Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,813cataloged exploits
35,788CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,549GitHub PoC 14,290VulnCheck XDB 8,722Nuclei 4,320Metasploit 3,477✓ verified onlyrecentpopularrisk
22,549 exploits
Referência✓ VexDay Proof
RSSonate - 'xml2rss.php' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Christopher Fowler (Rhode Island) RSSonate allow remote attackers
23RISK
open ↗Referência
CVE-2011-0885
A certain Comcast Business Gateway configuration of the SMC SMCD3G-CCR with firmware before 1.4.0.49.2 has a default pas
28RISK
open ↗Referência
CVE-2015-4665
Cross-site scripting (XSS) vulnerability in ajax_cmd.php in Xceedium Xsuite 2.4.4.1 and earlier allows remote attackers
23RISK
open ↗Referência
CVE-2015-4665
Cross-site scripting (XSS) vulnerability in ajax_cmd.php in Xceedium Xsuite 2.4.4.1 and earlier allows remote attackers
23RISK
open ↗Referência
CVE-2018-5359
The server in Flexense SysGauge 3.6.18 operating on port 9221 can be exploited remotely with the attacker gaining system
23RISK
open ↗Referência
CVE-2018-5359
The server in Flexense SysGauge 3.6.18 operating on port 9221 can be exploited remotely with the attacker gaining system
23RISK
open ↗Referência
CVE-2009-2564
NOS Microsystems getPlus Download Manager, as used in Adobe Reader 1.6.2.36 and possibly other versions, Corel getPlus D
23RISK
open ↗Referência✓ VexDay Proof
Firefly Media Server 0.2.4 - Remote Denial of Service
webserver.c in mt-dappd in Firefly Media Server 0.2.4 and earlier allows remote attackers to cause a denial of service (
23RISK
open ↗Referência
CVE-2013-4091
The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 does not have an off autocom
23RISK
open ↗Referência
CVE-2007-4734
Buffer overflow in Ots Labs OTSTurntables 1.00 allows user-assisted remote attackers to execute arbitrary code via a lon
23RISK
open ↗Referência✓ VexDay Proof
MW6 Barcode - ActiveX 'Barcode.dll' Remote Heap Overflow (PoC)
Heap-based buffer overflow in MW6 Technologies Barcode ActiveX control (Barcode.MW6Barcode.1, Barcode.dll) 3.0.0.1 allow
23RISK
open ↗Referência
CVE-2025-15500
Sangfor Operation and Maintenance Management System HTTP POST Request getHis os command injection
48RISK
open ↗Referência
CVE-2017-13056
The launchURL function in PDF-XChange Viewer 2.5 (Build 314.0) might allow remote attackers to execute arbitrary code vi
23RISK
open ↗Referência
CVE-2009-4836
Eval injection vulnerability in system/services/init.php in Movie PHP Script 2.0 allows remote attackers to execute arbi
23RISK
open ↗Referência
CVE-2017-0167
An information disclosure vulnerability exists in Windows 8.1, Windows RT 8.1, Windows Server 2012 R2, Windows 10, and W
23RISK
open ↗Referência
CVE-2009-4668
Stack-based buffer overflow in JetCast.exe 2.0.4.1109 in jetAudio 7.5.2 and 7.5.3.15 allows remote attackers to execute
23RISK
open ↗Referência
CVE-2009-2896
Buffer overflow in KMplayer 2.9.4.1433 and earlier allows remote attackers to cause a denial of service (application cra
23RISK
open ↗Referência
CVE-2010-2440
Stack-based buffer overflow in st-wizard.exe in Subtitle Translation Wizard 3.0 allows user-assisted remote attackers to
23RISK
open ↗Referência
CVE-2010-2331
Stack-based buffer overflow in iSharer File Sharing Wizard 1.5.0 allows remote attackers to execute arbitrary code via a
23RISK
open ↗Referência
CVE-2010-1049
Multiple SQL injection vulnerabilities in Uiga Business Portal allow remote attackers to execute arbitrary SQL commands
23RISK
open ↗Referência
CVE-2010-1050
SQL injection vulnerability in index.php in AudiStat 1.3 allows remote attackers to execute arbitrary SQL commands via t
23RISK
open ↗Referência
CVE-2014-0866
RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics sends cleartext c
23RISK
open ↗Referência
CVE-2017-18016
Parity Browser 1.6.10 and earlier allows remote attackers to bypass the Same Origin Policy and obtain sensitive informat
23RISK
open ↗Referência
CVE-2015-8285
The webssx.sys driver in QuickHeal 16.00 allows remote attackers to cause a denial of service.
23RISK
open ↗Referência
CVE-2014-8391
The Web interface in Sendio before 7.2.4 does not properly handle sessions, which allows remote authenticated users to o
23RISK
open ↗Referência
CVE-2014-8391
The Web interface in Sendio before 7.2.4 does not properly handle sessions, which allows remote authenticated users to o
23RISK
open ↗Referência
CVE-2010-5280
Directory traversal vulnerability in the Community Builder Enhanced (CBE) (com_cbe) component 1.4.8, 1.4.9, and 1.4.10 f
23RISK
open ↗Referência
CVE-2010-5280
Directory traversal vulnerability in the Community Builder Enhanced (CBE) (com_cbe) component 1.4.8, 1.4.9, and 1.4.10 f
23RISK
open ↗Referência
CVE-2016-1743
The Intel driver in the Graphics Drivers subsystem in Apple OS X before 10.11.4 allows attackers to execute arbitrary co
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.