Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,813cataloged exploits
35,788CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,549GitHub PoC 14,290VulnCheck XDB 8,722Nuclei 4,320Metasploit 3,477✓ verified onlyrecentpopularrisk
22,523 exploits
Referência
CVE-2013-5692
Directory traversal vulnerability in X2Engine X2CRM before 3.5 allows remote authenticated administrators to include and
23RISK
open ↗Referência
CVE-2009-4964
Stack-based buffer overflow in KSP 2006 FINAL allows remote attackers to execute arbitrary code via a long string in a .
23RISK
open ↗Referência
CVE-2009-3338
Stack-based buffer overflow in EffectMatrix (E.M.) Magic Morph 1.95b allows remote attackers to execute arbitrary code v
23RISK
open ↗Referência
CVE-2009-3670
Stack-based buffer overflow in KSP Sound Player 2009 R2 and R2.1 allows remote attackers to execute arbitrary code via a
23RISK
open ↗Referência
CVE-2017-13784
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RISK
open ↗Referência
CVE-2017-13785
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RISK
open ↗Referência
CVE-2014-0620
Multiple cross-site scripting (XSS) vulnerabilities in Technicolor (formerly Thomson) TC7200 STD6.01.12 allow remote att
23RISK
open ↗Referência✓ VexDay Proof
Mambo Component SMF Forum 1.3.1.3 - Remote File Inclusion
PHP remote file inclusion vulnerability in smf.php in the SMF-Forum 1.3.1.3 Bridge Component (com_smf) For Joomla! and M
23RISK
open ↗Referência
CVE-2014-4311
Epicor Enterprise 7.4 before FS74SP6_HotfixTL054181 allows attackers to obtain the (1) Database Connection and (2) E-mai
23RISK
open ↗Referência✓ VexDay Proof
Myspace Clone Script - 'index.php' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in datecomm Social Networking Script (aka Myspace Clone Script) all
23RISK
open ↗Referência✓ VexDay Proof
TUTOS 1.3 - 'cmd.php' Remote Command Execution
TUTOS 1.3 does not restrict access to php/admin/cmd.php, which allows remote attackers to execute arbitrary shell comman
23RISK
open ↗Referência✓ VexDay Proof
asg-sentry 7.0.0 - Multiple Vulnerabilities
Multiple buffer overflows in ASG-Sentry Network Manager 7.0.0 and earlier allow remote attackers to execute arbitrary co
28RISK
open ↗Referência
CVE-2018-12292
A use-after-free vulnerability exists in DOMProxyHandler::EnsureExpandoObject in Pale Moon before 27.9.3.
23RISK
open ↗Referência
CVE-2017-2371
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. The issue involves the "WebKit" compon
23RISK
open ↗Referência
CVE-2021-24750
WP Visitor Statistics (Real Time Traffic) < 4.8 - Subscriber+ SQL Injection
50RISK
open ↗Referência
CVE-2020-12352
Improper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adja
23RISK
open ↗Referência
CVE-2020-12352
Improper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adja
23RISK
open ↗Referência
CVE-2020-8899
Memory corruption in Quram library when decoding qmg can lead to RCE
48RISK
open ↗Referência
CVE-2011-0502
Music Animation Machine MIDI Player 2006aug19 Release 035 and possibly other versions allows user-assisted remote attack
23RISK
open ↗Referência
CVE-2025-14708
Shiguangwu sgwbox N3 WIREDCFGGET http_eshell_server buffer overflow
48RISK
open ↗Referência
CVE-2018-4193
An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Windows Ser
23RISK
open ↗Referência
CVE-2017-8869
Buffer overflow in MediaCoder 0.8.48.5888 allows remote attackers to execute arbitrary code via a crafted .m3u file.
43RISK
open ↗Referência✓ VexDay Proof
PHPFK 7.03 - 'page_bottom.php' Local File Inclusion
Directory traversal vulnerability in include/page_bottom.php in phpFK 7.03 allows remote attackers to include and execut
23RISK
open ↗Referência✓ VexDay Proof
e107 Plugin My_Gallery 2.3 - Arbitrary File Download
Absolute path traversal vulnerability in dload.php in the my_gallery 2.3 plugin for e107 allows remote attackers to obta
23RISK
open ↗Referência
CVE-2018-10655
DLPnpAuditor.exe in DeviceLock Plug and Play Auditor (freeware) 5.72 has a Unicode Buffer Overflow (SEH).
28RISK
open ↗Referência
CVE-2018-10655
DLPnpAuditor.exe in DeviceLock Plug and Play Auditor (freeware) 5.72 has a Unicode Buffer Overflow (SEH).
28RISK
open ↗Referência
CVE-2010-1046
Multiple SQL injection vulnerabilities in index.php in Rostermain 1.1 and earlier allow remote attackers to execute arbi
23RISK
open ↗Referência
CVE-2009-3484
Stack-based buffer overflow in Core FTP 2.1 build 1612 allows user-assisted remote attackers to execute arbitrary code v
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.