Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,647cataloged exploits
34,986CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,899GitHub PoC 14,014VulnCheck XDB 8,571Nuclei 4,248Metasploit 3,472✓ verified onlyrecentpopularrisk
21,899 exploits
Referência
CVE-2015-2564
SQL injection vulnerability in client-edit.php in ProjectSend (formerly cFTP) r561 allows remote authenticated users to
23RISK
open ↗Referência
CVE-2019-9184
SQL injection vulnerability in the J2Store plugin 3.x before 3.3.7 for Joomla! allows remote attackers to execute arbitr
23RISK
open ↗Referência
CVE-2011-5233
Heap-based buffer overflow in IrfanView before 4.32 allows remote attackers to execute arbitrary code via crafted "Rows
23RISK
open ↗Referência
CVE-2019-6224
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Mojave 10.
23RISK
open ↗Referência
CVE-2013-4985
Multiple Vivotek IP Cameras remote authentication bypass that could allow access to the video stream
23RISK
open ↗Referência
CVE-2026-2017
IP-COM W30AP POST Request wx3auth R7WebsSecurityHandler stack-based overflow
48RISK
open ↗Referência
CVE-2017-16884
Cross-site scripting (XSS) vulnerability in MistServer before 2.13 allows remote attackers to inject arbitrary web scrip
23RISK
open ↗Referência
CVE-2017-16884
Cross-site scripting (XSS) vulnerability in MistServer before 2.13 allows remote attackers to inject arbitrary web scrip
23RISK
open ↗Referência
CVE-2018-16302
MediaComm Zip-n-Go before 4.95 has a Buffer Overflow via a crafted file.
23RISK
open ↗Referência
CVE-2016-5348
The GPS component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 be
23RISK
open ↗Referência✓ VexDay Proof
pandaBB - 'displayCategory' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in modules/My_eGallery/public/displayCategory.php in the pandaBB modu
23RISK
open ↗Referência
CVE-2012-6644
Multiple cross-site scripting (XSS) vulnerabilities in ClipBucket 2.6 allow remote attackers to inject arbitrary web scr
23RISK
open ↗Referência✓ VexDay Proof
IrfanView 4.00 - '.iff' Local Buffer Overflow
Buffer overflow in IrfanView 4.00 and earlier allows user-assisted remote attackers to execute arbitrary code via a craf
23RISK
open ↗Referência✓ VexDay Proof
Mini File Host 1.x - Arbitrary '.PHP' File Upload
Unrestricted file upload vulnerability in Mini File Host 1.5 allows remote attackers to execute arbitrary code by upload
23RISK
open ↗Referência✓ VexDay Proof
Exodus 0.10 - URI Handler Arbitrary Parameter Injection (2)
Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, over
23RISK
open ↗Referência
CVE-2018-9926
An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add an admin account via index.php?m=
23RISK
open ↗Referência
CVE-2017-14096
A stored cross site scripting (XSS) vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and b
23RISK
open ↗Referência
CVE-2017-7446
HelpDEZk 1.1.1 has CSRF in admin/home#/person/ with an impact of obtaining admin privileges.
23RISK
open ↗Referência
CVE-2025-34101
Serviio Media Server Unauthenticated Command Injection via checkStreamUrl VIDEO Parameter
63RISK
open ↗Referência
CVE-2015-8258
AXIS Communications products with firmware through 5.80.x allow remote attackers to modify arbitrary files as root via v
23RISK
open ↗Referência
CVE-2025-34101
Serviio Media Server Unauthenticated Command Injection via checkStreamUrl VIDEO Parameter
63RISK
open ↗Referência
CVE-2025-34101
Serviio Media Server Unauthenticated Command Injection via checkStreamUrl VIDEO Parameter
63RISK
open ↗Referência
CVE-2025-34101
Serviio Media Server Unauthenticated Command Injection via checkStreamUrl VIDEO Parameter
63RISK
open ↗Referência
CVE-2014-4643
Multiple heap-based buffer overflows in the client in Core FTP LE 2.2 build 1798 allow remote FTP servers to cause a den
23RISK
open ↗Referência
CVE-2010-5002
Cross-site scripting (XSS) vulnerability in modules/slideshowmodule/slideshow.js.php in Exponent CMS 0.97.0 allows remot
23RISK
open ↗Referência
CVE-2017-6020
Leao Consultoria e Desenvolvimento de Sistemas (LCDS) LTDA ME LAquis SCADA software versions prior to version 4.1.0.3237
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.