Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,001cataloged exploits
34,636CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,662GitHub PoC 13,736VulnCheck XDB 8,460Nuclei 4,233Metasploit 3,467✓ verified onlyrecentpopularrisk
21,624 exploits
Referência
CVE-2018-0826
Windows Storage Services in Windows 10 versions 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, versi
23RISK
open ↗Referência
CVE-2021-35956
Stored cross-site scripting (XSS) in the embedded webserver of AKCP sensorProbe before SP480-20210624 enables remote aut
23RISK
open ↗Referência
CVE-2009-3859
Buffer overflow in eEye Retina WiFi Scanner 1.0.8.68, as used in Retina Network Security Scanner 5.10.14, allows user-as
28RISK
open ↗Referência
CVE-2010-2680
Directory traversal vulnerability in the JExtensions JE Section/Property Finder (jesectionfinder) component for Joomla!
38RISK
open ↗Referência✓ VexDay Proof
Softerra Time-Assistant 6.2 - 'inc_dir' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in lib/timesheet.class.php in Softerra Time-Assistant 6.2 and earlier
23RISK
open ↗Referência✓ VexDay Proof
Move Networks Quantum Streaming Player Control - Remote Buffer Overflow
Stack-based buffer overflow in the Quantum Streaming Player (Quantum Streaming IE Player) ActiveX control (aka QSP2IE.QS
23RISK
open ↗Referência
CVE-2016-1846
The nvCommandQueue::GetHandleIndex method in the NVIDIA Graphics Drivers subsystem in Apple OS X before 10.11.5 allows a
23RISK
open ↗Referência
CVE-2016-1846
The nvCommandQueue::GetHandleIndex method in the NVIDIA Graphics Drivers subsystem in Apple OS X before 10.11.5 allows a
23RISK
open ↗Referência
CVE-2017-11333
The vorbis_analysis_wrote function in lib/block.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial
23RISK
open ↗Referência
CVE-2009-3535
Directory traversal vulnerability in image.php in Clear Content 1.1 allows remote attackers to read arbitrary files via
23RISK
open ↗Referência
CVE-2009-3535
Directory traversal vulnerability in image.php in Clear Content 1.1 allows remote attackers to read arbitrary files via
23RISK
open ↗Referência
CVE-2014-8375
SQL injection vulnerability in GBgallery.php in the GB Gallery Slideshow plugin 1.5 for WordPress allows remote administ
23RISK
open ↗Referência
CVE-2018-1123
procps-ng before version 3.3.15 is vulnerable to a denial of service in ps via mmap buffer overflow. Inbuilt protection
28RISK
open ↗Referência
CVE-2016-1610
Directory traversal vulnerability in the email-template feature in Novell Filr before 1.2 Security Update 3 and 2.0 befo
28RISK
open ↗Referência✓ VexDay Proof
MiniBB keyword_replacer 1.0 - 'pathToFiles' File Inclusion
PHP remote file inclusion vulnerability in addon_keywords.php in Keyword Replacer (keyword_replacer) 1.0 and earlier, a
23RISK
open ↗Referência
CVE-2009-4757
Stack-based buffer overflow in BrotherSoft EW-MusicPlayer 0.8 allows remote attackers to cause a denial of service (appl
23RISK
open ↗Referência✓ VexDay Proof
RunCMS 1.5.2 - 'debug_show.php' SQL Injection
SQL injection vulnerability in class/debug/debug_show.php in RunCms 1.5.2 and earlier allows remote attackers to execute
23RISK
open ↗Referência✓ VexDay Proof
QuickTicket 1.5 - 'qti_usr.php' SQL Injection
Multiple SQL injection vulnerabilities in QuickTicket 1.2 build:20070621 and QuickTalk Forum 1.3 allow remote attackers
23RISK
open ↗Referência✓ VexDay Proof
Microsoft Visual 6 - 'VDT70.dll NotSafe' Remote Stack Overflow
Stack-based buffer overflow in a certain ActiveX control in VDT70.DLL in Microsoft Visual Database Tools Database Design
28RISK
open ↗Referência✓ VexDay Proof
PHPbbBook 1.3 - 'bbcode.php?l' Local File Inclusion
Directory traversal vulnerability in bbcode.php in PHPbbBook 1.3 and 1.3h allows remote attackers to include and execute
23RISK
open ↗Referência✓ VexDay Proof
Elecard AVC HD Player - '.XPL' Stack Buffer Overflow (SEH) (PoC)
Stack-based buffer overflow in Elecard AVC HD Player allows remote attackers to execute arbitrary code via a long MP3 fi
23RISK
open ↗Referência
CVE-2006-2315
PHP remote file inclusion vulnerability in session.inc.php in ISPConfig 2.2.2 and earlier allows remote attackers to exe
23RISK
open ↗Referência
CVE-2015-7235
Multiple SQL injection vulnerabilities in dex_reservations.php in the CP Reservation Calendar plugin before 1.1.7 for Wo
23RISK
open ↗Referência
CVE-2018-20326
ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have XSS via the cgi-bin/webproc?getpage
23RISK
open ↗Referência
CVE-2018-20326
ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have XSS via the cgi-bin/webproc?getpage
23RISK
open ↗Referência
CVE-2009-2736
Static code injection vulnerability in admin.php in sun-jester OpenNews 1.0 allows remote authenticated administrators t
23RISK
open ↗Referência
CVE-2009-4372
AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows
23RISK
open ↗Referência
CVE-2015-6008
install.php in Web Reference Database (aka refbase) through 0.9.6 allows remote attackers to execute arbitrary commands
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.