Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,620cataloged exploits
35,647CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,429GitHub PoC 14,270VulnCheck XDB 8,693Nuclei 4,299Metasploit 3,474✓ verified onlyrecentpopularrisk
22,407 exploits
Referência
CVE-2022-24637
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, wh
60RISK
open ↗Referência
CVE-2022-24637
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, wh
60RISK
open ↗Referência✓ VexDay Proof
PHP Blue Dragon CMS 2.9.1 - Cross-Site Scripting / SQL Injection Code Execution
Directory traversal vulnerability in pbd_engine.php in Php Blue Dragon 2.9.1 and earlier allows remote attackers to read
23RISK
open ↗Referência
CVE-2022-26134
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open ↗Referência✓ VexDay Proof
PHP Blue Dragon CMS 3.0.0 - Remote Code Execution
Directory traversal vulnerability in pbd_engine.php in Php Blue Dragon 2.9.1 and earlier allows remote attackers to read
23RISK
open ↗Referência✓ VexDay Proof
pNews 1.1.0 - 'nbs' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/global.php in Joshua Wilson pNews System 1.1.0 (aka PowerNews) allow
23RISK
open ↗Referência✓ VexDay Proof
PHPartenaire 1.0 - 'dix.php3' Remote File Inclusion
PHP remote file inclusion vulnerability in dix.php3 in PHPartenaire 1.0 allows remote attackers to execute arbitrary PHP
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component Joomlaboard 1.1.1 - 'sbp' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in the Joomlaboard Forum Component (com_joomlaboard) before 1.1.2 for
23RISK
open ↗Referência✓ VexDay Proof
Advaced-Clan-Script 3.4 - 'mcf.php' Remote File Inclusion
PHP remote file inclusion vulnerability in mcf.php in Advanced-Clan-Script (AVCX) 3.4 and earlier allows remote attacker
23RISK
open ↗Referência✓ VexDay Proof
PBLang 4.66z - 'temppath' Remote File Inclusion
PHP remote file inclusion vulnerability in templates/pb/language/lang_nl.php in PBLang (PBL) 4.66z and earlier allows re
23RISK
open ↗Referência✓ VexDay Proof
faceStones personal 2.0.42 - 'fs_form_links.php' File Inclusion
PHP remote file inclusion vulnerability in fsl2/objects/fs_form_links.php in faceStones Personal 2.0.42 and earlier allo
23RISK
open ↗Referência✓ VexDay Proof
evoBB 0.3 - 'path' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in evoBB 0.3 and earlier allow remote attackers to execute arbitrary
23RISK
open ↗Referência✓ VexDay Proof
NaviCOPA Web Server 2.01 - 'GET' Remote Buffer Overflow
Buffer overflow in InterVations NaviCOPA Web Server 2.01 allows remote attackers to execute arbitrary code via a long HT
50RISK
open ↗Referência
CVE-2022-26986
SQL Injection in ImpressCMS 1.4.3 and earlier allows remote attackers to inject into the code in unintended way, this al
23RISK
open ↗Referência
CVE-2022-27308
A stored cross-site scripting (XSS) vulnerability in PHProjekt PhpSimplyGest v1.3.0 allows attackers to execute arbitrar
23RISK
open ↗Referência
CVE-2022-27412
Explore CMS v1.0 was discovered to contain a SQL injection vulnerability via a /page.php?id= request.
23RISK
open ↗Referência
CVE-2022-28117
A Server-Side Request Forgery (SSRF) in feed_parser class of Navigate CMS v2.9.4 allows remote attackers to force the ap
43RISK
open ↗Referência
CVE-2022-2846
Calendar Event Multi View < 1.4.07 - Unauthenticated Arbitrary Event Creation to Stored XSS
33RISK
open ↗Referência
CVE-2022-29296
A reflected cross-site scripting (XSS) vulnerability in the login portal of Avantune Genialcloud ProJ - 10 allows attack
23RISK
open ↗Referência
PyScript - Read Remote Python Source Code
pyscriptjs (aka PyScript Demonstrator) in PyScript through 2022-05-04 allows a remote user to read Python source code.
28RISK
open ↗Referência
CVE-2022-30525
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Pat
100RISK
open ↗Referência
CVE-2022-30525
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Pat
100RISK
open ↗Referência✓ VexDay Proof
Microsoft Office 2003 - '.PPT' Local Buffer Overflow (PoC)
PowerPoint in Microsoft Office 2003 does not properly handle a container object whose position value exceeds the record
28RISK
open ↗Referência✓ VexDay Proof
phpBB SpamBlocker Mod 1.0.2 - Remote File Inclusion
PHP remote file inclusion vulnerability in includes/antispam.php in the SpamBlockerMODv 1.0.2 and earlier module for php
23RISK
open ↗Referência✓ VexDay Proof
Redaction System 1.0 - 'lang_prefix' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Redaction System 1.0000 allow remote attackers to execute arbitrar
23RISK
open ↗Referência
CVE-2022-31188
Server-Side Request Forgery Vulnerability in Computer Vision Annotation Tool (CVAT)
53RISK
open ↗Referência✓ VexDay Proof
phpBB Prillian French Mod 0.8.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in language/lang_french/lang_prillian_faq.php in the Prillian French 0.8.0 and e
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.