Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,647cataloged exploits
34,986CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,899GitHub PoC 14,014VulnCheck XDB 8,571Nuclei 4,248Metasploit 3,472✓ verified onlyrecentpopularrisk
21,899 exploits
Referência✓ VexDay Proof
Mambo Module Calendar (Agenda) 1.5.5 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in the Calendar Module (com_calendar) 1.5.5 for Mambo allow remote at
23RISK
open ↗Referência
CVE-2022-1040
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sopho
100RISK
open ↗Referência✓ VexDay Proof
RicarGBooK 1.2.1 - 'lang' Local File Inclusion
Multiple directory traversal vulnerabilities in header.php in RicarGBooK 1.2.1 allow remote attackers to include and exe
23RISK
open ↗Referência
CVE-2020-7961
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RISK
open ↗Referência
CVE-2020-7961
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RISK
open ↗Referência
CVE-2009-4935
SQL injection vulnerability in ogp_show.php in Online Guestbook Pro allows remote attackers to execute arbitrary SQL com
23RISK
open ↗Referência✓ VexDay Proof
openMairie 1.10 - '/scr/soustab.php' Local File Inclusion
Directory traversal vulnerability in scr/soustab.php in openMairie 1.11 and earlier allows remote attackers to include a
23RISK
open ↗Referência✓ VexDay Proof
XAMPP for Windows 1.6.0a - 'mssql_connect()' Remote Buffer Overflow
Multiple SQL injection vulnerabilities in XAMPP 1.6.0a for Windows allow remote attackers to execute arbitrary SQL comma
23RISK
open ↗Referência
CVE-2021-31207
Microsoft Exchange Server Security Feature Bypass Vulnerability
100RISK
open ↗Referência
CVE-2019-15107
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open ↗Referência
CVE-2025-34103
WePresent WiPG-1000 Unauthenticated Command Injection in via rdfs.cgi
63RISK
open ↗Referência✓ VexDay Proof
Joomla! / Mambo Component New Article 1.1 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in the Jx Development Article 1.1 and earlier component for Mambo and
23RISK
open ↗Referência✓ VexDay Proof
xoops module tsdisplay4xoops 0.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in blocks/tsdisplay4xoops_block2.php in tsdisplay4xoops (TSD4XOOPS, aka the Team
23RISK
open ↗Referência
CVE-2026-6379
WP Photo Album Plus < 9.1.11.001 - Unauthenticated SQL Injection via 'wppa-supersearch' Parameter
41RISK
open ↗Referência
Sophos XG115w Firewall 17.0.10 MR-10 - Authentication Bypass
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sopho
100RISK
open ↗Referência
CVE-2022-47966
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RISK
open ↗Referência
CVE-2022-47966
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RISK
open ↗Referência
CVE-2022-47966
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RISK
open ↗Referência✓ VexDay Proof
audioCMS arash 0.1.4 - 'arashlib_dir' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in audioCMS arash 0.1.4 allow remote attackers to execute arbitrary P
23RISK
open ↗Referência✓ VexDay Proof
NMDeluxe 1.0.1 - 'footer.php?template' Local File Inclusion
Directory traversal vulnerability in includes/footer.php in News Manager Deluxe (NMDeluxe) 1.0.1 allows remote attackers
23RISK
open ↗Referência✓ VexDay Proof
Quick and Dirty Blog (qdblog) 0.4 - SQL Injection / Local File Inclusion
Multiple directory traversal vulnerabilities in Quick and Dirty Blog (QDBlog) 0.4, and possibly earlier, allow remote at
23RISK
open ↗Referência✓ VexDay Proof
JulmaCMS 1.4 - 'file.php' Remote File Disclosure
Directory traversal vulnerability in file.php in JulmaCMS 1.4 allows remote attackers to read arbitrary files via a .. (
23RISK
open ↗Referência✓ VexDay Proof
CreaDirectory 1.2 - 'error.asp?id' SQL Injection
SQL injection vulnerability in error.asp in CreaScripts CreaDirectory 1.2 allows remote attackers to execute arbitrary S
23RISK
open ↗Referência✓ VexDay Proof
burnCMS 0.2 - 'root' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in burnCMS 0.2 and earlier allow remote attackers to execute arbitrar
23RISK
open ↗Referência✓ VexDay Proof
Photoshop CS2/CS3 / Paint Shop Pro 11.20 - '.png' Local Buffer Overflow
Buffer overflow in Adobe Photoshop CS2 and CS3, Photoshop Elements 5.0, Illustrator CS3, and GoLive 9 allows user-assist
35RISK
open ↗Referência✓ VexDay Proof
Photoshop CS2/CS3 / Paint Shop Pro 11.20 - '.png' Local Buffer Overflow
Buffer overflow in Corel Paint Shop Pro 11.20 allows user-assisted remote attackers to execute arbitrary code via a craf
35RISK
open ↗Referência✓ VexDay Proof
WebSPELL 4.01.02 - 'picture.php' File Disclosure
picture.php in WebSPELL 4.01.02 and earlier allows remote attackers to read arbitrary files via the file parameter.
23RISK
open ↗Referência
CVE-2009-4988
Stack-based buffer overflow in NT_Naming_Service.exe in SAP Business One 2005 A 6.80.123 and 6.80.320 allows remote atta
50RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.