Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,313cataloged exploits
34,834CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,797GitHub PoC 13,885VulnCheck XDB 8,484Nuclei 4,237Metasploit 3,467✓ verified onlyrecentpopularrisk
21,692 exploits
Referência
CVE-2014-6389
backup.php in PHPCompta/NOALYSS before 6.7.2 allows remote attackers to execute arbitrary commands via shell metacharact
23RISK
open ↗Referência
CVE-2014-6389
backup.php in PHPCompta/NOALYSS before 6.7.2 allows remote attackers to execute arbitrary commands via shell metacharact
23RISK
open ↗Referência
CVE-2014-9144
Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to execute arbitrary commands via shell metac
23RISK
open ↗Referência
CVE-2009-5135
The Java XML parser in Echo before 2.1.1 and 3.x before 3.0.b6 allows remote attackers to read arbitrary files via a req
23RISK
open ↗Referência
CVE-2007-6584
Multiple directory traversal vulnerabilities in 1024 CMS 1.3.1 allow remote attackers to include and execute arbitrary l
23RISK
open ↗Referência
CVE-2015-3986
Cross-site request forgery (CSRF) vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPr
23RISK
open ↗Referência
CVE-2015-3986
Cross-site request forgery (CSRF) vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPr
23RISK
open ↗Referência
CVE-2017-9746
The disassemble_bytes function in objdump.c in GNU Binutils 2.28 allows remote attackers to cause a denial of service (b
23RISK
open ↗Referência✓ VexDay Proof
Easy Scripts Answer and Question Script - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in myaccount.php in Easy Scripts Answer and Question Script allow remote authenti
23RISK
open ↗Referência✓ VexDay Proof
Groupit 2.00b5 - 'c_basepath' Remote File Inclusion
Variable overwrite vulnerability in groupit/base/groupit.start.inc in Groupit 2.00b5 allows remote attackers to conduct
23RISK
open ↗Referência✓ VexDay Proof
McAfee E-Business Server 8.5.2 - Remote Code Execution / Denial of Service (PoC)
The administration interface in McAfee E-Business Server 8.5.2 and earlier allows remote attackers to cause a denial of
23RISK
open ↗Referência✓ VexDay Proof
Fuzzylime CMS 3.01 - 'commrss.php' Remote Code Execution
Directory traversal vulnerability in commsrss.php in fuzzylime (cms) before 3.01b allows remote attackers to include and
23RISK
open ↗Referência
CVE-2017-2800
A specially crafted x509 certificate can cause a single out of bounds byte overwrite in wolfSSL through 3.10.2 resulting
41RISK
open ↗Referência
CVE-2020-8794
OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for mult
60RISK
open ↗Referência
CVE-2010-3128
Untrusted search path vulnerability in TeamViewer 5.0.8703 and earlier allows local users, and possibly remote attackers
23RISK
open ↗Referência
CVE-2017-2471
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. watchOS
23RISK
open ↗Referência
CVE-2014-4912
An Arbitrary File Upload issue was discovered in Frog CMS 0.9.5 due to lack of extension validation.
23RISK
open ↗Referência
CVE-2018-7316
Arbitrary File Upload exists in the Proclaim 9.1.1 component for Joomla! via a mediafileform action.
23RISK
open ↗Referência
CVE-2010-1132
The mlfi_envrcpt function in spamass-milter.cpp in SpamAssassin Milter Plugin 0.3.1, when using the expand option, allow
23RISK
open ↗Referência
CVE-2017-9749
The *regs* macros in opcodes/bfin-dis.c in GNU Binutils 2.28 allow remote attackers to cause a denial of service (buffer
23RISK
open ↗Referência
CVE-2008-4558
Array index error in VLC media player 0.9.2 allows remote attackers to overwrite arbitrary memory and execute arbitrary
23RISK
open ↗Referência
CVE-2010-1302
Directory traversal vulnerability in dwgraphs.php in the DecryptWeb DW Graphs (com_dwgraphs) component 1.0 for Joomla! a
38RISK
open ↗Referência✓ VexDay Proof
Eggdrop/Windrop 1.6.19 - ctcpbuf Remote Crash
mod/server.mod/servmsg.c in Eggheads Eggdrop and Windrop 1.6.19 and earlier allows remote attackers to cause a denial of
23RISK
open ↗Referência✓ VexDay Proof
Mozilla Firefox 3.0.5 - location.hash Remote Crash
Mozilla Firefox 3.0.5 on Windows Vista allows remote attackers to cause a denial of service (application crash) via Java
23RISK
open ↗Referência
CVE-2017-14704
Multiple unrestricted file upload vulnerabilities in the (1) imageSubmit and (2) proof_submit functions in Claydip Larav
23RISK
open ↗Referência
CVE-2012-4253
Multiple directory traversal vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to read arbitrary files via a
38RISK
open ↗Referência
CVE-2017-1000499
phpMyAdmin versions 4.7.x (prior to 4.7.6.1/4.7.7) are vulnerable to a CSRF weakness. By deceiving a user to click on a
23RISK
open ↗Referência
CVE-2018-8002
In PoDoFo 0.9.5, there exists an infinite loop vulnerability in PdfParserObject::ParseFileComplete() in PdfParserObject.
23RISK
open ↗Referência
CVE-2010-4181
Directory traversal vulnerability in Yaws 1.89 allows remote attackers to read arbitrary files via ..\ (dot dot backslas
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.