Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,231cataloged exploits
35,420CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,266GitHub PoC 14,131VulnCheck XDB 8,635Nuclei 4,274Metasploit 3,474✓ verified onlyrecentpopularrisk
22,233 exploits
Referência✓ VexDay Proof
KTP Computer Customer Database CMS 1.0 - Local File Inclusion
Directory traversal vulnerability in KTP Computer Customer Database (KTPCCD) CMS, when magic_quotes_gpc is disabled, all
23RISK
open ↗Referência✓ VexDay Proof
Absolute Form Processor XE-V 1.5 - Insecure Cookie Handling
Absolute Form Processor XE 1.5 allows remote attackers to bypass authentication and gain administrative access by settin
23RISK
open ↗Referência✓ VexDay Proof
Bitweaver 2.6 - 'saveFeed()' Remote Code Execution
Directory traversal vulnerability in the saveFeed function in rss/feedcreator.class.php in Bitweaver 2.6 and earlier all
23RISK
open ↗Referência
CVE-2009-3545
DataWizard Technologies FtpXQ FTP Server 3.0 allows remote authenticated users to cause a denial of service (crash) via
23RISK
open ↗Referência
CVE-2021-33353
Directory Traversal vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows at
48RISK
open ↗Referência
CVE-2007-6191
Multiple PHP remote file inclusion vulnerabilities in Armin Burger p.mapper 3.2.0 beta3 allow remote attackers to execut
23RISK
open ↗Referência
CVE-2012-1613
Cross-site scripting (XSS) vulnerability in edit_one_pic.php in Coppermine Photo Gallery before 1.5.20 allows remote aut
23RISK
open ↗Referência
CVE-2012-1613
Cross-site scripting (XSS) vulnerability in edit_one_pic.php in Coppermine Photo Gallery before 1.5.20 allows remote aut
23RISK
open ↗Referência
CVE-2017-16962
The WebMail components (Crystal, pronto, and pronto4) in CommuniGate Pro before 6.2.1 have stored XSS vulnerabilities vi
23RISK
open ↗Referência
CVE-2017-16962
The WebMail components (Crystal, pronto, and pronto4) in CommuniGate Pro before 6.2.1 have stored XSS vulnerabilities vi
23RISK
open ↗Referência
CVE-2011-4673
SQL injection vulnerability in modules/sharedaddy.php in the Jetpack plugin for WordPress allows remote attackers to exe
23RISK
open ↗Referência
MyT Project Management 1.5.1 - User[username] Persistent Cross-Site Scripting
In MyT 1.5.1, the User[username] parameter has XSS.
23RISK
open ↗Referência
CVE-2026-10230
Assimp Half-Life 1 MDL Loader HL1MDLLoader.cpp read_animations heap-based overflow
33RISK
open ↗Referência✓ VexDay Proof
CcMail 1.0.1 - Insecure Cookie Handling
Cicoandcico CcMail 1.0.1 and earlier does not verify that the this_cookie cookie corresponds to an authenticated session
23RISK
open ↗Referência
CVE-2010-0665
JAG (Just Another Guestbook) 1.14 stores sensitive information under the web root with insufficient access control, whic
23RISK
open ↗Referência✓ VexDay Proof
Download Accelerator Plus DAP 8.x - '.m3u' File Buffer Overflow
Stack-based buffer overflow in DAP.exe in Download Accelerator Plus (DAP) 7.0.1.3, 8.6.6.3, and other 8.x versions allow
23RISK
open ↗Referência✓ VexDay Proof
Download Accelerator Plus DAP 8.x - '.m3u' Local Buffer Overflow
Stack-based buffer overflow in DAP.exe in Download Accelerator Plus (DAP) 7.0.1.3, 8.6.6.3, and other 8.x versions allow
23RISK
open ↗Referência✓ VexDay Proof
CCLeague Pro 1.2 - Insecure Cookie Authentication
admin.php in CCleague Pro 1.2 allows remote attackers to bypass authentication by setting the type cookie value to admin
23RISK
open ↗Referência✓ VexDay Proof
TxtBlog 1.0 Alpha - Local File Inclusion
Directory traversal vulnerability in index.php in TxtBlog 1.0 Alpha allows remote attackers to read arbitrary files via
23RISK
open ↗Referência✓ VexDay Proof
4Images 1.7.7 - Filter Bypass HTML Injection / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in 4images 1.7.7 and earlier allows remote authenticated users to inject arbitr
23RISK
open ↗Referência
CVE-2014-3857
Multiple SQL injection vulnerabilities in Kerio Control Statistics in Kerio Control (formerly WinRoute Firewall) before
23RISK
open ↗Referência
CVE-2014-3857
Multiple SQL injection vulnerabilities in Kerio Control Statistics in Kerio Control (formerly WinRoute Firewall) before
23RISK
open ↗Referência
CVE-2018-5976
Cross Site Request Forgery (CSRF) exists in RSVP Invitation Online 1.0 via function/account.php, as demonstrated by modi
23RISK
open ↗Referência
CVE-2017-1000474
Soyket Chowdhury Vehicle Sales Management System version 2017-07-30 is vulnerable to multiple SQL Injecting in login/veh
23RISK
open ↗Referência
CVE-2010-1498
Multiple SQL injection vulnerabilities in dl_stats before 2.0 allow remote attackers to execute arbitrary SQL commands v
23RISK
open ↗Referência
CVE-2010-1498
Multiple SQL injection vulnerabilities in dl_stats before 2.0 allow remote attackers to execute arbitrary SQL commands v
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.