Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,449cataloged exploits
35,552CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,367GitHub PoC 14,225VulnCheck XDB 8,649Nuclei 4,283Metasploit 3,474✓ verified onlyrecentpopularrisk
22,367 exploits
Referência
CVE-2017-14840
TeamWork TicketPlus allows Arbitrary File Upload in updateProfile.
23RISK
open ↗Referência
CVE-2017-14841
Mojoomla Annual Maintenance Contract (AMC) Management System allows Arbitrary File Upload in profilesetting image handli
23RISK
open ↗Referência
CVE-2006-1652
Multiple buffer overflows in (a) UltraVNC (aka Ultr@VNC) 1.0.1 and earlier and (b) tabbed_viewer 1.29 (1) allow user-ass
50RISK
open ↗Referência
CVE-2006-1652
Multiple buffer overflows in (a) UltraVNC (aka Ultr@VNC) 1.0.1 and earlier and (b) tabbed_viewer 1.29 (1) allow user-ass
50RISK
open ↗Referência
CVE-2017-14843
Mojoomla School Management System for WordPress allows SQL Injection via the id parameter.
23RISK
open ↗Referência
CVE-2017-14844
Mojoomla WPGYM WordPress Gym Management System allows SQL Injection via the id parameter.
23RISK
open ↗Referência✓ VexDay Proof
SQuery 4.5 - 'libpath' Remote File Inclusion
PHP remote file inclusion vulnerability in lib/armygame.php in SQuery 4.5 and earlier, as used in products such as Auton
23RISK
open ↗Referência
CVE-2021-36260
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISK
open ↗Referência
CVE-2015-4681
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows local users to have unspecified impact via vectors re
23RISK
open ↗Referência
CVE-2015-4681
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows local users to have unspecified impact via vectors re
23RISK
open ↗Referência
CVE-2026-9435
Totolink A8000RU Web Management cstecgi.cgi setQosCfg os command injection
48RISK
open ↗Referência
CVE-2026-9417
code-projects Employee Management System myprofileup.php cross site scripting
33RISK
open ↗Referência✓ VexDay Proof
mxBB Module mx_tinies 1.3.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in includes/mx_common.php in the mx_tinies 1.3.0 Module for MxBB Portal 1.06 all
23RISK
open ↗Referência
CVE-2017-14845
Mojoomla WPCHURCH Church Management System for WordPress allows SQL Injection via the id parameter.
23RISK
open ↗Referência✓ VexDay Proof
Microsoft Windows - spoolss GetPrinterData() Remote Denial of Service
The RpcGetPrinterData function in the Print Spooler (spoolsv.exe) service in Microsoft Windows 2000 SP4 and earlier, and
28RISK
open ↗Referência✓ VexDay Proof
torrentflux 2.2 - Arbitrary File Create/ Execute/Delete
Directory traversal vulnerability in index.php for TorrentFlux 2.2 allows remote attackers to create or overwrite arbitr
23RISK
open ↗Referência✓ VexDay Proof
torrentflux 2.2 - Arbitrary File Create/ Execute/Delete
index.php for TorrentFlux 2.2 allows remote attackers to delete files by specifying the target filename in the delfile p
23RISK
open ↗Referência
CVE-2017-14846
Mojoomla Hospital Management System for WordPress allows SQL Injection via the id parameter.
23RISK
open ↗Referência✓ VexDay Proof
torrentflux 2.2 - Arbitrary File Create/ Execute/Delete
index.php for TorrentFlux 2.2 allows remote registered users to execute arbitrary commands via shell metacharacters in t
23RISK
open ↗Referência
CVE-2017-14847
Mojoomla WPAMS Apartment Management System for WordPress allows SQL Injection via the id parameter.
23RISK
open ↗Referência
CVE-2017-14955
Check_MK before 1.2.8p26 mishandles certain errors within the failed-login save feature because of a race condition, whi
28RISK
open ↗Referência✓ VexDay Proof
The Classified Ad System 1.0 - 'main' SQL Injection
Multiple SQL injection vulnerabilities in PWP Technologies The Classified Ad System allow remote attackers to execute ar
23RISK
open ↗Referência✓ VexDay Proof
F-Prot AntiVirus 4.6.6 - 'ACE' Denial of Service
FRISK Software F-Prot Antivirus before 4.6.7 allows user-assisted remote attackers to cause a denial of service (infinit
23RISK
open ↗Referência✓ VexDay Proof
awrate.com Message Board 1.0 - 'search.php' Remote File Inclusion
PHP remote file inclusion vulnerability in login.php.inc in awrate 1.0 allows remote attackers to execute arbitrary PHP
23RISK
open ↗Referência✓ VexDay Proof
Ultimate HelpDesk - Cross-Site Scripting / Local File Disclosure
Cross-site scripting (XSS) vulnerability in index.asp in Ultimate HelpDesk allows remote attackers to inject arbitrary w
23RISK
open ↗Referência✓ VexDay Proof
HR Assist 1.05 - 'vdateUsr.asp' Remote Authentication Bypass
SQL injection vulnerability in vdateUsr.asp in EzHRS HR Assist 1.05 and earlier allows remote attackers to execute arbit
23RISK
open ↗Referência✓ VexDay Proof
SpotLight CRM 1.0 - 'login.asp' SQL Injection
Multiple SQL injection vulnerabilities in login.asp in AppIntellect SpotLight CRM 1.0 allow remote attackers to execute
23RISK
open ↗Referência
CVE-2017-15081
In PHPSUGAR PHP Melody CMS 2.6.1, SQL Injection exists via the playlist parameter to playlists.php.
23RISK
open ↗Referência✓ VexDay Proof
mxBB Module ErrorDocs 1.0 - 'common.php' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/common.php in the ErrorDocs 1.0.0 and earlier module for mxBB (mx_er
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.