Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,151cataloged exploits
35,370CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,233GitHub PoC 14,119VulnCheck XDB 8,617Nuclei 4,257Metasploit 3,474✓ verified onlyrecentpopularrisk
22,175 exploits
Referência
CVE-2025-14708
Shiguangwu sgwbox N3 WIREDCFGGET http_eshell_server buffer overflow
48RISK
open ↗Referência
CVE-2018-4193
An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Windows Ser
23RISK
open ↗Referência
CVE-2017-8869
Buffer overflow in MediaCoder 0.8.48.5888 allows remote attackers to execute arbitrary code via a crafted .m3u file.
43RISK
open ↗Referência
CVE-2014-0869
The decrypt function in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algori
23RISK
open ↗Referência✓ VexDay Proof
e107 Plugin My_Gallery 2.3 - Arbitrary File Download
Absolute path traversal vulnerability in dload.php in the my_gallery 2.3 plugin for e107 allows remote attackers to obta
23RISK
open ↗Referência✓ VexDay Proof
Microsoft Windows - InternalOpenColorProfile Heap Overflow (PoC) (MS08-046)
Heap-based buffer overflow in the InternalOpenColorProfile function in mscms.dll in Microsoft Windows Image Color Manage
35RISK
open ↗Referência✓ VexDay Proof
PHPFK 7.03 - 'page_bottom.php' Local File Inclusion
Directory traversal vulnerability in include/page_bottom.php in phpFK 7.03 allows remote attackers to include and execut
23RISK
open ↗Referência
CVE-2010-2920
Directory traversal vulnerability in the Foobla Suggestions (com_foobla_suggestions) component 1.5.1.2 for Joomla! allow
38RISK
open ↗Referência
CVE-2016-4997
The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux
38RISK
open ↗Referência
CVE-2016-4997
The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux
38RISK
open ↗Referência
CVE-2019-8924
XAMPP through 5.6.8 allows XSS via the cds-fpdf.php interpret or titel parameter. NOTE: This product is discontinued.
23RISK
open ↗Referência
CVE-2019-8924
XAMPP through 5.6.8 allows XSS via the cds-fpdf.php interpret or titel parameter. NOTE: This product is discontinued.
23RISK
open ↗Referência
CVE-2010-4230
Stack-based buffer overflow in a certain ActiveX control for the Camtron CMNC-200 Full HD IP Camera and TecVoz CMNC-200
23RISK
open ↗Referência
CVE-2015-3673
Admin Framework in Apple OS X before 10.10.4 does not properly restrict the location of writeconfig clients, which allow
38RISK
open ↗Referência✓ VexDay Proof
WordPress Plugin dmsguestbook 1.7.0 - Multiple Vulnerabilities
SQL injection vulnerability in the administration panel in the DMSGuestbook 1.7.0 plugin for WordPress allows remote aut
23RISK
open ↗Referência
CVE-2007-6478
Stack-based buffer overflow in Rosoft Media Player 4.1.7, 4.1.8, and possibly earlier versions allows remote attackers t
23RISK
open ↗Referência
CVE-2014-0871
RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allows remote att
23RISK
open ↗Referência✓ VexDay Proof
AS-GasTracker 1.0.0 - Insecure Cookie Handling
AustinSmoke GasTracker (AS-GasTracker) 1.0.0 allows remote attackers to bypass authentication and gain privileges by set
23RISK
open ↗Referência✓ VexDay Proof
DoSePa 1.0.4 - 'textview.php' Information Disclosure
Directory traversal vulnerability in textview.php in Anton Vlasov DoSePa 1.0.4 allows remote attackers to read arbitrary
23RISK
open ↗Referência✓ VexDay Proof
Feedback and Rating Script 1.0 - 'detail.php' SQL Injection
SQL injection vulnerability in detail.php in Feedback and Rating Script 1.0 allows remote attackers to execute arbitrary
23RISK
open ↗Referência✓ VexDay Proof
Microsoft Internet Explorer - Print Table of Links Cross-Zone Scripting
Cross-zone scripting vulnerability in the Print Table of Links feature in Internet Explorer 6.0, 7.0, and 8.0b allows us
28RISK
open ↗Referência✓ VexDay Proof
Core Image Fun House 2.0 (OSX) - Arbitrary Code Execution (PoC)
Buffer overflow in Apple Core Image Fun House 2.0 and earlier in CoreImage Examples in Xcode tools before 3.1 allows use
23RISK
open ↗Referência
CVE-2026-4585
Tiandy Easy7 Integrated Management Platform Configuration ImportSystemConfiguration.jsp os command injection
48RISK
open ↗Referência
CVE-2010-1044
SQL injection vulnerability in Login.do in ManageEngine OpUtils 5.0 allows remote attackers to execute arbitrary SQL com
23RISK
open ↗Referência
CVE-2012-2210
The Sony Bravia TV KDL-32CX525 allows remote attackers to cause a denial of service (configuration outage or device cras
23RISK
open ↗Referência
CVE-2018-17441
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'username' parameter of the addUser
23RISK
open ↗Referência
CVE-2018-17443
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'sitename' parameter of the UpdateS
23RISK
open ↗Referência
CVE-2014-0980
Buffer overflow in Poster Software PUBLISH-iT 3.6d allows remote attackers to execute arbitrary code via a crafted PUI f
50RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.