Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,772cataloged exploits
35,760CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,523GitHub PoC 14,289VulnCheck XDB 8,710Nuclei 4,319Metasploit 3,476✓ verified onlyrecentpopularrisk
22,523 exploits
Referência
FortiWeb Fabric Connector 7.6.x - SQL Injection to Remote Code Execution
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RISK
open ↗Referência✓ VexDay Proof
Eggdrop/Windrop 1.6.19 - ctcpbuf Remote Crash
mod/server.mod/servmsg.c in Eggheads Eggdrop and Windrop 1.6.19 and earlier allows remote attackers to cause a denial of
23RISK
open ↗Referência
CVE-2010-1302
Directory traversal vulnerability in dwgraphs.php in the DecryptWeb DW Graphs (com_dwgraphs) component 1.0 for Joomla! a
38RISK
open ↗Referência
CVE-2017-14704
Multiple unrestricted file upload vulnerabilities in the (1) imageSubmit and (2) proof_submit functions in Claydip Larav
23RISK
open ↗Referência✓ VexDay Proof
Mozilla Firefox 3.0.5 - location.hash Remote Crash
Mozilla Firefox 3.0.5 on Windows Vista allows remote attackers to cause a denial of service (application crash) via Java
23RISK
open ↗Referência
CVE-2016-5063
The RSCD agent in BMC Server Automation before 8.6 SP1 Patch 2 and 8.7 before Patch 3 on Windows might allow remote atta
23RISK
open ↗Referência
CVE-2018-7317
Backup Download exists in the Proclaim 9.1.1 component for Joomla! via a direct request for a .sql file under backup/.
23RISK
open ↗Referência
CVE-2010-3460
Directory traversal vulnerability in the HTTP interface in AXIGEN Mail Server 7.4.1 for Windows allows remote attackers
23RISK
open ↗Referência
CVE-2009-2917
Stack-based buffer overflow in ImTOO MPEG Encoder 3.1.53 allows remote attackers to cause a denial of service (crash) or
23RISK
open ↗Referência
CVE-2022-25359
On ICL ScadaFlex II SCADA Controller SC-1 and SC-2 1.03.07 devices, unauthenticated remote attackers can overwrite, dele
35RISK
open ↗Referência✓ VexDay Proof
PHPStore Real Estate - Arbitrary File Upload
Unrestricted file upload vulnerability in PHPStore Real Estate allows remote authenticated users to execute arbitrary co
23RISK
open ↗Referência✓ VexDay Proof
ashNews 0.83 - 'pathtoashnews' Remote File Inclusion
PHP remote file include vulnerability in Derek Ashauer ashNews 0.83 allows remote attackers to include and execute arbit
23RISK
open ↗Referência
CVE-2019-12252
In Zoho ManageEngine ServiceDesk Plus through 10.5, users with the lowest privileges (guest) can view an arbitrary post
23RISK
open ↗Referência
CVE-2017-11398
A session hijacking via log disclosure vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 an
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component LMO 1.0b2 - Remote File Inclusion
PHP remote file inclusion vulnerability in lmo.php in the LMO Component (com_lmo) 1.0b2 and earlier for Joomla! allows r
23RISK
open ↗Referência
CVE-2010-4279
The default configuration of Pandora FMS 3.1 and earlier specifies an empty string for the loginhash_pwd field, which al
50RISK
open ↗Referência
CVE-2010-4281
Incomplete blacklist vulnerability in the safe_url_extraclean function in ajax.php in Pandora FMS before 3.1.1 allows re
23RISK
open ↗Referência✓ VexDay Proof
UNAK-CMS 1.5 - 'dirroot' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in UNAK-CMS 1.5 and earlier allow remote attackers to execute arbitra
23RISK
open ↗Referência✓ VexDay Proof
CWB PRO 1.5 - 'INCLUDE_PATH' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in GraFX Company WebSite Builder (CWB) PRO 1.5 allow remote attackers
23RISK
open ↗Referência✓ VexDay Proof
XnView 1.92.1 - 'FontName' Slideshow Buffer Overflow
Stack-based buffer overflow in XnView 1.92 and 1.92.1 allows user-assisted remote attackers to execute arbitrary code vi
23RISK
open ↗Referência✓ VexDay Proof
eXV2 Module MyAnnonces - 'lid' SQL Injection
SQL injection vulnerability in annonces-p-f.php in the MyAnnonces 1.8 module for eXV2 allows remote attackers to execute
23RISK
open ↗Referência✓ VexDay Proof
eXV2 Module WebChat 1.60 - 'roomid' SQL Injection
SQL injection vulnerability in index.php in the WebChat 1.60 module for eXV2 allows remote attackers to execute arbitrar
23RISK
open ↗Referência
CVE-2019-16645
An issue was discovered in Embedthis GoAhead 2.5.0. Certain pages (such as goform/login and config/log_off_page.htm) cre
23RISK
open ↗Referência
CVE-2019-15501
Reflected cross site scripting (XSS) in L-Soft LISTSERV before 16.5-2018a exists via the /scripts/wa.exe OK parameter.
38RISK
open ↗Referência
CVE-2015-7564
Multiple SQL injection vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to execute arbitrary SQL co
23RISK
open ↗Referência
CVE-2013-5528
Directory traversal vulnerability in the Tomcat administrative web interface in Cisco Unified Communications Manager all
43RISK
open ↗Referência
CVE-2010-1607
Directory traversal vulnerability in wmi.php in the Webmoney Web Merchant Interface (aka WMI or com_wmi) component 1.5.0
38RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.