Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,130cataloged exploits
35,368CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,231GitHub PoC 14,110VulnCheck XDB 8,607Nuclei 4,257Metasploit 3,474✓ verified onlyrecentpopularrisk
22,175 exploits
Referência
CVE-2010-4776
SQL injection vulnerability in takefreestart.php in PreProjects Pre Online Tests Generator Pro allows remote attackers t
23RISK
open ↗Referência
CVE-2010-4776
SQL injection vulnerability in takefreestart.php in PreProjects Pre Online Tests Generator Pro allows remote attackers t
23RISK
open ↗Referência
CVE-2010-1980
Directory traversal vulnerability in joomlaflickr.php in the Joomla Flickr (com_joomlaflickr) component 1.0.3 for Joomla
43RISK
open ↗Referência
CVE-2019-1003000
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RISK
open ↗Referência
CVE-2019-1003000
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RISK
open ↗Referência
CVE-2026-18601
GL.iNet GL-MT3000 ovpn-client.so Native Plugin glc ovpn-client.check_config command injection
48RISK
open ↗Referência
CVE-2026-18600
GL.iNet GL-MT3000 Network Lua RPC Plugin network network.switch_status command injection
41RISK
open ↗Referência
CVE-2026-18599
GL.iNet GL-MT3000 Logread Lua RPC Plugin logread logread.set_config command injection
41RISK
open ↗Referência
CVE-2026-18598
GL.iNet GL-MT3000 Logread Lua RPC plugin logread logread.get_system_log command injection
41RISK
open ↗Referência✓ VexDay Proof
Smoothflash - 'cid' SQL Injection
SQL injection vulnerability in admin_view_image.php in Smoothflash allows remote attackers to execute arbitrary SQL comm
23RISK
open ↗Referência
CVE-2026-65701
SoftVC VITS Singing Voice Conversion Path Traversal via /wav2wav Flask Route
48RISK
open ↗Referência
CVE-2010-4864
SQL injection vulnerability in the Club Manager (com_clubmanager) component for Joomla! allows remote attackers to execu
23RISK
open ↗Referência
CVE-2010-4866
SQL injection vulnerability in index.php in Chipmunk Board 1.3 allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗Referência
CVE-2010-4869
SQL injection vulnerability in index.php in DBHcms 1.1.4 allows remote attackers to execute arbitrary SQL commands via t
23RISK
open ↗Referência
CVE-2016-1960
Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string parser in Mozilla Firefox before 45.0 and Firefox
35RISK
open ↗Referência
CVE-2010-1062
Directory traversal vulnerability in codelib/sys/common.inc.php in Phpkobo Free Real Estate Contact Form 1.09, when magi
23RISK
open ↗Referência
CVE-2016-2004
HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allow remote attackers to execute arbitrary cod
60RISK
open ↗Referência
CVE-2010-1066
AR Web Content Manager (AWCM) 2.1 stores sensitive information under the web root with insufficient access control, whic
23RISK
open ↗Referência
CVE-2020-6207
SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform an
100RISK
open ↗Referência
CVE-2020-6207
SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform an
100RISK
open ↗Referência
CVE-2020-6207
SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform an
100RISK
open ↗Referência
CVE-2022-21587
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload).
100RISK
open ↗Referência
CVE-2010-4895
Cross-site scripting (XSS) vulnerability in core/showsite.php in chillyCMS 1.1.3 allows remote attackers to inject arbit
23RISK
open ↗Referência
CVE-2010-4898
SQL injection vulnerability in the Gantry (com_gantry) component 3.0.10 for Joomla! allows remote attackers to execute a
23RISK
open ↗Referência
CVE-2010-4902
Multiple SQL injection vulnerabilities in the Clantools (com_clantools) component 1.2.3 for Joomla! allow remote attacke
23RISK
open ↗Referência
CVE-2010-4910
SQL injection vulnerability in index.cfm in ColdGen ColdCalendar 2.06 allows remote attackers to execute arbitrary SQL c
23RISK
open ↗Referência
CVE-2010-4910
SQL injection vulnerability in index.cfm in ColdGen ColdCalendar 2.06 allows remote attackers to execute arbitrary SQL c
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.