Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,231cataloged exploits
35,420CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,266GitHub PoC 14,131VulnCheck XDB 8,635Nuclei 4,274Metasploit 3,474✓ verified onlyrecentpopularrisk
22,266 exploits
Referência✓ VexDay Proof
DomPHP 0.81 - 'index.php' Remote File Inclusion
PHP remote file inclusion vulnerability in /aides/index.php in DomPHP 0.81 and earlier allows remote attackers to execut
23RISK
open ↗Referência
CVE-2008-5947
PHP remote file inclusion vulnerability in include/class_yapbbcooker.php in YapBB 1.2.Beta 2 allows remote attackers to
23RISK
open ↗Referência
CVE-2012-4923
Multiple cross-site scripting (XSS) vulnerabilities in Endian Firewall 2.4 allow remote attackers to inject arbitrary we
23RISK
open ↗Referência
CVE-2009-4936
Multiple SQL injection vulnerabilities in Small Pirate (SPirate) 2.1 allow remote attackers to execute arbitrary SQL com
23RISK
open ↗Referência
CVE-2017-1000379
The Linux Kernel running on AMD64 systems will sometimes map the contents of PIE executable, the heap or ld.so to where
23RISK
open ↗Referência✓ VexDay Proof
Dokeos 1.8.0 - 'my_progress.php?course' SQL Injection
Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.0 and earlier allow remote attackers to inject arbitra
23RISK
open ↗Referência✓ VexDay Proof
polypager 1.0rc2 - SQL Injection / Cross-Site Scripting
SQL injection vulnerability in PolyPager 1.0 rc2 and earlier allows remote attackers to execute arbitrary SQL commands v
23RISK
open ↗Referência✓ VexDay Proof
LoveCMS 1.6.2 Final - Update Settings
LoveCMS 1.6.2 does not require administrative authentication for (1) addblock.php, (2) blocks.php, and (3) themes.php in
23RISK
open ↗Referência
CVE-2010-3483
cms_write.php in Primitive CMS 1.0.9 does not properly restrict access, which allows remote attackers to gain administra
23RISK
open ↗Referência
CVE-2013-2712
Cross-site scripting (XSS) vulnerability in services/get_article.php in KrisonAV CMS before 3.0.2 allows remote attacker
23RISK
open ↗Referência
CVE-2024-48445
An issue in compop.ca ONLINE MALL v.3.5.3 allows a remote attacker to execute arbitrary code via the rid, tid, et, and t
48RISK
open ↗Referência
CVE-2022-36633
Teleport 9.3.6 is vulnerable to Command injection leading to Remote Code Execution. An attacker can craft a malicious ss
35RISK
open ↗Referência
CVE-2014-0793
Multiple cross-site scripting (XSS) vulnerabilities in the StackIdeas Komento (com_komento) component before 1.7.3 for J
23RISK
open ↗Referência
CVE-2014-10018
Cross-site scripting (XSS) vulnerability in webconfig/wlan/country.html/country in the Teracom T2-B-Gawv1.4U10Y-BI modem
23RISK
open ↗Referência
CVE-2010-1146
The Linux kernel 2.6.33.2 and earlier, when a ReiserFS filesystem exists, does not restrict read or write access to the
23RISK
open ↗Referência
CVE-2012-2569
Cross-site scripting (XSS) vulnerability in Synametrics Technologies Xeams 4.4 Build 5720 allows remote attackers to inj
23RISK
open ↗Referência
CVE-2026-5995
Totolink A7100RU CGI cstecgi.cgi setMiniuiHomeInfoShow os command injection
48RISK
open ↗Referência✓ VexDay Proof
ASPPortal 4.0.0 - 'default1.asp' SQL Injection
SQL injection vulnerability in default1.asp in ASPPortal 4.0.0 beta and earlier allows remote attackers to execute arbit
23RISK
open ↗Referência
CVE-2026-5996
Totolink A7100RU CGI cstecgi.cgi setAdvancedInfoShow os command injection
48RISK
open ↗Referência✓ VexDay Proof
NuRems 1.0 - 'propertysdetails.asp' SQL Injection
SQL injection vulnerability in propertysdetails.asp in Dynamic Dataworx NuRealestate (NuRems) 1.0 and earlier allows rem
23RISK
open ↗Referência
CVE-2010-0678
PHP remote file inclusion vulnerability in includes/moderation.php in Katalog Stron Hurricane 1.3.5, and possibly earlie
23RISK
open ↗Referência
CVE-2010-0678
PHP remote file inclusion vulnerability in includes/moderation.php in Katalog Stron Hurricane 1.3.5, and possibly earlie
23RISK
open ↗Referência
CVE-2008-3513
SQL injection vulnerability in the Book Catalog module 1.0 for PHP-Nuke allows remote attackers to execute arbitrary SQL
23RISK
open ↗Referência✓ VexDay Proof
Anata CMS 1.0b5 - 'change.php' Arbitrary Add Admin
change.php in Ananta CMS 1.0b5, with magic_quotes_gpc disabled, allows remote attackers to gain administrator privileges
23RISK
open ↗Referência
CVE-2022-36633
Teleport 9.3.6 is vulnerable to Command injection leading to Remote Code Execution. An attacker can craft a malicious ss
35RISK
open ↗Referência
CVE-2018-7289
An issue was discovered in armadito-windows-driver/src/communication.c in Armadito 0.12.7.2. Malware with filenames cont
23RISK
open ↗Referência
CVE-2007-3824
SQL injection vulnerability in katgoster.asp in MzK Blog (tr) allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗Referência✓ VexDay Proof
TotalCalendar 2.402 - 'view_event.php' SQL Injection
SQL injection vulnerability in view_event.php in TotalCalendar 2.402 and earlier allows remote attackers to execute arbi
23RISK
open ↗Referência
CVE-2010-1351
Multiple PHP remote file inclusion vulnerabilities in Nodesforum 1.033 and 1.045, when register_globals is enabled, allo
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.