Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
75,902cataloged exploits
34,597CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,624GitHub PoC 13,727VulnCheck XDB 8,410Nuclei 4,231Metasploit 3,467✓ verified onlyrecentpopularrisk
21,624 exploits
Referência
CVE-2015-7259
ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow user accounts to have multiple valid
23RISK
open ↗Referência
CVE-2014-1665
Cross-site scripting (XSS) vulnerability in ownCloud before 6.0.1 allows remote authenticated users to inject arbitrary
23RISK
open ↗Referência
CVE-2014-1665
Cross-site scripting (XSS) vulnerability in ownCloud before 6.0.1 allows remote authenticated users to inject arbitrary
23RISK
open ↗Referência
CVE-2010-3899
IBM OmniFind Enterprise Edition 8.x and 9.x performs web crawls with an unlimited recursion depth, which allows remote w
23RISK
open ↗Referência
CVE-2020-25270
PHPGurukul hostel-management-system 2.1 allows XSS via Guardian Name, Guardian Relation, Guardian Contact no, Address, o
23RISK
open ↗Referência
CVE-2010-1739
SQL injection vulnerability in the Newsfeeds (com_newsfeeds) component for Joomla! allows remote attackers to execute ar
23RISK
open ↗Referência✓ VexDay Proof
Mambo Component com_flyspray < 1.0.1 - Remote File Disclosure
Directory traversal vulnerability in startdown.php in the Flyspray ME 1.0.1 (com_flyspray) component for Mambo allows re
23RISK
open ↗Referência
CVE-2015-7259
ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow user accounts to have multiple valid
23RISK
open ↗Referência
CVE-2026-6109
FoundationAgents MetaGPT Mineflayer HTTP API index.js evaluateCode cross-site request forgery
33RISK
open ↗Referência
CVE-2010-1718
Directory traversal vulnerability in archeryscores.php in the Archery Scores (com_archeryscores) component 1.0.6 for Joo
38RISK
open ↗Referência✓ VexDay Proof
MyNews 4.2.2 - 'themefunc.php' Remote File Inclusion
PHP remote file inclusion vulnerability in include/themes/themefunc.php in MyNews 4.2.2 and earlier allows remote attack
23RISK
open ↗Referência✓ VexDay Proof
CandyPress eCommerce suite 4.1.1.26 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in CandyPress (CP) 4.1.1.26, and earlier 4.1.x versions, allow remote attackers t
23RISK
open ↗Referência
CVE-2009-4752
PHP remote file inclusion vulnerability in anzeiger/start.php in Swinger Club Portal allows remote attackers to execute
23RISK
open ↗Referência
CVE-2010-4283
PHP remote file inclusion vulnerability in extras/pandora_diag.php in Pandora FMS before 3.1.1 allows remote attackers t
23RISK
open ↗Referência
CVE-2018-1002005
These vulnerabilities require administrative privileges to exploit. There is an XSS vulnerability in bft_list.html.php:4
23RISK
open ↗Referência
CVE-2014-2587
SQL injection vulnerability in jsp/reports/ReportsAudit.jsp in McAfee Asset Manager 6.6 allows remote authenticated user
23RISK
open ↗Referência
CVE-2014-2587
SQL injection vulnerability in jsp/reports/ReportsAudit.jsp in McAfee Asset Manager 6.6 allows remote authenticated user
23RISK
open ↗Referência
CVE-2017-11309
Buffer overflow in the SoftConsole client in Avaya IP Office before 10.1.1 allows remote servers to execute arbitrary co
23RISK
open ↗Referência
CVE-2017-11309
Buffer overflow in the SoftConsole client in Avaya IP Office before 10.1.1 allows remote servers to execute arbitrary co
23RISK
open ↗Referência✓ VexDay Proof
Redaction System 1.0 - 'lang_prefix' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Redaction System 1.0000 allow remote attackers to execute arbitrar
23RISK
open ↗Referência
CVE-2020-8495
In Kronos Web Time and Attendance (webTA) 3.8.x and later 3.x versions before 4.0, the com.threeis.webta.H491delegate se
41RISK
open ↗Referência
CVE-2014-3848
The iMember360 plugin before 3.9.001 for WordPress does not properly restrict access, which allows remote attackers to o
23RISK
open ↗Referência
CVE-2014-3848
The iMember360 plugin before 3.9.001 for WordPress does not properly restrict access, which allows remote attackers to o
23RISK
open ↗Referência
CVE-2006-5521
PHP remote file inclusion vulnerability in DNS/RR.php in Net_DNS 0.03 and earlier allows remote attackers to execute arb
23RISK
open ↗Referência✓ VexDay Proof
Net_DNS 0.3 - '/DNS/RR.php' Remote File Inclusion
PHP remote file inclusion vulnerability in DNS/RR.php in Net_DNS 0.03 and earlier allows remote attackers to execute arb
23RISK
open ↗Referência✓ VexDay Proof
vp-asp shopping cart 6.09 - SQL Injection / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in shopcustadmin.asp in VP-ASP Shopping Cart 6.09 and earlier allows remote att
23RISK
open ↗Referência
CVE-2013-4865
Cross-site request forgery (CSRF) vulnerability in upgrade_step2.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows
23RISK
open ↗Referência✓ VexDay Proof
Anthologia 0.5.2 - 'index.php?ads_file' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in Anthologia 0.5.2 allows remote attackers to execute arbitrary PH
23RISK
open ↗Referência✓ VexDay Proof
VisoHotlink 1.01 - 'functions.visohotlink.php' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/functions.visohotlink.php in VisoHotlink 1.01 and possibly earlier a
23RISK
open ↗Referência✓ VexDay Proof
PHP-Generics 1.0.0 Beta - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in PHP-Generics 1.0 beta allow remote attackers to execute arbitrary
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.