Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,813cataloged exploits
35,788CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,549GitHub PoC 14,290VulnCheck XDB 8,722Nuclei 4,320Metasploit 3,477✓ verified onlyrecentpopularrisk
22,549 exploits
Referência
CVE-2015-2182
Multiple cross-site scripting (XSS) vulnerabilities in ZeusCart 4 allow remote attackers to inject arbitrary web script
23RISK
open ↗Referência✓ VexDay Proof
Apple Safari 3.2.2/4b - nested elements XML Parsing Remote Crash
Apple Safari 3.2.2 and 4 Beta on Windows allows remote attackers to cause a denial of service (application crash) via an
23RISK
open ↗Referência
CVE-2014-5464
Cross-site scripting (XSS) vulnerability in the nDPI traffic classification library in ntopng (aka ntop) before 1.2.1 al
23RISK
open ↗Referência
CVE-2019-12788
An issue was discovered in Photodex ProShow Producer v9.0.3797 (an application that runs with Administrator privileges).
23RISK
open ↗Referência
CVE-2014-2084
Skybox View Appliances with ISO 6.3.33-2.14, 6.3.31-2.14, 6.4.42-2.54, 6.4.45-2.56, and 6.4.46-2.57 does not properly re
23RISK
open ↗Referência
CVE-2018-20009
DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider.php SSL Provider Name or SSL Provider URL field.
38RISK
open ↗Referência✓ VexDay Proof
Sponge News 2.2 - 'sndir' Remote File Inclusion
PHP remote file inclusion vulnerability in news.php in Sponge News 2.2 and earlier allows remote attackers to execute ar
23RISK
open ↗Referência✓ VexDay Proof
5 star review - Cross-Site Scripting / SQL Injection
Cross-site scripting (XSS) vulnerability in search/index.php in Five Star Review Script allows remote attackers to injec
23RISK
open ↗Referência✓ VexDay Proof
5 star review - Cross-Site Scripting / SQL Injection
SQL injection vulnerability in recommend.php in Five Star Review Script allows remote attackers to execute arbitrary SQL
23RISK
open ↗Referência
CVE-2015-9222
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MSM8909W,
23RISK
open ↗Referência
CVE-2012-4988
Heap-based buffer overflow in the xjpegls.dll (aka JLS, JPEG-LS, or JPEG lossless) format plugin in XnView 1.99 and 1.99
23RISK
open ↗Referência
CVE-2014-3139
recoveryconsole/bpl/snmpd.php in Unitrends Enterprise Backup 7.3.0 allows remote attackers to bypass authentication by s
23RISK
open ↗Referência
CVE-2018-19782
Multiple cross-site scripting (XSS) vulnerabilities in GET requests in FreshRSS 1.11.1 allow remote attackers to inject
23RISK
open ↗Referência
CVE-2018-19782
Multiple cross-site scripting (XSS) vulnerabilities in GET requests in FreshRSS 1.11.1 allow remote attackers to inject
23RISK
open ↗Referência
CVE-2020-10385
A stored cross-site scripting (XSS) vulnerability exists in the WPForms Contact Form (aka wpforms-lite) plugin before 1.
23RISK
open ↗Referência
CVE-2022-4328
WooCommerce Checkout Field Manager < 18.0 - Unauthenticated Arbitrary File Upload
63RISK
open ↗Referência
CVE-2009-4867
Buffer overflow in Tuniac 090517c allows remote attackers to cause a denial of service (application crash) or possibly e
23RISK
open ↗Referência
CVE-2017-13875
An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "Intel Graph
23RISK
open ↗Referência✓ VexDay Proof
K&S Shopsysteme - Arbitrary File Upload
Unrestricted file upload vulnerability in admin/editor/images.php in K&S Shopsoftware allows remote attackers to execute
23RISK
open ↗Referência✓ VexDay Proof
Ext 1.0 - 'feed-proxy.php?feed' Remote File Disclosure
Directory traversal vulnerability in examples/layout/feed-proxy.php in Jack Slocum Ext 1.0 alpha1 (Ext JS) allows remote
28RISK
open ↗Referência
CVE-2019-9593
A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 18.82.2000.0 allows remote attackers to
23RISK
open ↗Referência
CVE-2011-5129
Heap-based buffer overflow in XChat 2.8.9 and earlier allows remote attackers to cause a denial of service (crash) and p
23RISK
open ↗Referência✓ VexDay Proof
SyndeoCMS 2.5.01 - 'cmsdir' Remote File Inclusion
PHP remote file inclusion vulnerability in starnet/themes/c-sky/main.inc.php in Fred Stuurman SyndeoCMS 2.5.01 allows re
23RISK
open ↗Referência
CVE-2011-5135
Multiple SQL injection vulnerabilities in the save_connection function in lib/lib.iotask.php in the iotask module in Doc
23RISK
open ↗Referência
CVE-2008-3942
SQL injection vulnerability in landsee.php in Full PHP Emlak Script allows remote attackers to execute arbitrary SQL com
23RISK
open ↗Referência
CVE-2017-2533
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "DiskArbitra
23RISK
open ↗Referência
CVE-2021-28418
A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via settings.php and
23RISK
open ↗Referência
CVE-2018-10257
A CSV Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privile
23RISK
open ↗Referência
CVE-2018-10257
A CSV Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privile
23RISK
open ↗Referência
CVE-2021-28419
The "order_col" parameter in archive.php of SEO Panel 4.8.0 is vulnerable to time-based blind SQL injection, which leads
28RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.