Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,302cataloged exploits
35,469CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,301GitHub PoC 14,141VulnCheck XDB 8,646Nuclei 4,289Metasploit 3,474✓ verified onlyrecentpopularrisk
22,266 exploits
Referência✓ VexDay Proof
ScriptMagix Jokes 2.0 - 'index.php?catid' SQL Injection
SQL injection vulnerability in index.php in ScriptMagix Jokes 2.0 and earlier allows remote attackers to execute arbitra
23RISK
open ↗Referência✓ VexDay Proof
Prozilla Reviews Script 1.0 - Arbitrary Delete User
Prozilla Reviews 1.0 allows remote attackers to delete arbitrary users via a modified UserID parameter in a direct reque
23RISK
open ↗Referência✓ VexDay Proof
Meto Forum 1.1 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in Meto Forum 1.1 allow remote attackers to execute arbitrary SQL commands via th
23RISK
open ↗Referência✓ VexDay Proof
Sisplet CMS 2008-01-24 - 'id' SQL Injection
SQL injection vulnerability in index.php in OneClick CMS (aka Sisplet CMS) 2008-01-24 allows remote attackers to execute
23RISK
open ↗Referência✓ VexDay Proof
CMS MAXSITE Component Guestbook - Remote Command Execution
Static code injection vulnerability in the Guestbook component in CMS MAXSITE allows remote attackers to inject arbitrar
23RISK
open ↗Referência✓ VexDay Proof
MauryCMS 0.53.2 - Arbitrary File Upload
SQL injection vulnerability in Rss.php in MauryCMS 0.53.2 and earlier allows remote attackers to execute arbitrary SQL c
23RISK
open ↗Referência
CVE-2012-5700
Multiple cross-site scripting (XSS) vulnerabilities in Baby Gekko before 1.2.2f allow remote attackers to inject arbitra
23RISK
open ↗Referência
CVE-2024-25003
KiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the hostname, occurs due to insuf
41RISK
open ↗Referência
CVE-2024-25003
KiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the hostname, occurs due to insuf
41RISK
open ↗Referência
CVE-2021-24272
Fitness Calculators < 1.9.6 - Cross-Site Request Forgery to Cross-Site Scripting (XSS)
23RISK
open ↗Referência
CVE-2016-2188
The iowarrior_probe function in drivers/usb/misc/iowarrior.c in the Linux kernel before 4.5.1 allows physically proximat
23RISK
open ↗Referência
CVE-2012-2938
Multiple cross-site scripting (XSS) vulnerabilities in Travelon Express 6.2.2 allow remote attackers to inject arbitrary
23RISK
open ↗Referência
CVE-2010-5048
Cross-site scripting (XSS) vulnerability in admin.jcomments.php in the JoomlaTune JComments (com_jcomments) component 2.
23RISK
open ↗Referência
CVE-2015-2999
Multiple SQL injection vulnerabilities in SysAid Help Desk before 15.2 allow remote administrators to execute arbitrary
23RISK
open ↗Referência
CVE-2023-3897
Bypassing CAPTCHA & Enumerating Usernames via Password Reset Page
33RISK
open ↗Referência✓ VexDay Proof
Alstrasoft e-Friends 4.21 - Admin Session Retrieve
SQL injection vulnerability in paypal.php in AlstraSoft E-Friends 4.21 and earlier allows remote attackers to execute ar
23RISK
open ↗Referência
CVE-2010-2138
Multiple directory traversal vulnerabilities in ProMan 0.1.1 and earlier allow remote attackers to include and execute a
23RISK
open ↗Referência
CVE-2010-2138
Multiple directory traversal vulnerabilities in ProMan 0.1.1 and earlier allow remote attackers to include and execute a
23RISK
open ↗Referência✓ VexDay Proof
Interact 2.4.1 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Interact Learning Community Environment Interact 2.4.1, when regis
23RISK
open ↗Referência
CVE-2017-0145
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open ↗Referência
CVE-2017-0145
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open ↗Referência
CVE-2017-0145
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open ↗Referência✓ VexDay Proof
cmsWorks 2.2 RC4 - 'mod_root' Remote File Inclusion
PHP remote file inclusion vulnerability in admin/include/lib.module.php in cmsWorks 2.2 RC4, when register_globals is en
23RISK
open ↗Referência✓ VexDay Proof
Free Hosting Manager 1.2/2.0 - Insecure Cookie Handling
Free Hosting Manager 1.2 and 2.0 allows remote attackers to bypass authentication and gain administrative access by sett
23RISK
open ↗Referência
CVE-2017-8422
KDE kdelibs before 4.14.32 and KAuth before 5.34 allow local users to gain root privileges by spoofing a callerID and le
23RISK
open ↗Referência
CVE-2010-3490
Directory traversal vulnerability in page.recordings.php in the System Recordings component in the configuration interfa
23RISK
open ↗Referência
CVE-2012-1787
Multiple cross-site scripting (XSS) vulnerabilities in wgarcmin.cgi in Webglimpse 2.20.0 and earlier allow remote attack
23RISK
open ↗Referência
CVE-2009-3360
Multiple cross-site scripting (XSS) vulnerabilities in Datemill 1.0 allow remote attackers to inject arbitrary web scrip
23RISK
open ↗Referência
CVE-2011-5140
Multiple SQL injection vulnerabilities in the blog module 1.0 for DiY-CMS allow remote attackers to execute arbitrary SQ
23RISK
open ↗Referência✓ VexDay Proof
NuSchool 1.0 - 'CampusNewsDetails.asp' SQL Injection
SQL injection vulnerability in CampusNewsDetails.asp in Dynamic Dataworx NuSchool 1.0 allows remote attackers to execute
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.