Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,647cataloged exploits
34,986CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,899GitHub PoC 14,014VulnCheck XDB 8,571Nuclei 4,248Metasploit 3,472✓ verified onlyrecentpopularrisk
21,899 exploits
Referência
CVE-2021-25298
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi
100RISK
open ↗Referência✓ VexDay Proof
PHP-Update 2.7 - '/admin/uploads.php' Remote Code Execution
Unrestricted file upload vulnerability in admin/uploads.php in PHP-Update 2.7 and earlier allows remote authenticated us
23RISK
open ↗Referência
CVE-2026-9377
SourceCodester SUP Online Shopping productedit.php cross site scripting
33RISK
open ↗Referência✓ VexDay Proof
PHP-Update 2.7 - Multiple Vulnerabilities
Unrestricted file upload vulnerability in admin/uploads.php in PHP-Update 2.7 and earlier allows remote authenticated us
23RISK
open ↗Referência✓ VexDay Proof
PHP-Update 2.7 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in code/guestadd.php in PHP-Update 2.7 and earlier allow remote attackers to exec
23RISK
open ↗Referência✓ VexDay Proof
Vz (Adp) Forum 2.0.3 - Remote Password Disclosure
Vz (Adp) Forum 2.0.3 stores sensitive information under the web root with insufficient access control, which allows remo
23RISK
open ↗Referência✓ VexDay Proof
Nitrotech 0.0.3a - Remote Code Execution
Directory traversal vulnerability in includes/common.php in NitroTech 0.0.3a, as distributed before 2006, allows remote
23RISK
open ↗Referência
CVE-2023-4278
MasterStudy LMS < 3.0.18 - Unauthenticated Instructor Account Creation
41RISK
open ↗Referência
CVE-2023-4278
MasterStudy LMS < 3.0.18 - Unauthenticated Instructor Account Creation
41RISK
open ↗Referência✓ VexDay Proof
FreeWebShop.org script 2.2.2 - Multiple Vulnerabilities
index.php in FreeWebshop 2.2.2 and earlier allows remote attackers to obtain sensitive information via an invalid action
23RISK
open ↗Referência
glibc 2.38 - Buffer Overflow
Glibc: buffer overflow in ld.so leading to privilege escalation
100RISK
open ↗Referência
CVE-2026-23760
SmarterTools SmarterMail < Build 9511 Authentication Bypass via Password Reset API
100RISK
open ↗Referência
CVE-2023-6553
Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
85RISK
open ↗Referência
CVE-2015-1497
radexecd.exe in Persistent Systems Radia Client Automation (RCA) 7.9, 8.1, 9.0, and 9.1 allows remote attackers to execu
60RISK
open ↗Referência
CVE-2015-1497
radexecd.exe in Persistent Systems Radia Client Automation (RCA) 7.9, 8.1, 9.0, and 9.1 allows remote attackers to execu
60RISK
open ↗Referência
VirtualBox 7.0.16 - Privilege Escalation
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
41RISK
open ↗Referência
CVE-2022-24112
apisix/batch-requests plugin allows overwriting the X-REAL-IP header
100RISK
open ↗Referência✓ VexDay Proof
Linux Kernel 2.6.x - 'sys_timer_create()' Local Denial of Service
The sys_timer_create function in posix-timers.c for Linux kernel 2.6.x allows local users to cause a denial of service (
23RISK
open ↗Referência
Microsoft Windows 11 - Kernel Privilege Escalation
Windows Kernel Elevation of Privilege Vulnerability
83RISK
open ↗Referência✓ VexDay Proof
TinyPHP Forum 3.6 - 'profile.php' Remote Code Execution
Directory traversal vulnerability in profile.php in TinyPHPforum 3.6 and earlier allows remote attackers to include and
23RISK
open ↗Referência✓ VexDay Proof
PhpNews 1.0 - 'Include' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in PhpNews 1.0 allow remote attackers to execute arbitrary PHP code v
23RISK
open ↗Referência
CVE-2015-4852
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers
100RISK
open ↗Referência
CVE-2015-1497
radexecd.exe in Persistent Systems Radia Client Automation (RCA) 7.9, 8.1, 9.0, and 9.1 allows remote attackers to execu
60RISK
open ↗Referência
CVE-2014-3871
Multiple SQL injection vulnerabilities in register.php in Geodesic Solutions GeoCore MAX 7.3.3 (formerly GeoClassifieds
23RISK
open ↗Referência
ManageEngine Application Manager 14.2 - Privilege Escalation / Remote Command Execution (Metasploit)
An issue was discovered in Zoho ManageEngine Application Manager through 14.2. There is a SQL Injection vulnerability in
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.