Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,058cataloged exploits
35,300CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,175GitHub PoC 14,096VulnCheck XDB 8,607Nuclei 4,255Metasploit 3,474✓ verified onlyrecentpopularrisk
22,175 exploits
Referência
CVE-2012-1669
Directory traversal vulnerability in index.php in phpMoneyBooks before 1.0.3 allows remote attackers to include and exec
23RISK
open ↗Referência✓ VexDay Proof
ISPworker 1.21 - 'download.php' Remote File Disclosure
Multiple directory traversal vulnerabilities in download.php in ISPworker 1.21 allow remote attackers to read arbitrary
23RISK
open ↗Referência
CVE-2017-14838
TeamWork Job Links allows Arbitrary File Upload in profileChange and coverChange.
23RISK
open ↗Referência
CVE-2017-14839
TeamWork Photo Fusion allows Arbitrary File Upload in changeAvatar and changeCover.
23RISK
open ↗Referência✓ VexDay Proof
FlashBlog - 'articulo_id' SQL Injection
SQL injection vulnerability in php/leer_comentarios.php in FlashBlog allows remote attackers to execute arbitrary SQL co
23RISK
open ↗Referência✓ VexDay Proof
freeSSHd 1.2.1 - (Authenticated) Remote Overflow (SEH)
Stack-based buffer overflow in SFTP in freeSSHd 1.2.1 allows remote authenticated users to execute arbitrary code via a
23RISK
open ↗Referência
CVE-2014-9522
Multiple cross-site scripting (XSS) vulnerabilities in CMS Papoo Light 6.0.0 (Rev 4701) allow remote attackers to inject
23RISK
open ↗Referência
CVE-2014-9522
Multiple cross-site scripting (XSS) vulnerabilities in CMS Papoo Light 6.0.0 (Rev 4701) allow remote attackers to inject
23RISK
open ↗Referência
CVE-2006-2226
Buffer overflow in XM Easy Personal FTP Server 4.2 and 5.0.1 allows remote authenticated users to cause a denial of serv
23RISK
open ↗Referência
CVE-2014-8653
Cross-site scripting (XSS) vulnerability in Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway 1.0 wit
23RISK
open ↗Referência
CVE-2014-8653
Cross-site scripting (XSS) vulnerability in Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway 1.0 wit
23RISK
open ↗Referência
CVE-2010-1349
Integer overflow in Opera 10.10 through 10.50 allows remote attackers to execute arbitrary code via a large Content-Leng
28RISK
open ↗Referência
CVE-2019-6263
An issue was discovered in Joomla! before 3.9.2. Inadequate checks of the Global Configuration Text Filter settings allo
23RISK
open ↗Referência
CVE-2009-5087
Directory traversal vulnerability in geohttpserver in Geovision Digital Video Surveillance System 8.2 allows remote atta
23RISK
open ↗Referência
CVE-2014-10035
Multiple cross-site scripting (XSS) vulnerabilities in the admin area in couponPHP before 1.2.0 allow remote administrat
23RISK
open ↗Referência
CVE-2014-10035
Multiple cross-site scripting (XSS) vulnerabilities in the admin area in couponPHP before 1.2.0 allow remote administrat
23RISK
open ↗Referência
CVE-2018-7543
Cross-site scripting (XSS) vulnerability in installer/build/view.step4.php of the SnapCreek Duplicator plugin 1.2.32 for
23RISK
open ↗Referência✓ VexDay Proof
phpCMS 1.2.2 - 'file' Remote File Disclosure
Directory traversal vulnerability in parser/include/class.cache_phpcms.php in phpCMS 1.2.2 allows remote attackers to re
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component acctexp 0.12.x - Blind SQL Injection
SQL injection vulnerability in the acctexp (com_acctexp) component 0.12.x and earlier for Joomla! allows remote attacker
23RISK
open ↗Referência✓ VexDay Proof
XM Easy Personal FTP Server 1.0 - 'Port' Remote Overflow (PoC)
Buffer overflow in XM Easy Personal FTP Server 4.2 and 5.0.1 allows remote authenticated users to cause a denial of serv
23RISK
open ↗Referência✓ VexDay Proof
Pre News Manager 1.0 - 'id' SQL Injection
SQL injection vulnerability in Pre News Manager 1.0 allows remote attackers to execute arbitrary SQL commands via the (1
23RISK
open ↗Referência✓ VexDay Proof
SAPID 1.2.3.05 - 'ROOT_PATH' Remote File Inclusion
PHP remote file inclusion vulnerability in SAPID CMS 123 rc3 allows remote attackers to execute arbitrary PHP code via a
23RISK
open ↗Referência✓ VexDay Proof
PHP-revista 1.1.2 - Remote File Inclusion / SQL Injection / Authentication Bypass / Cross-Site Scripting
admin/index.php in Longino Jacome php-Revista 1.1.2 allows remote attackers to bypass authentication controls by setting
23RISK
open ↗Referência
CVE-2012-4335
Samsung NET-i viewer 1.37.120316 allows remote attackers to cause a denial of service (infinite loop) via a negative siz
23RISK
open ↗Referência
CVE-2009-3322
The Siemens Gigaset SE361 WLAN router allows remote attackers to cause a denial of service (device reboot) via a flood o
23RISK
open ↗Referência
CVE-2014-9240
SQL injection vulnerability in member.php in MyBB (aka MyBulletinBoard) 1.8.x before 1.8.2 allows remote attackers to ex
23RISK
open ↗Referência
CVE-2018-18772
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=send_ssh, as dem
23RISK
open ↗Referência
CVE-2018-0877
The Desktop Bridge Virtual File System (VFS) in Windows 10 1607, 1703, and 1709, Windows Server 2016 and Windows Server,
23RISK
open ↗Referência
CVE-2013-6882
Multiple cross-site scripting (XSS) vulnerabilities in CRU Ditto Forensic FieldStation with firmware 2013Oct15a and earl
23RISK
open ↗Referência
CVE-2013-6882
Multiple cross-site scripting (XSS) vulnerabilities in CRU Ditto Forensic FieldStation with firmware 2013Oct15a and earl
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.