Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,008cataloged exploits
34,638CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,662GitHub PoC 13,743VulnCheck XDB 8,460Nuclei 4,233Metasploit 3,467✓ verified onlyrecentpopularrisk
21,624 exploits
Referência
CVE-2010-1945
Multiple PHP remote file inclusion vulnerabilities in openMairie Openfoncier 2.00, when register_globals is enabled, all
23RISK
open ↗Referência
CVE-2019-16223
WordPress before 5.2.3 allows XSS in post previews by authenticated users.
23RISK
open ↗Referência✓ VexDay Proof
Libxine 1.14 - MPEG Stream Buffer Overflow (PoC)
Buffer overflow in xine_list_delete_current in libxine 1.14 and earlier, as distributed in xine-lib 1.1.1 and earlier, a
28RISK
open ↗Referência
CVE-2023-4112
PHP Jabbers Shuttle Booking Software index.php cross site scripting
48RISK
open ↗Referência
CVE-2018-12981
An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerabilit
23RISK
open ↗Referência
CVE-2014-9097
Multiple SQL injection vulnerabilities in the Apptha WordPress Video Gallery (contus-video-gallery) plugin 2.5, possibly
23RISK
open ↗Referência
CVE-2017-6098
A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/camp
23RISK
open ↗Referência✓ VexDay Proof
Crafty Syntax Image Gallery 3.1g - Remote Code Execution
SQL injection vulnerability in slides.php in Eric Gerdes Crafty Syntax Image Gallery (CSIG) (aka PHP thumbnail Photo Gal
23RISK
open ↗Referência
CVE-2009-2361
SQL injection vulnerability in include/class.staff.php in osTicket before 1.6 RC5 allows remote attackers to execute arb
23RISK
open ↗Referência
CVE-2018-16517
asm/labels.c in Netwide Assembler (NASM) is prone to NULL Pointer Dereference, which allows the attacker to cause a deni
23RISK
open ↗Referência
CVE-2018-16517
asm/labels.c in Netwide Assembler (NASM) is prone to NULL Pointer Dereference, which allows the attacker to cause a deni
23RISK
open ↗Referência✓ VexDay Proof
VRNews 1.1.1 - 'admin.php' Remote Security Bypass
admin.php in VRNews 1.1.1, and possibly other 1.x versions, does not require authentication, which allows remote attacke
23RISK
open ↗Referência
CVE-2008-1247
The web interface on the Linksys WRT54g router with firmware 1.00.9 does not require credentials when invoking scripts,
23RISK
open ↗Referência✓ VexDay Proof
Macrovision FlexNet - 'isusweb.dll' DownloadAndExecute Method
Insecure method vulnerability in the MVSNCLientWebAgent61.WebAgent.1 ActiveX control (isusweb.dll 6.1.100.61372) in Macr
23RISK
open ↗Referência
CVE-2010-1176
Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash)
23RISK
open ↗Referência
CVE-2018-4121
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud b
28RISK
open ↗Referência
CVE-2019-19031
Easy XML Editor through v1.7.8 is affected by: XML External Entity Injection. The impact is: Arbitrary File Read and DoS
23RISK
open ↗Referência
CVE-2019-7652
TheHive Project UnshortenLink analyzer before 1.1, included in Cortex-Analyzers before 1.15.2, has SSRF. To exploit the
23RISK
open ↗Referência
CVE-2025-14709
Shiguangwu sgwbox N3 WIRELESSCFGGET http_eshell_server buffer overflow
48RISK
open ↗Referência
CVE-2011-0961
Cross-site scripting (XSS) vulnerability in cwhp/device.center.do in the Help servlet in Cisco CiscoWorks Common Service
23RISK
open ↗Referência✓ VexDay Proof
runawaysoft haber portal 1.0 - 'tr' Multiple Vulnerabilities
RunawaySoft Haber portal 1.0 stores sensitive information under the web root with insufficient access control, which all
23RISK
open ↗Referência
CVE-2015-1368
Multiple cross-site scripting (XSS) vulnerabilities in Ansible Tower (aka Ansible UI) before 2.0.5 allow remote attacker
23RISK
open ↗Referência
CVE-2015-1368
Multiple cross-site scripting (XSS) vulnerabilities in Ansible Tower (aka Ansible UI) before 2.0.5 allow remote attacker
23RISK
open ↗Referência
CVE-2018-5759
jsparse.c in Artifex MuJS through 1.0.2 does not properly maintain the AST depth for binary expressions, which allows re
23RISK
open ↗Referência
CVE-2016-4793
The clientIp function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the CLIENT-IP HTTP head
23RISK
open ↗Referência
CVE-2010-2549
Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Vista SP1 and SP2 and Server 2008 Gold and
23RISK
open ↗Referência
CVE-2016-1803
CoreCapture in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers
23RISK
open ↗Referência
CVE-2016-1803
CoreCapture in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.