Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,107cataloged exploits
34,679CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,692GitHub PoC 13,812VulnCheck XDB 8,460Nuclei 4,233Metasploit 3,467✓ verified onlyrecentpopularrisk
21,692 exploits
Referência
CVE-2010-4781
index.php in Enano CMS 1.1.7pl1, and possibly other versions before 1.1.8, 1.0.6pl3, and 1.1.7pl2, allows remote attacke
23RISK
open ↗Referência
CVE-2007-0122
Multiple SQL injection vulnerabilities in Coppermine Photo Gallery 1.4.10 and earlier allow remote authenticated adminis
23RISK
open ↗Referência✓ VexDay Proof
open NewsLetter 2.5 - Multiple Vulnerabilities (2)
Open Newsletter 2.5 and earlier allows remote authenticated administrators to execute arbitrary PHP code by inserting th
23RISK
open ↗Referência✓ VexDay Proof
PHPFootball 1.6 - Remote Database Disclosure
show.php in Vlad Alexa Mancini PHPFootball 1.6 allows remote attackers to obtain sensitive information (database content
23RISK
open ↗Referência✓ VexDay Proof
Xpression News 1.0.1 - 'archives.php' Remote File Disclosure
Directory traversal vulnerability in archives.php in Xpression News (X-News) 1.0.1 allows remote attackers to include ar
23RISK
open ↗Referência✓ VexDay Proof
db Software Laboratory VImpX - 'VImpX.ocx' Multiple Vulnerabilities
Multiple insecure method vulnerabilities in the VImpX.VImpAX ActiveX control (VImpX.ocx) 4.8.8.0 in DB Software Laborato
23RISK
open ↗Referência✓ VexDay Proof
Ez Ringtone Manager - Multiple Remote File Disclosure Vulnerabilities
Multiple directory traversal vulnerabilities in Ez Ringtone Manager allow remote attackers to read arbitrary files via a
23RISK
open ↗Referência
CVE-2015-6965
Multiple cross-site request forgery (CSRF) vulnerabilities in the Contact Form Generator plugin 2.0.1 and earlier for Wo
23RISK
open ↗Referência
CVE-2015-6965
Multiple cross-site request forgery (CSRF) vulnerabilities in the Contact Form Generator plugin 2.0.1 and earlier for Wo
23RISK
open ↗Referência
Genexis Platinum 4410 Router 2.1 - UPnP Credential Exposure
UPNP Service listening on port 5555 in Genexis Platinum 4410 Router V2.1 (P4410-V2–1.34H) has an action 'X_GetAccess' wh
23RISK
open ↗Referência
CVE-2010-1918
SQL injection vulnerability in ask_chat.php in eFront 3.6.2 and earlier allows remote attackers to execute arbitrary SQL
23RISK
open ↗Referência
CVE-2019-7671
Prima Systems FlexAir, Versions 2.3.38 and prior. Parameters sent to scripts are not properly sanitized before being ret
23RISK
open ↗Referência
CVE-2017-11785
The Microsoft Windows Kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Wind
23RISK
open ↗Referência
CVE-2017-8564
Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and
23RISK
open ↗Referência
CVE-2017-2508
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The
23RISK
open ↗Referência✓ VexDay Proof
Hitweb 4.2.1 - 'REP_INC' Remote File Inclusion
PHP remote file inclusion vulnerability in genpage-cgi.php in Brian Fraval hitweb 4.2 and possibly earlier versions allo
23RISK
open ↗Referência✓ VexDay Proof
ACGV News 0.9.1 - 'article.php' Remote File Inclusion
PHP remote file inclusion vulnerability in article.php in ACGV News 0.9.1 and earlier allows remote attackers to execute
23RISK
open ↗Referência✓ VexDay Proof
Spaminator 1.7 - 'page' Remote File Inclusion
PHP remote file inclusion vulnerability in Login.php in Spaminator 1.7 and earlier allows remote attackers to execute ar
23RISK
open ↗Referência✓ VexDay Proof
phpBB Journals System Mod 1.0.2 RC2 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in the Journals System module 1.0.2 (RC2) and earlier for phpBB allow
23RISK
open ↗Referência✓ VexDay Proof
MyABraCaDaWeb 1.0.3 - 'base' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in MyABraCaDaWeb 1.0.3, when register_globals is enabled, allow remot
23RISK
open ↗Referência✓ VexDay Proof
Formbankserver 1.9 - 'Name' Remote Denial of Service
formbankcgi.exe in Fersch Formbankserver 1.9, when the PATH_INFO begins with Abfrage, allows remote attackers to cause a
23RISK
open ↗Referência✓ VexDay Proof
PHP 5.2.3 - 'bz2 com_print_typeinfo()' Denial of Service
The com_print_typeinfo function in the bz2 extension in PHP 5.2.3 allows context-dependent attackers to cause a denial o
23RISK
open ↗Referência✓ VexDay Proof
PHP iCalendar 2.24 - Insecure Cookie Handling
PHP iCalendar 2.24 and earlier allows remote attackers to bypass authentication by setting the phpicalendar and phpicale
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component com_Projectfork 2.0.10 - Local File Inclusion
Directory traversal vulnerability in the JoomlaPraise Projectfork (com_projectfork) component 2.0.10 for Joomla! allows
38RISK
open ↗Referência✓ VexDay Proof
Campsite 3.3.0 RC1 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Campsite 3.3.0 RC1 allow remote attackers to execute arbitrary PHP
23RISK
open ↗Referência
CVE-2020-26808
SAP AS ABAP(DMIS), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2011_1_752, 2020 a
48RISK
open ↗Referência
CVE-2018-4241
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS b
23RISK
open ↗Referência
CVE-2009-4251
Stack-based buffer overflow in Jasc Paint Shop Pro 8.10 (aka Corel Paint Shop Pro) allows user-assisted remote attackers
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.