Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,620cataloged exploits
35,647CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,429GitHub PoC 14,270VulnCheck XDB 8,693Nuclei 4,299Metasploit 3,474✓ verified onlyrecentpopularrisk
22,429 exploits
Referência✓ VexDay Proof
mxBB Module Meeting 1.1.2 - Remote File Inclusion
PHP remote file inclusion vulnerability in pages/meeting_constants.php in the Meeting (mx_meeting) 1.1.2 and earlier mod
23RISK
open ↗Referência✓ VexDay Proof
mxbb module charts 1.0.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in charts_constants.php in the Charts (mx_charts) 1.0.0 and earlier module for m
23RISK
open ↗Referência
CVE-2011-5211
Cross-site scripting (XSS) vulnerability in the poll module in Subrion CMS 2.0.4 allows remote attackers to inject arbit
23RISK
open ↗Referência
CVE-2026-7738
puchunjie doc-tools-mcp MCP mcp-server.ts open_document path traversal
33RISK
open ↗Referência✓ VexDay Proof
ccTiddly 1.7.4 - 'cct_base' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in ccTiddly 1.7.4 and 1.7.6 allow remote attackers to execute arbitra
23RISK
open ↗Referência✓ VexDay Proof
template creature - SQL Injection / File Disclosure
SQL injection vulnerability in media/media_level.asp in ASP Template Creature allows remote attackers to execute arbitra
23RISK
open ↗Referência✓ VexDay Proof
template creature - SQL Injection / File Disclosure
ASP Template Creature stores sensitive information under the web root with insufficient access control, which allows rem
23RISK
open ↗Referência
CVE-2024-10914
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISK
open ↗Referência
CVE-2026-19823
Tenda W20E QoS Rule Deletion delQos formQOSRuleDel stack-based overflow
41RISK
open ↗Referência
CVE-2019-9082
ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public/
100RISK
open ↗Referência✓ VexDay Proof
Active Price Comparison 4 - Authentication Bypass
Multiple SQL injection vulnerabilities in login.aspx in Active Price Comparison 4.0 allow remote attackers to execute ar
23RISK
open ↗Referência✓ VexDay Proof
Ocean12 Mailing List Manager Gold - File Disclosure / SQL Injection / Cross-Site Scripting
Multiple SQL injection vulnerabilities in Ocean12 Mailing List Manager Gold allow remote attackers to execute arbitrary
23RISK
open ↗Referência✓ VexDay Proof
Jetik Emlak ESA 2.0 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in Jetik Emlak Sistem A (ESA) 2.0 allow remote attackers to execute arbitrary SQL
23RISK
open ↗Referência✓ VexDay Proof
I-Rater Basic - SQL Injection
SQL injection vulnerability in messages.php in I-Rater Basic allows remote attackers to execute arbitrary SQL commands v
23RISK
open ↗Referência
CVE-2019-0230
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lea
60RISK
open ↗Referência
CVE-2019-0230
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lea
60RISK
open ↗Referência
CVE-2026-19812
TOTOLINK A800R product.so cstecgi.cgi UploadCustomModule stack-based overflow
41RISK
open ↗Referência✓ VexDay Proof
Uploader & Downloader 3.0 - 'id_user' SQL Injection
SQL injection vulnerability in administration/administre2.php in Eric GUILLAUME uploader&downloader 3 allows remote atta
23RISK
open ↗Referência
CVE-2026-19811
TOTOLINK A800R firewall.so cstecgi.cgi setIpQosRules stack-based overflow
41RISK
open ↗Referência
CVE-2026-18039
Essential Addons for Elementor < 6.7.2 - Unauthenticated Privilege Escalation via Custom Profile Field Mass Assignment
41RISK
open ↗Referência
CVE-2026-16739
Epeken All Kurir <= 2.1.2 - Unauthenticated Order Payment Confirmation Forgery
33RISK
open ↗Referência✓ VexDay Proof
Fez 1.3/2.0 RC1 - 'list.php' SQL Injection
SQL injection vulnerability in list.php in University of Queensland Library Fez 1.3 and 2.0 RC1 allows remote attackers
23RISK
open ↗Referência
CVE-2017-3248
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Core Components). Suppo
60RISK
open ↗Referência
CVE-2026-15205
Paymob for WooCommerce < 4.1.9 - Unauthenticated SQL Injection via Paymob Callback Pixel Lookup
41RISK
open ↗Referência
CVE-2026-14290
Embed Google Photos Album Easily <= 2.2.1 - Contributor+ Stored XSS via link Shortcode Attribute
33RISK
open ↗Referência✓ VexDay Proof
Bandwebsite 1.5 - 'LOGIN' Remote Add Admin
Bandwebsite (aka Bandsite portal system) 1.5 allows remote attackers to create administrative accounts via a direct requ
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.