with guest access to escalate their privileges and reset the admin
41RISK
open ↗Referência
CVE-2014-3110
Multiple cross-site scripting (XSS) vulnerabilities on Honeywell FALCON XLWeb Linux controller devices 2.04.01 and earli
23RISK
open ↗Referência
CVE-2010-4280
Multiple SQL injection vulnerabilities in Pandora FMS before 3.1.1 allow remote authenticated users to execute arbitrary
23RISK
open ↗Referência
CVE-2017-3622
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Common Desktop Environment (C
38RISK
open ↗Referência
CVE-2013-6627
net/http/http_stream_parser.cc in Google Chrome before 31.0.1650.48 does not properly process HTTP Informational (aka 1x
23RISK
open ↗Referência
CVE-2013-6627
net/http/http_stream_parser.cc in Google Chrome before 31.0.1650.48 does not properly process HTTP Informational (aka 1x
23RISK
open ↗Referência
CVE-2012-6506
Multiple cross-site scripting (XSS) vulnerabilities in the Zingiri Web Shop plugin 2.4.0 for WordPress allow remote atta
23RISK
open ↗Referência
CVE-2018-10969
SQL injection vulnerability in the Pie Register plugin before 3.0.10 for WordPress allows remote attackers to execute ar
23RISK
open ↗Referência
CVE-2014-4170
A Privilege Escalation Vulnerability exists in Free Reprintables ArticleFR 11.06.2014 due to insufficient access restric
28RISK
open ↗Referência✓ VexDay Proof
X.Org xorg-server 1.1.1-48.13 - Probe for Files (PoC)
X.Org Xserver before 1.4.1 allows local users to determine the existence of arbitrary files via a filename argument in t
23RISK
open ↗Referência✓ VexDay Proof
Agares phpAutoVideo 2.21 - Local/Remote File Inclusion
Directory traversal vulnerability in includes/block.php in Agares Media phpAutoVideo 2.21 allows remote attackers to inc
23RISK
open ↗Referência✓ VexDay Proof
VidiScript (Avatar) - Arbitrary File Upload
Unrestricted file upload vulnerability in the profile feature in VidiScript allows registered remote authenticated users
23RISK
open ↗Referência✓ VexDay Proof
CDex 1.70b2 (Windows XP SP3) - '.ogg' Local Buffer Overflow
Buffer overflow in CDex 1.70b2 allows remote attackers to execute arbitrary code via a crafted Info header in an Ogg Vor
23RISK
open ↗Referência
CVE-2009-3757
Multiple cross-site scripting (XSS) vulnerabilities in sample code in the XenServer Resource Kit in Citrix XenCenterWeb
23RISK
open ↗Referência
CVE-2017-15662
In Flexense VX Search Enterprise v10.1.12, the Control Protocol suffers from a denial of service vulnerability. The atta
23RISK
open ↗Referência
CVE-2017-15665
In Flexense DiskBoss Enterprise 8.5.12, the Control Protocol suffers from a denial of service vulnerability. The attack
23RISK
open ↗Referência
CVE-2010-1089
SQL injection vulnerability in vedi_faq.php in PHP Trouble Ticket 2.2 allows remote attackers to execute arbitrary SQL c
23RISK
open ↗Referência
CVE-2016-2417
media/libmedia/IOMX.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x befo
23RISK
open ↗Referência
CVE-2013-7030
The TFTP service in Cisco Unified Communications Manager (aka CUCM or Unified CM) allows remote attackers to obtain sens
41RISK
open ↗Referência
CVE-2022-22832
An issue was discovered in Servisnet Tessa 0.0.2. Authorization data is available via an unauthenticated /data-service/u
28RISK
open ↗Referência
CVE-2015-3245
Incomplete blacklist vulnerability in the chfn function in libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in t
38RISK
open ↗Referência
CVE-2019-6804
An XSS issue was discovered on the Job Edit page in Rundeck Community Edition before 3.0.13, related to assets/javascrip
23RISK
open ↗Referência✓ VexDay Proof
JV2 Folder Gallery 3.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in theme/include_mode/template.php in JV2 Folder Gallery 3.0.2 and earlier allow
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.