Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,058cataloged exploits
35,300CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,175GitHub PoC 14,096VulnCheck XDB 8,607Nuclei 4,255Metasploit 3,474✓ verified onlyrecentpopularrisk
22,166 exploits
Referência
CVE-2026-9476
Totolink A8000RU Web Management cstecgi.cgi setPasswordCfg os command injection
48RISK
open ↗Referência
CVE-2026-9465
Tiandy Easy7 Integrated Management Platform GetDBDataEx.jsp sql injection
33RISK
open ↗Referência
CVE-2018-25380
Joomla Component eXtroForms 2.1.5 SQL Injection via filter parameters
41RISK
open ↗Referência
CVE-2018-25374
Softneta MedDream PACS Server Premium 6.7.1.1 Directory Traversal
41RISK
open ↗Referência
CVE-2016-4372
HPE iMC PLAT before 7.2 E0403P04, iMC EAD before 7.2 E0405P05, iMC APM before 7.2 E0401P04, iMC NTA before 7.2 E0401P01,
28RISK
open ↗Referência
CVE-2016-6854
An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code which got injected to a mail with inline
23RISK
open ↗Referência
CVE-2016-6854
An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code which got injected to a mail with inline
23RISK
open ↗Referência
Zhiyuan OA - arbitrary file upload leading
Seeyon Zhiyuan OA System Path Traversal File Upload
68RISK
open ↗Referência
WordPress Madara - Local File Inclusion
Madara – Responsive and modern WordPress theme for manga sites <= 2.2.2 - Unauthenticated Local File Inclusion
63RISK
open ↗Referência
CVE-2018-19862
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP POST re
28RISK
open ↗Referência
CVE-2018-19862
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP POST re
28RISK
open ↗Referência
CVE-2018-20062
An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP
100RISK
open ↗Referência
CVE-2016-7661
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. The is
23RISK
open ↗Referência✓ VexDay Proof
XOOPS 2.0.13.2 - 'xoopsOption[nocommon]' Remote Command Execution
mainfile.php in XOOPS 2.0.13.2 and earlier, when register_globals is enabled, allows remote attackers to overwrite varia
23RISK
open ↗Referência✓ VexDay Proof
phpListPro 2.0.1 - 'Language' Remote Code Execution
PHP remote file inclusion vulnerability in config.php in phpListPro 2.0.1 and earlier, with magic_quotes_gpc disabled, a
23RISK
open ↗Referência
CVE-2017-0144
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open ↗Referência
Inosoft VisiWin 7 2022-2.1 - Insecure Folders Permissions
An issue was discovered in Inosoft VisiWin 7 through 2022-2.1 (Runtime RT7.3 RC3 20221209.5). The "%PROGRAMFILES(X86)%\I
41RISK
open ↗Referência
CVE-2023-31747
Wondershare Filmora 12 (Build 12.2.1.2088) was discovered to contain an unquoted service path vulnerability via the comp
41RISK
open ↗Referência
CVE-2023-31748
Insecure permissions in MobileTrans v4.0.11 allows attackers to escalate privileges to local admin via replacing the exe
41RISK
open ↗Referência✓ VexDay Proof
TR Newsportal 0.36tr1 - 'poll.php' Remote File Inclusion
PHP remote file inclusion vulnerability in extras/poll/poll.php in Florian Amrhein NewsPortal before 0.37, and TR Newspo
28RISK
open ↗Referência✓ VexDay Proof
Woltlab Burning Board 2.3.5 - 'links.php' SQL Injection
SQL injection vulnerability in links.php in 4R Linklist 1.0 RC2 and earlier, a module for Woltlab Burning Board, allows
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.