Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,772cataloged exploits
35,760CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,523GitHub PoC 14,289VulnCheck XDB 8,710Nuclei 4,319Metasploit 3,476✓ verified onlyrecentpopularrisk
22,523 exploits
Referência
CVE-2018-15152
Authentication bypass vulnerability in portal/account/register.php in versions of OpenEMR before 5.0.1.4 allows a remote
28RISK
open ↗Referência
CVE-2023-30013
TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setting/s
68RISK
open ↗Referência
CVE-2017-16886
The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact
23RISK
open ↗Referência
CVE-2009-4531
httpdx 1.4.4 and earlier allows remote attackers to obtain the source code for a web page by appending a . (dot) charact
23RISK
open ↗Referência
CVE-2014-5092
Status2k allows Remote Command Execution in admin/options/editpl.php.
23RISK
open ↗Referência
CVE-2017-8652
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to disclose in
28RISK
open ↗Referência
CVE-2020-11804
An issue was discovered in Titan SpamTitan 7.07. Due to improper sanitization of the parameter quid, used in the page ma
23RISK
open ↗Referência
CVE-2017-15220
Flexense VX Search Enterprise 10.1.12 is vulnerable to a buffer overflow via an empty POST request to a long URI beginni
23RISK
open ↗Referência
Rukovoditel Project Management CRM 2.3.1 - Remote Code Execution (Metasploit)
A file-upload vulnerability exists in Rukovoditel 2.3.1. index.php?module=configuration/save allows the user to upload a
23RISK
open ↗Referência
CVE-2010-0672
SQL injection vulnerability in index.php in WSN Guest 1.02 allows remote attackers to execute arbitrary SQL commands via
23RISK
open ↗Referência
CVE-2017-0175
The Windows kernel in Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows authenticated attackers to obtain sen
23RISK
open ↗Referência
CVE-2010-3136
Untrusted search path vulnerability in Skype 4.2.0.169 and earlier allows local users, and possibly remote attackers, to
23RISK
open ↗Referência
CVE-2015-2527
The process-initialization implementation in win32k.sys in the kernel-mode drivers in Microsoft Windows 8, Windows 8.1,
23RISK
open ↗Referência
CVE-2018-5715
phprint.php in SugarCRM 3.5.1 has XSS via a parameter name in the query string (aka a $key variable).
38RISK
open ↗Referência
CVE-2014-100029
Multiple directory traversal vulnerabilities in class/session.php in Ganesha Digital Library (GDL) 4.2 allow remote atta
23RISK
open ↗Referência
CVE-2017-2365
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS
23RISK
open ↗Referência
CVE-2010-3468
Directory traversal vulnerability in fileManager.cfc in Mura CMS 5.1 before 5.1.498 and 5.2 before 5.2.2809, and Sava CM
23RISK
open ↗Referência✓ VexDay Proof
RGameScript Pro - 'page.php?id' Remote File Inclusion
PHP remote file inclusion vulnerability in page.php in RCMS Pro RGameScript Pro allows remote attackers to execute arbit
23RISK
open ↗Referência
CVE-2017-7018
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RISK
open ↗Referência✓ VexDay Proof
BS.Player 2.27 Build 959 - '.srt' File Buffer Overflow (PoC)
Buffer overflow in BS.player 2.27 build 959 allows remote attackers to cause a denial of service (crash) and possibly ex
23RISK
open ↗Referência
CVE-2019-16679
Gila CMS before 1.11.1 allows admin/fm/?f=../ directory traversal, leading to Local File Inclusion.
23RISK
open ↗Referência✓ VexDay Proof
EZContents CMS 2.0.3 - Multiple Local File Inclusions
Multiple directory traversal vulnerabilities in ezContents 2.0.3 allow remote attackers to include and execute arbitrary
23RISK
open ↗Referência
CVE-2009-3365
PHP remote file inclusion vulnerability in add-ons/modules/sysmanager/plugins/install.plugin.php in Aurora CMS 1.0.2 all
23RISK
open ↗Referência✓ VexDay Proof
EasyMail MessagePrinter Object - 'emprint.dll 6.0.1.0' Remote Buffer Overflow
Heap-based buffer overflow in the EasyMailMessagePrinter ActiveX control in emprint.DLL 6.0.1.0 in the Quiksoft EasyMail
23RISK
open ↗Referência✓ VexDay Proof
Mcafee EPO 4.0 - 'FrameworkService.exe' Remote Denial of Service
FrameworkService.exe in McAfee Common Management Agent (CMA) 3.6.0.574 Patch 3 and earlier, as used by ePolicy Orchestra
23RISK
open ↗Referência
CVE-2010-4935
SQL injection vulnerability in poll.php in Entrans 0.3.2 and earlier allows remote attackers to execute arbitrary SQL co
23RISK
open ↗Referência
CVE-2010-4940
SQL injection vulnerability in index.php in WAnewsletter 2.1.2 allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗Referência
CVE-2015-6763
Multiple unspecified vulnerabilities in Google Chrome before 46.0.2490.71 allow attackers to cause a denial of service o
23RISK
open ↗Referência
CVE-2015-6763
Multiple unspecified vulnerabilities in Google Chrome before 46.0.2490.71 allow attackers to cause a denial of service o
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.