Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,620cataloged exploits
35,647CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,429GitHub PoC 14,270VulnCheck XDB 8,693Nuclei 4,299Metasploit 3,474✓ verified onlyrecentpopularrisk
22,429 exploits
Referência✓ VexDay Proof
KTP Computer Customer Database CMS 1.0 - Blind SQL Injection
SQL injection vulnerability in KTP Computer Customer Database (KTPCCD) CMS, when magic_quotes_gpc is disabled, allows re
23RISK
open ↗Referência
CVE-2026-7732
code-projects BloodBank Managing System request_blood.php unrestricted upload
33RISK
open ↗Referência✓ VexDay Proof
Active Test 2.1 - 'QuizID' Blind SQL Injection
Multiple SQL injection vulnerabilities in Active Test 2.1 allow remote attackers to execute arbitrary SQL commands via t
23RISK
open ↗Referência
CVE-2024-10914
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISK
open ↗Referência
CVE-2026-19823
Tenda W20E QoS Rule Deletion delQos formQOSRuleDel stack-based overflow
41RISK
open ↗Referência
CVE-2019-9082
ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public/
100RISK
open ↗Referência✓ VexDay Proof
Active Price Comparison 4 - Authentication Bypass
Multiple SQL injection vulnerabilities in login.aspx in Active Price Comparison 4.0 allow remote attackers to execute ar
23RISK
open ↗Referência✓ VexDay Proof
Netartmedia Jobs Portal 1.3 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in NetArtMedia Jobs Portal 1.3 allow remote attackers to execute arbitrary SQL co
23RISK
open ↗Referência
CVE-2025-34028
Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal
100RISK
open ↗Referência★ 21
watchtowrlabs/watchTowr-vs-Commvault-PreAuth-RCE-CVE-2025-34028
Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal
100RISK
open ↗Referência✓ VexDay Proof
WSN Links 2.22/2.23 - 'vote.php' SQL Injection
SQL injection vulnerability in vote.php in WSN Links 2.22 and 2.23 allows remote attackers to execute arbitrary SQL comm
23RISK
open ↗Referência
CVE-2023-1671
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10
100RISK
open ↗Referência
CVE-2026-19791
Tenda G0 httpd web management interface module addStaticRoute stack-based overflow
41RISK
open ↗Referência
CVE-2026-19790
Tenda G0 httpd Web Management module formSetPortMirror stack-based overflow
41RISK
open ↗Referência
CVE-2026-19789
Tenda AC1206 httpd web management interface WifiGuestSet set_wl_guest_iplist stack-based overflow
41RISK
open ↗Referência
CVE-2026-19788
Tenda AC1206 httpd web management interface SetOnlineDevName set_device_name stack-based overflow
41RISK
open ↗Referência✓ VexDay Proof
DomPHP 0.81 - 'cat' SQL Injection
Multiple SQL injection vulnerabilities in DomPHP 0.81 allow remote attackers to execute arbitrary SQL commands via the c
23RISK
open ↗Referência
CVE-2023-26360
Adobe ColdFusion Improper Access Control Arbitrary code execution
100RISK
open ↗Referência
CVE-2021-44790
Possible buffer overflow when parsing multipart content in mod_lua of Apache HTTP Server 2.4.51 and earlier
45RISK
open ↗Referência
CVE-2018-9206
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
60RISK
open ↗Referência
CVE-2016-7089
WatchGuard RapidStream appliances allow local users to gain privileges and execute arbitrary commands via a crafted ifco
23RISK
open ↗Referência
CVE-2012-0782
Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/setup-config.php in the installation component in WordPr
23RISK
open ↗Referência✓ VexDay Proof
Titan FTP Server 6.26 build 630 - Remote Denial of Service
Titan FTP Server 6.26 build 630 allows remote attackers to cause a denial of service (CPU consumption) via the SITE WHO
50RISK
open ↗Referência✓ VexDay Proof
Iamma Simple Gallery 1.0/2.0 - Arbitrary File Upload
Unrestricted file upload vulnerability in pages/download.php in Iamma Simple Gallery 1.0 and 2.0 allows remote attackers
23RISK
open ↗Referência✓ VexDay Proof
Back-End CMS 0.7.2.2 - 'BE_config.php' Remote File Inclusion
PHP remote file inclusion vulnerability in BE_config.php in Back-End CMS 0.7.2.1 and earlier allows remote attackers to
23RISK
open ↗Referência✓ VexDay Proof
Camera Life 2.6.2b4 - SQL Injection / Cross-Site Scripting
SQL injection vulnerability in album.php in Camera Life 2.6.2b4 allows remote attackers to execute arbitrary SQL command
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.