Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,724cataloged exploits
35,724CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,492GitHub PoC 14,286VulnCheck XDB 8,703Nuclei 4,314Metasploit 3,474✓ verified onlyrecentpopularrisk
77,620 exploits
VulnCheck XDB
initial-access
Fortra GoAnywhere MFT License Response Servlet Command Injection
100RISK
open ↗Exploit-DB✓ VexDay Proof
Employee Task Management System v1.0 - SQL Injection on edit-task.php
SourceCodester Simple Food Ordering System process_order.php cross site scripting
28RISK
open ↗Exploit-DB✓ VexDay Proof
Employee Task Management System v1.0 - SQL Injection on (task-details.php?task_id=?)
SourceCodester Employee Task Management System task-details.php sql injection
33RISK
open ↗GitHub PoC★ 6
CVE-2023-22809 Linux Sudo
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISK
open ↗GitHub PoC
BaconCriCRi/PoC-CVE-2022-4939-
WCFM Membership <= 2.10.0 - Unauthenticated Privilege Escalation
48RISK
open ↗Exploit-DB✓ VexDay Proof
Auto Dealer Management System v1.0 - SQL Injection
SourceCodester Auto Dealer Management System sql injection
33RISK
open ↗GitHub PoC★ 8
GoAnywhere MFT CVE-2023-0669 LicenseResponseServlet Deserialization Vulnerabilities Python RCE PoC(Proof of Concept)
Fortra GoAnywhere MFT License Response Servlet Command Injection
100RISK
open ↗Exploit-DB✓ VexDay Proof
Art Gallery Management System Project in PHP v 1.0 - SQL injection
Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the pid par
23RISK
open ↗Exploit-DB✓ VexDay Proof
Simple Food Ordering System v1.0 - Cross-Site Scripting (XSS)
SourceCodester Simple Food Ordering System process_order.php cross site scripting
28RISK
open ↗Exploit-DB✓ VexDay Proof
Employee Task Management System v1.0 - Broken Authentication
SourceCodester Employee Task Management System changePasswordForEmployee.php improper authentication
41RISK
open ↗Exploit-DB✓ VexDay Proof
BTCPay Server v1.7.4 - HTML Injection
Improper Neutralization of Equivalent Special Elements in btcpayserver/btcpayserver
33RISK
open ↗VulnCheck XDB
local
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
68RISK
open ↗Exploit-DB
itech TrainSmart r1044 - SQL injection
A SQL injection vulnerability in I-Tech Trainsmart r1044 exists via a evaluation/assign-evaluation?id= URI.
41RISK
open ↗Exploit-DB
Froxlor 2.0.3 Stable - Remote Code Execution (RCE)
Command Injection in froxlor/froxlor
78RISK
open ↗Exploit-DB
Secure Web Gateway 10.2.11 - Cross-Site Scripting (XSS)
XSS in Skyhigh Security SWG
33RISK
open ↗Exploit-DB
ERPNext 12.29 - Cross-Site Scripting (XSS)
Frappe ERPNext 12.29.0 is vulnerable to XSS where the software does not neutralize or incorrectly neutralize user-contro
23RISK
open ↗Exploit-DB
Calendar Event Multi View 1.4.07 - Unauthenticated Arbitrary Event Creation to Cross-Site Scripting (XSS)
Calendar Event Multi View < 1.4.07 - Unauthenticated Arbitrary Event Creation to Stored XSS
33RISK
open ↗Exploit-DB
CKEditor 5 35.4.0 - Cross-Site Scripting (XSS)
CKSource CKEditor 5 35.4.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Full Featured CK
33RISK
open ↗Exploit-DB
Apache Tomcat 10.1 - Denial Of Service
EncryptInterceptor does not provide complete protection on insecure networks
45RISK
open ↗Exploit-DB
ImageMagick 7.1.0-49 - DoS
ImageMagick 7.1.0-49 is vulnerable to Denial of Service. When it parses a PNG image (e.g., for resize), the convert proc
55RISK
open ↗Exploit-DB
ImageMagick 7.1.0-49 - Arbitrary File Read
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RISK
open ↗Exploit-DB
Provide Server v.14.4 XSS - CSRF & Remote Code Execution (RCE)
Cross Site Scripting (XSS) vulnerability in Provide server 14.4 allows attackers to execute arbitrary code through the s
33RISK
open ↗Metasploit300
ThinManager Path Traversal (CVE-2023-27856) Arbitrary File Download
Rockwell Automation ThinManager ThinServer Path Traversal Download
58RISK
open ↗Exploit-DB
Dell EMC Networking PC5500 firmware versions 4.1.0.22 and Cisco Sx / SMB - Information Disclosure
Dell EMC Networking X-Series firmware versions 3.0.1.2 and older, Dell EMC Networking PC5500 firmware versions 4.1.0.22
46RISK
open ↗Metasploit300
ThinManager Path Traversal (CVE-2023-27855) Arbitrary File Upload
Rockwell Automation ThinManager ThinServer Path Traversal Upload
48RISK
open ↗Exploit-DB✓ VexDay Proof
Answerdev 1.0.3 - Account Takeover
Improper Access Control in answerdev/answer
48RISK
open ↗Exploit-DB
Liferay Portal 6.2.5 - Insecure Permissions
Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists. NOTE: The
53RISK
open ↗Exploit-DB✓ VexDay Proof
Responsive FileManager 9.9.5 - Remote Code Execution (RCE)
An issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanis
41RISK
open ↗Exploit-DB
D-Link DIR-846 - Remote Command Execution (RCE) vulnerability
D-Link DIR-846 Firmware FW100A53DBR was discovered to contain a remote command execution (RCE) vulnerability via the lan
46RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.