Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,724cataloged exploits
35,724CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,492GitHub PoC 14,286VulnCheck XDB 8,703Nuclei 4,314Metasploit 3,474✓ verified onlyrecentpopularrisk
22,429 exploits
Referência
CVE-2022-35899
There is an unquoted service path in ASUSTeK Aura Ready Game SDK service (GameSDK.exe) 1.0.0.4. This might allow a local
23RISK
open ↗Referência✓ VexDay Proof
TribunaLibre 3.12 Beta - 'ftag.php' Remote File Inclusion
PHP remote file inclusion vulnerability in ftag.php in TribunaLibre 3.12 Beta allows remote attackers to execute arbitra
23RISK
open ↗Referência
CVE-2022-35919
Authenticated requests for server update admin API allows path traversal in minio
53RISK
open ↗Referência✓ VexDay Proof
registroTL - 'main.php' Remote File Inclusion
PHP remote file inclusion vulnerability in main.php in registroTL allows remote attackers to execute arbitrary PHP code
23RISK
open ↗Referência
CVE-2022-36446
software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.
60RISK
open ↗Referência
CVE-2022-36446
software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.
60RISK
open ↗Referência
CVE-2022-37061
All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command Injection. This
60RISK
open ↗Referência✓ VexDay Proof
HP-UX 11i - 'swmodify' Local Stack Overflow / Local Privilege Escalation
Stack-based buffer overflow in the (1) swpackage and (2) swmodify commands in HP-UX B.11.11 and possibly other versions
23RISK
open ↗Referência✓ VexDay Proof
HP-UX 11i - 'swpackage' Local Stack Overflow / Local Privilege Escalation
Stack-based buffer overflow in the (1) swpackage and (2) swmodify commands in HP-UX B.11.11 and possibly other versions
23RISK
open ↗Referência✓ VexDay Proof
HP-UX 11i - 'swask' Format String Privilege Escalation
Format string vulnerability in the swask command in HP-UX B.11.11 and possibly other versions allows local users to exec
23RISK
open ↗Referência
CVE-2022-40946
On D-Link DIR-819 Firmware Version 1.06 Hardware Version A1 devices, it is possible to trigger a Denial of Service via t
41RISK
open ↗Referência
CVE-2022-41358
A stored cross-site scripting (XSS) vulnerability in Garage Management System v1.0 allows attackers to execute arbitrary
33RISK
open ↗Referência
CVE-2022-41413
perfSONAR v4.x <= v4.4.5 was discovered to contain a Cross-Site Request Forgery (CSRF) which is triggered when an attack
33RISK
open ↗Referência✓ VexDay Proof
SourceForge 1.0.4 - 'database.php' Remote File Inclusion
PHP remote file inclusion vulnerability in include/database.php in SourceForge (aka alexandria) 1.0.4 allows remote atta
23RISK
open ↗Referência
CVE-2022-42889
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open ↗Referência
CVE-2022-44877
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execut
100RISK
open ↗Referência
CVE-2022-45297
EQ v1.5.31 to v2.2.0 was discovered to contain a SQL injection vulnerability via the UserPwd parameter.
48RISK
open ↗Referência
CVE-2022-45701
Arris TG2482A firmware through 9.1.103GEM9 allow Remote Code Execution (RCE) via the ping utility feature.
53RISK
open ↗Referência✓ VexDay Proof
gtcatalog 0.9.1 - 'index.php' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in Chris Mac gtcatalog (aka GimeScripts Shopping Catalog) 0.9.1 and
23RISK
open ↗Referência✓ VexDay Proof
ASP Smiley 1.0 - 'default.asp' Authentication Bypass / SQL Injection
SQL injection vulnerability in admin/default.asp in ASP Smiley 1.0 allows remote attackers to execute arbitrary SQL comm
23RISK
open ↗Referência✓ VexDay Proof
Hpecs Shopping Cart - Remote Authentication Bypass
Multiple SQL injection vulnerabilities in Hpecs Shopping Cart allow remote attackers to execute arbitrary SQL commands v
23RISK
open ↗Referência
CVE-2022-46552
D-Link DIR-846 Firmware FW100A53DBR was discovered to contain a remote command execution (RCE) vulnerability via the lan
46RISK
open ↗Referência
CVE-2022-46770
qubes-mirage-firewall (aka Mirage firewall for QubesOS) 0.8.x through 0.8.3 allows guest OS users to cause a denial of s
61RISK
open ↗Referência
CVE-2022-47076
An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to view sensitive information via Display
41RISK
open ↗Referência
CVE-2022-47636
A DLL hijacking vulnerability has been discovered in OutSystems Service Studio 11 11.53.30 build 61739. When a user open
23RISK
open ↗Referência
CVE-2022-47874
Improper Access Control in /tc/rpc in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to view details of dat
38RISK
open ↗Referência
CVE-2022-47875
A Directory Traversal vulnerability in /be/erpc.php in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to ex
46RISK
open ↗Referência
CVE-2022-47876
The integrator in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to create Jobs to execute arbitrary code v
48RISK
open ↗Referência
CVE-2022-48110
CKSource CKEditor 5 35.4.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Full Featured CK
33RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.