Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,813cataloged exploits
35,788CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,549GitHub PoC 14,290VulnCheck XDB 8,722Nuclei 4,320Metasploit 3,477✓ verified onlyrecentpopularrisk
22,549 exploits
Referência
CVE-2013-6232
Cross-site scripting (XSS) vulnerability in SpagoBI before 4.1 allows remote authenticated users to inject arbitrary web
23RISK
open ↗Referência
CVE-2015-1427
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the s
100RISK
open ↗Referência✓ VexDay Proof
ModSecurity < 2.5.9 - Remote Denial of Service
The multipart processor in ModSecurity before 2.5.9 allows remote attackers to cause a denial of service (crash) via a m
28RISK
open ↗Referência✓ VexDay Proof
uniForum 4 - 'wbsearch.aspx' SQL Injection
SQL injection vulnerability in wbsearch.aspx in uniForum 4 and earlier allows remote attackers to execute arbitrary SQL
23RISK
open ↗Referência
CVE-2026-24061
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open ↗Referência✓ VexDay Proof
CPCommerce 1.2.x - 'GLOBALS[prefix]' Arbitrary File Inclusion
_functions.php in cpCommerce 1.2.x, possibly including 1.2.9, sends a redirect but does not exit when it is called direc
60RISK
open ↗Referência✓ VexDay Proof
WebEyes Guest Book 3 - 'yorum.asp?mesajid' SQL Injection
SQL injection vulnerability in yorum.asp in WebEyes Guest Book 3 allows remote attackers to execute arbitrary SQL comman
23RISK
open ↗Referência✓ VexDay Proof
propertymax pro free - SQL Injection / Cross-Site Scripting
Multiple SQL injection vulnerabilities in the administrative login feature in PropertyMax Pro FREE 0.3, when magic_quote
23RISK
open ↗Referência✓ VexDay Proof
Apache mod_dav / svn - Remote Denial of Service
The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav
35RISK
open ↗Referência✓ VexDay Proof
Family Connections CMS 1.9 - SQL Injection
Multiple SQL injection vulnerabilities in Haudenschilt Family Connections CMS (FCMS) 1.9 and earlier allow remote authen
23RISK
open ↗Referência✓ VexDay Proof
Worldweaver DX Studio Player < 3.0.29.1 Firefox plugin - Command Injection
Worldweaver DX Studio Player 3.0.29.0, 3.0.22.0, 3.0.12.0, and probably other versions before 3.0.29.1, when used as a p
50RISK
open ↗Referência✓ VexDay Proof
Joomla! Component MooFAQ (com_moofaq) - Local File Inclusion
Directory traversal vulnerability in includes/file_includer.php in the Ideal MooFAQ (com_moofaq) component 1.0 for Jooml
38RISK
open ↗Referência✓ VexDay Proof
PHPWebThings 1.5.2 - 'help.php?module' Local File Inclusion
Directory traversal vulnerability in help.php in phpWebThings 1.5.2 and earlier, when magic_quotes_gpc is disabled, allo
23RISK
open ↗Referência✓ VexDay Proof
Mundi Mail 0.8.2 - 'top' Remote File Inclusion
PHP remote file inclusion vulnerability in template/simpledefault/admin/_masterlayout.php in Mundi Mail 0.8.2, when regi
23RISK
open ↗Referência
CVE-2013-6881
CRU Ditto Forensic FieldStation with firmware before 2013Oct15a allows remote attackers to execute arbitrary commands vi
28RISK
open ↗Referência
CVE-2013-6924
Seagate BlackArmor NAS devices with firmware sg2000-2000.1331 allow remote attackers to execute arbitrary commands via s
28RISK
open ↗Referência✓ VexDay Proof
OCS Inventory NG 1.02 - Remote File Disclosure
Absolute path traversal vulnerability in cvs.php in OCS Inventory NG before 1.02.1 on Unix allows remote attackers to re
23RISK
open ↗Referência
CVE-2021-3129
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open ↗Referência
CVE-2021-3129
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open ↗Referência
CVE-2015-1489
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticat
43RISK
open ↗Referência✓ VexDay Proof
vBulletin Radio and TV Player AddOn - HTML Injection
Cross-site scripting (XSS) vulnerability in forum/radioandtv.php in the Radio and TV Player addon for vBulletin allows r
23RISK
open ↗Referência✓ VexDay Proof
phpDatingClub 3.7 - SQL Injection / Cross-Site Scripting Injection
SQL injection vulnerability in search.php in phpDatingClub 3.7 allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗Referência
CVE-2013-7409
Buffer overflow in ALLPlayer 5.6.2 through 5.8.1 allows remote attackers to cause a denial of service (crash) and possib
50RISK
open ↗Referência
CVE-2013-7409
Buffer overflow in ALLPlayer 5.6.2 through 5.8.1 allows remote attackers to cause a denial of service (crash) and possib
50RISK
open ↗Referência
CVE-2013-7409
Buffer overflow in ALLPlayer 5.6.2 through 5.8.1 allows remote attackers to cause a denial of service (crash) and possib
50RISK
open ↗Referência
CVE-2020-10189
Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted d
100RISK
open ↗Referência
CVE-2026-2441
Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside
76RISK
open ↗Referência
CVE-2009-2363
Stack-based buffer overflow in KUDRSOFT AudioPLUS 2.00.215 allows remote attackers to execute arbitrary code via a .pls
23RISK
open ↗Referência
CVE-2009-2363
Stack-based buffer overflow in KUDRSOFT AudioPLUS 2.00.215 allows remote attackers to execute arbitrary code via a .pls
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.