Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,724cataloged exploits
35,724CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,492GitHub PoC 14,286VulnCheck XDB 8,703Nuclei 4,314Metasploit 3,474✓ verified onlyrecentpopularrisk
77,620 exploits
Exploit-DB
Tenda N300 F3 12.01.01.48 - Malformed HTTP Request Header Processing
Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_pas
60RISK
open ↗VulnCheck XDB
infoleak
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication c
100RISK
open ↗GitHub PoC★ 2
POC,EXP,chatGPT for me
Apache MINA SSHD: Java unsafe deserialization vulnerability
48RISK
open ↗Exploit-DB
NotrinosERP 0.7 - Authenticated Blind SQL Injection
NotrinosERP v0.7 was discovered to contain a SQL injection vulnerability via the OrderNumber parameter at /NotrinosERP/s
23RISK
open ↗GitHub PoC
jedai47/CVE-2018-7273
In the Linux kernel through 4.15.4, the floppy driver reveals the addresses of kernel functions and global variables usi
23RISK
open ↗Exploit-DB
MAC 1200R - Directory Traversal
A directory traversal vulnerability on Mercury MAC1200R devices allows attackers to read arbitrary files via a web-stati
41RISK
open ↗Exploit-DB✓ VexDay Proof
Music Gallery Site v1.0 - Broken Access Control
SourceCodester Music Gallery Site POST Request Users.php access control
41RISK
open ↗Exploit-DB
Agilebio Lab Collector Electronic Lab Notebook v4.234 - Remote Code Execution (RCE)
AgileBio Electronic Lab Notebook v4.234 was discovered to contain a local file inclusion vulnerability.
41RISK
open ↗Exploit-DB
Dompdf 1.2.1 - Remote Code Execution (RCE)
Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (
60RISK
open ↗GitHub PoC
qaisarafridi/cve-2021-3129
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open ↗Exploit-DB
TitanFTP 2.0.1.2102 - Path traversal to Remote Code Execution (RCE)
An issue was discovered in TitanFTP through 1.94.1205. The move-file function has a path traversal vulnerability in the
61RISK
open ↗Exploit-DB✓ VexDay Proof
Music Gallery Site v1.0 - SQL Injection on page view_music_details.php
SourceCodester Music Gallery Site GET Request view_music_details.php sql injection
33RISK
open ↗Exploit-DB✓ VexDay Proof
Music Gallery Site v1.0 - SQL Injection on music_list.php
SourceCodester Music Gallery Site GET Request music_list.php sql injection
33RISK
open ↗VulnCheck XDB
initial-access
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open ↗Exploit-DB✓ VexDay Proof
Simple Task Managing System v1.0 - SQL Injection (Unauthenticated)
SQL Injection vulnerability in Simple Task Managing System version 1.0 in login.php in 'username' and 'password' paramet
68RISK
open ↗Exploit-DB✓ VexDay Proof
Intern Record System v1.0 - SQL Injection (Unauthenticated)
SQL Injection vulnerability in Intern Record System version 1.0 in /intern/controller.php in 'phone', 'email', 'deptType
48RISK
open ↗Exploit-DB✓ VexDay Proof
Best pos Management System v1.0 - Remote Code Execution (RCE) on File Upload
SourceCodester Best POS Management System Image save_settings unrestricted upload
33RISK
open ↗Exploit-DB✓ VexDay Proof
Auto Dealer Management System v1.0 - SQL Injection in sell_vehicle.php
SourceCodester Auto Dealer Management System sql injection
33RISK
open ↗VulnCheck XDB
initial-access
Fortra GoAnywhere MFT License Response Servlet Command Injection
100RISK
open ↗Exploit-DB
Arris Router Firmware 9.1.103 - Remote Code Execution (RCE) (Authenticated)
Arris TG2482A firmware through 9.1.103GEM9 allow Remote Code Execution (RCE) via the ping utility feature.
53RISK
open ↗Exploit-DB
Mitel MiCollab AWV 8.1.2.4 and 9.1.3 - Directory Traversal and LFI
A Directory Traversal vulnerability in the web conference component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before
50RISK
open ↗Exploit-DB✓ VexDay Proof
Auto Dealer Management System 1.0 - Broken Access Control Exploit
SourceCodester Auto Dealer Management System Users.php access control
33RISK
open ↗Exploit-DB✓ VexDay Proof
Music Gallery Site v1.0 - SQL Injection on page Master.php
SourceCodester Music Gallery Site GET Request Master.php sql injection
33RISK
open ↗Exploit-DB✓ VexDay Proof
Art Gallery Management System Project in PHP v 1.0 - SQL injection
Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the pid par
23RISK
open ↗Exploit-DB✓ VexDay Proof
Auto Dealer Management System v1.0 - SQL Injection on manage_user.php
SourceCodester Auto Dealer Management System sql injection
33RISK
open ↗Exploit-DB✓ VexDay Proof
Employee Task Management System v1.0 - SQL Injection on edit-task.php
SourceCodester Simple Food Ordering System process_order.php cross site scripting
28RISK
open ↗GitHub PoC★ 1
CVE-2023-23752
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.