Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,542cataloged exploits
34,971CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,899GitHub PoC 13,947VulnCheck XDB 8,542Nuclei 4,243Metasploit 3,468✓ verified onlyrecentpopularrisk
21,899 exploits
Referência
CVE-2017-20275
Joomla! Component PHP-Bridge 1.2.3 SQL Injection via id Parameter
41RISK
open ↗Referência
CVE-2017-20274
Joomla LMS King Professional 3.2.4.0 SQL Injection via learningpath
41RISK
open ↗Referência✓ VexDay Proof
Borland Interbase 2007 - 'ibserver.exe' Buffer Overflow (PoC)
Stack-based buffer overflow in the database service (ibserver.exe) in Borland InterBase 2007 SP2 allows remote attackers
23RISK
open ↗Referência
CVE-2017-20272
Joomla Ultimate Property Listing 1.0.2 SQL Injection via sf_selectuser_id
41RISK
open ↗Referência✓ VexDay Proof
1024 CMS 1.4.2 - Local File Inclusion / Blind SQL Injection
SQL injection vulnerability in includes/system.php in 1024 CMS 1.4.2 beta and earlier, when magic_quotes_gpc is disabled
23RISK
open ↗Referência✓ VexDay Proof
DivX Player 6.7 - '.srt' File Subtitle Parsing Buffer Overflow
Stack-based buffer overflow in DivX Player 6.7 build 6.7.0.22 and earlier allows user-assisted remote attackers to cause
28RISK
open ↗Referência
CVE-2026-7604
JeecgBoot OpenApi Service OpenApiController.java OpenApiController.call server-side request forgery
33RISK
open ↗Referência
CVE-2026-7401
SourceCodester CET Automated Grading System with AI Predictive Analytics Registration index.php register cross site scripting
33RISK
open ↗Referência
CVE-2026-7400
geekgod382 filesystem-mcp-server read_file_tool/write_file_tool server.py is_path_allowed path traversal
33RISK
open ↗Referência✓ VexDay Proof
Watchfire Appscan 7.0 - ActiveX Multiple Insecure Methods
Multiple absolute path traversal vulnerabilities in certain ActiveX controls in WatchFire AppScan 7.0 allow remote attac
23RISK
open ↗Referência
CVE-2026-7319
elinsky execution-system-mcp add_action Tool server.py _get_context_file_path path traversal
33RISK
open ↗Referência
CVE-2026-7316
eiliyaabedini aider-mcp code_with_ai aider_mcp.py command injection
33RISK
open ↗Referência
CVE-2026-7314
eiceblue spire-doc-mcp-server base.py get_doc_path path traversal
33RISK
open ↗Referência✓ VexDay Proof
Megabbs Forum 2.2 - SQL Injection / Cross-Site Scripting
Multiple SQL injection vulnerabilities in PD9 Software MegaBBS 2.2 allow remote attackers to execute arbitrary SQL comma
23RISK
open ↗Referência✓ VexDay Proof
MiniBB 2.2 - Cross-Site Scripting / SQL Injection / Full Path Disclosure
Cross-site scripting (XSS) vulnerability in index.php in miniBB 2.2, and possibly earlier, when register_globals is enab
23RISK
open ↗Referência✓ VexDay Proof
MiniBB 2.2 - Cross-Site Scripting / SQL Injection / Full Path Disclosure
Multiple SQL injection vulnerabilities in (1) setup_mysql.php and (2) setup_options.php in miniBB 2.2 and possibly earli
23RISK
open ↗Referência✓ VexDay Proof
Dream4 Koobi Pro 6.25 Poll - 'poll_id' SQL Injection
SQL injection vulnerability in index.php in dream4 Koobi Pro 6.25 allows remote attackers to execute arbitrary SQL comma
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.