Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,620cataloged exploits
35,647CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,429GitHub PoC 14,270VulnCheck XDB 8,693Nuclei 4,299Metasploit 3,474✓ verified onlyrecentpopularrisk
22,407 exploits
Referência
CVE-2021-35323
Cross Site Scripting (XSS) vulnerability exists in bludit 3-13-1 via the username in admin/login.
38RISK
open ↗Referência
CVE-2021-35464
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pa
100RISK
open ↗Referência
CVE-2021-35464
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pa
100RISK
open ↗Referência
CVE-2021-3560
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open ↗Referência✓ VexDay Proof
WebprojectDB 0.1.3 - 'INCDIR' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in WebprojectDB 0.1.3 and earlier allow remote attackers to execute a
23RISK
open ↗Referência✓ VexDay Proof
aePartner 0.8.3 - 'dir[data]' Remote File Inclusion
PHP remote file inclusion vulnerability in inc/design.inc.php in LoveCompass aePartner 0.8.3 and earlier allows remote a
23RISK
open ↗Referência✓ VexDay Proof
free QBoard 1.1 - 'qb_path' Remote File Inclusion
PHP remote file inclusion vulnerability in board/post.php in free QBoard 1.1 and earlier allows remote attackers to exec
23RISK
open ↗Referência✓ VexDay Proof
WEBInsta MM 1.3e - 'cabsolute_path' Remote File Inclusion
PHP remote file inclusion vulnerability in install3.php in WEBInsta Mailing List Manager 1.3e allows remote attackers to
23RISK
open ↗Referência✓ VexDay Proof
Thatware 0.4.6 - 'ROOT_PATH' Remote File Inclusion
PHP remote file inclusion vulnerability in config.php in David Kent Norman Thatware 0.4.6 and possibly earlier allows re
23RISK
open ↗Referência
Sophos XG115w Firewall 17.0.10 MR-10 - Authentication Bypass
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sopho
100RISK
open ↗Referência
CVE-2022-1388
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open ↗Referência✓ VexDay Proof
PHP-revista 1.1.2 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in Longino Jacome php-Revista 1.1.2 allow remote attackers to execute arbitrary S
23RISK
open ↗Referência✓ VexDay Proof
SL_Site 1.0 - 'spaw_root' Remote File Inclusion
PHP remote file inclusion vulnerability in admin/editeur/spaw_control.class.php in Web Provence SL_Site 1.0 and earlier
28RISK
open ↗Referência✓ VexDay Proof
PhotoKorn Gallery 1.52 - 'dir_path' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in PhotoKorn Gallery 1.52 and earlier allow remote attackers to execu
28RISK
open ↗Referência✓ VexDay Proof
Fantastic News 2.1.4 - Multiple Remote File Inclusions
PHP remote file inclusion vulnerability in headlines.php in Fantastic News 2.1.4, and possibly earlier, allows remote at
23RISK
open ↗Referência✓ VexDay Proof
TIBCO Rendezvous 7.4.11 - Password Extractor
TIBCO RendezVous 7.4.11 and earlier logs base64-encoded usernames and passwords in rvrd.db, which allows local users to
23RISK
open ↗Referência✓ VexDay Proof
IBM Director < 5.10 - 'Redirect.bat' Directory Traversal
Directory traversal vulnerability in Redirect.bat in IBM Director before 5.10 allows remote attackers to read arbitrary
23RISK
open ↗Referência✓ VexDay Proof
CMtextS 1.0 - '/users_logins/admin.txt' Credentials Disclosure
CMtextS 1.0 and earlier stores users_logins/admin.txt under the web document root with insufficient access control, whic
23RISK
open ↗Referência✓ VexDay Proof
guanxiCRM Business Solution 0.9.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in include/phpxd/phpXD.php in guanxiCRM 0.9.1 and earlier allows remote attacker
23RISK
open ↗Referência
CVE-2022-22963
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open ↗Referência
CVE-2022-24637
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, wh
60RISK
open ↗Referência
CVE-2022-24637
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, wh
60RISK
open ↗Referência✓ VexDay Proof
PHP Blue Dragon CMS 2.9.1 - Cross-Site Scripting / SQL Injection Code Execution
Directory traversal vulnerability in pbd_engine.php in Php Blue Dragon 2.9.1 and earlier allows remote attackers to read
23RISK
open ↗Referência
CVE-2022-26134
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open ↗Referência✓ VexDay Proof
PHP Blue Dragon CMS 3.0.0 - Remote Code Execution
Directory traversal vulnerability in pbd_engine.php in Php Blue Dragon 2.9.1 and earlier allows remote attackers to read
23RISK
open ↗Referência✓ VexDay Proof
pNews 1.1.0 - 'nbs' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/global.php in Joshua Wilson pNews System 1.1.0 (aka PowerNews) allow
23RISK
open ↗Referência✓ VexDay Proof
PHPartenaire 1.0 - 'dix.php3' Remote File Inclusion
PHP remote file inclusion vulnerability in dix.php3 in PHPartenaire 1.0 allows remote attackers to execute arbitrary PHP
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component Joomlaboard 1.1.1 - 'sbp' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in the Joomlaboard Forum Component (com_joomlaboard) before 1.1.2 for
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.