Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
75,589cataloged exploits
34,508CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,554GitHub PoC 13,689VulnCheck XDB 8,216Nuclei 4,223Metasploit 3,464✓ verified onlyrecentpopularrisk
21,554 exploits
Referência
CVE-2015-4064
SQL injection vulnerability in modules/module.ab-testing.php in the Landing Pages plugin before 1.8.5 for WordPress allo
23RISK
open ↗Referência
CVE-2015-4064
SQL injection vulnerability in modules/module.ab-testing.php in the Landing Pages plugin before 1.8.5 for WordPress allo
23RISK
open ↗Referência
CVE-2015-4018
SQL injection vulnerability in feedwordpresssyndicationpage.class.php in the FeedWordPress plugin before 2015.0514 for W
23RISK
open ↗Referência
CVE-2015-4018
SQL injection vulnerability in feedwordpresssyndicationpage.class.php in the FeedWordPress plugin before 2015.0514 for W
23RISK
open ↗Referência
CVE-2017-11494
SQL injection vulnerability in SOL.Connect ISET-mpp meter 1.2.4.2 and earlier allows remote attackers to execute arbitra
23RISK
open ↗Referência✓ VexDay Proof
OpenDock Easy Gallery 1.4 - 'doc_directory' File Inclusion
Multiple PHP remote file inclusion vulnerabilities in OpenDock Easy Gallery 1.4 and earlier, when register_globals is en
23RISK
open ↗Referência✓ VexDay Proof
MolyX BOARD 2.5.0 - 'index.php?lang' Local File Inclusion
Multiple directory traversal vulnerabilities in MolyX BOARD 2.5.0 allow remote attackers to read arbitrary files via a .
23RISK
open ↗Referência✓ VexDay Proof
EnjoySAP ActiveX kweditcontrol.kwedit.1 - Remote Stack Overflow (PoC)
Multiple unspecified vulnerabilities in ActiveX controls in the EnjoySAP SAP GUI allow remote attackers to cause a denia
23RISK
open ↗Referência✓ VexDay Proof
OSSIM 0.9.9rc5 - Cross-Site Scripting / SQL Injection
Cross-site scripting (XSS) vulnerability in session/login.php in Open Source Security Information Management (OSSIM) 0.9
23RISK
open ↗Referência✓ VexDay Proof
phpdaily - SQL Injection / Cross-Site Scripting / Local File Download
Directory traversal vulnerability in download_file.php in PHP-Daily allows remote attackers to read arbitrary local file
23RISK
open ↗Referência✓ VexDay Proof
DB Top Sites 1.0 - Remote Command Execution
Static code injection vulnerability in add_reg.php in DB Top Sites 1.0 allows remote attackers to inject arbitrary PHP c
23RISK
open ↗Referência
CVE-2009-4932
Stack-based buffer overflow in 1by1 1.67 (aka 1.6.7.0) allows remote attackers to cause a denial of service (application
23RISK
open ↗Referência
CVE-2016-3694
Multiple SQL injection vulnerabilities in modified eCommerce Shopsoftware 2.0.0.0 revision 9678, when the easybill-modul
23RISK
open ↗Referência
CVE-2016-3694
Multiple SQL injection vulnerabilities in modified eCommerce Shopsoftware 2.0.0.0 revision 9678, when the easybill-modul
23RISK
open ↗Referência
CVE-2020-15364
The Nexos theme through 1.7 for WordPress allows top-map/?search_location= reflected XSS.
23RISK
open ↗Referência
CVE-2010-2102
Buffer overflow in Webby Webserver 1.01 allows remote attackers to execute arbitrary code via a long HTTP GET request.
23RISK
open ↗Referência
CVE-2009-2275
Directory traversal vulnerability in frontend/x3/stats/lastvisit.html in cPanel allows remote attackers to read arbitrar
23RISK
open ↗Referência
CVE-2013-4862
MiCasaVerde VeraLite with firmware 1.5.408 does not properly restrict access, which allows remote authenticated users to
23RISK
open ↗Referência
CVE-2013-4862
MiCasaVerde VeraLite with firmware 1.5.408 does not properly restrict access, which allows remote authenticated users to
23RISK
open ↗Referência
CVE-2015-2366
win32k.sys in the kernel-mode drivers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Wi
23RISK
open ↗Referência
CVE-2015-2365
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server
23RISK
open ↗Referência
CVE-2012-4772
SQL injection vulnerability in register/ in Subrion CMS before 2.2.3 allows remote attackers to execute arbitrary SQL co
23RISK
open ↗Referência
CVE-2009-2784
Multiple directory traversal vulnerabilities in dit.cms 1.3, when register_globals is enabled, allow remote attackers to
23RISK
open ↗Referência
CVE-2008-6495
Cross-site scripting (XSS) vulnerability in index.php in Fritz Berger yet another php photo album - next generation (yap
23RISK
open ↗Referência✓ VexDay Proof
Web//News 1.4 - 'parser.php' Remote File Inclusion (1)
PHP remote file inclusion vulnerability in parse/parser.php in WEB//NEWS (aka webnews) 1.4 and earlier allows remote att
23RISK
open ↗Referência✓ VexDay Proof
MiniBill 20061010 - 'menu_builder.php' File Inclusion
PHP remote file inclusion vulnerability in include/menu_builder.php in MiniBILL 2006-10-10 (1.2.3) and earlier, when reg
23RISK
open ↗Referência✓ VexDay Proof
PHP Upload Center 2.0 - 'activate.php' File Inclusion
PHP remote file inclusion vulnerability in activate.php in PHP Upload Center 2.0 allows remote attackers to execute arbi
23RISK
open ↗Referência✓ VexDay Proof
CandyPress eCommerce suite 4.1.1.26 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in admin/utilities_ConfigHelp.asp in CandyPress (CP) 4.1.1.26, and probably ear
23RISK
open ↗Referência✓ VexDay Proof
WholeHogSoftware Ware Support - Insecure Cookie Handling
Whole Hog Ware Support 1.x allows remote attackers to bypass authentication and obtain administrative access via an inte
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.