Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,343cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,721GitHub PoC 14,496VulnCheck XDB 8,829Nuclei 4,350Metasploit 3,489✓ verified onlyrecentpopularrisk
22,573 exploits
Referência✓ VexDay Proof
Uploader & Downloader 3.0 - 'id_user' SQL Injection
SQL injection vulnerability in administration/administre2.php in Eric GUILLAUME uploader&downloader 3 allows remote atta
23RISK
open ↗Referência✓ VexDay Proof
Bandwebsite 1.5 - 'LOGIN' Remote Add Admin
Bandwebsite (aka Bandsite portal system) 1.5 allows remote attackers to create administrative accounts via a direct requ
23RISK
open ↗Referência✓ VexDay Proof
MiniBB 2.2 - Cross-Site Scripting / SQL Injection / Full Path Disclosure
Cross-site scripting (XSS) vulnerability in index.php in miniBB 2.2, and possibly earlier, when register_globals is enab
23RISK
open ↗Referência
CVE-2025-34028
Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal
100RISK
open ↗Referência★ 21
watchtowrlabs/watchTowr-vs-Commvault-PreAuth-RCE-CVE-2025-34028
Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal
100RISK
open ↗Referência
Payara Micro Community 5.2021.6 - Directory Traversal
Payara Micro Community 5.2021.6 and below allows Directory Traversal.
50RISK
open ↗Referência
CVE-2023-1671
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10
100RISK
open ↗Referência
CVE-2026-19791
Tenda G0 httpd web management interface module addStaticRoute stack-based overflow
41RISK
open ↗Referência
CVE-2021-41773
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open ↗Referência
CVE-2026-19790
Tenda G0 httpd Web Management module formSetPortMirror stack-based overflow
41RISK
open ↗Referência
CVE-2026-19789
Tenda AC1206 httpd web management interface WifiGuestSet set_wl_guest_iplist stack-based overflow
41RISK
open ↗Referência
CVE-2026-19788
Tenda AC1206 httpd web management interface SetOnlineDevName set_device_name stack-based overflow
41RISK
open ↗Referência
CVE-2021-41773
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open ↗Referência
CVE-2021-41773
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open ↗Referência
CVE-2021-41773
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open ↗Referência✓ VexDay Proof
MiniBB 2.2 - Cross-Site Scripting / SQL Injection / Full Path Disclosure
Multiple SQL injection vulnerabilities in (1) setup_mysql.php and (2) setup_options.php in miniBB 2.2 and possibly earli
23RISK
open ↗Referência✓ VexDay Proof
Siteman 2.x - Code Execution / Local File Inclusion / Cross-Site Scripting
Directory traversal vulnerability in index.php in Siteman 2.0.x2 allows remote authenticated administrators to include a
23RISK
open ↗Referência
CVE-2023-26360
Adobe ColdFusion Improper Access Control Arbitrary code execution
100RISK
open ↗Referência✓ VexDay Proof
PHP Forge 3 Beta 2 - 'id' SQL Injection
SQL injection vulnerability in admin/news.php in PHP Forge 3.0 beta 2 allows remote attackers to execute arbitrary SQL c
23RISK
open ↗Referência
CVE-2018-9206
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
60RISK
open ↗Referência✓ VexDay Proof
Joomla! Component FlippingBook 1.0.4 - SQL Injection
SQL injection vulnerability in index.php in the FlippingBook (com_flippingbook) 1.0.4 component for Joomla! allows remot
23RISK
open ↗Referência✓ VexDay Proof
BackLinkSpider 1.1 - 'cat_id' SQL Injection
SQL injection vulnerability in BackLinkSpider allows remote attackers to execute arbitrary SQL commands via the cat_id p
23RISK
open ↗Referência✓ VexDay Proof
Netartmedia Jobs Portal 1.3 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in NetArtMedia Jobs Portal 1.3 allow remote attackers to execute arbitrary SQL co
23RISK
open ↗Referência✓ VexDay Proof
WSN Links 2.22/2.23 - 'vote.php' SQL Injection
SQL injection vulnerability in vote.php in WSN Links 2.22 and 2.23 allows remote attackers to execute arbitrary SQL comm
23RISK
open ↗Referência
CVE-2019-12255
Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4). This is a IPNET security vulnerability: TC
45RISK
open ↗Referência✓ VexDay Proof
Pre Shopping Mall 1.1 - 'search.php' SQL Injection
SQL injection vulnerability in emall/search.php in Pre Shopping Mall 1.1 allows remote attackers to execute arbitrary SQ
23RISK
open ↗Referência
CVE-2026-19756
Dromara lamp-cloud Code Generator DefGenProjectController.java path traversal
33RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.