Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,866cataloged exploits
35,812CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,573GitHub PoC 14,316VulnCheck XDB 8,722Nuclei 4,320Metasploit 3,477✓ verified onlyrecentpopularrisk
22,549 exploits
Referência
CVE-2015-2291
(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows all
71RISK
open ↗Referência
CVE-2018-7538
A SQL injection vulnerability in the tracker functionality of Enalean Tuleap software engineering platform before 9.18 a
23RISK
open ↗Referência
CVE-2016-9351
An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. The directory traversal/file upload error
23RISK
open ↗Referência
CVE-2009-4097
Stack-based buffer overflow in the MplayInputFile function in Serenity Audio Player 3.2.3 and earlier allows remote atta
23RISK
open ↗Referência✓ VexDay Proof
NVR SP2 2.0 'nvUnifiedControl.dll 1.1.45.0' - 'SetText()' Command Execution
Buffer overflow in the nvUnifiedControl.AUnifiedControl.1 ActiveX control in nvUnifiedControl.dll 1.1.45.0 in ACTi Netwo
23RISK
open ↗Referência
CVE-2014-3120
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execut
100RISK
open ↗Referência✓ VexDay Proof
Ipswitch WS_FTP Home/Professional FTP Client - Remote Format String (PoC)
Format string vulnerability in Ipswitch WS_FTP Home 2007.0.0.2 and WS_FTP Professional 2007.1.0.0 allows remote FTP serv
28RISK
open ↗Referência
CVE-2020-7934
In LifeRay Portal CE 7.1.0 through 7.2.1 GA2, the First Name, Middle Name, and Last Name fields for user accounts in MyA
23RISK
open ↗Referência
CVE-2010-1538
SQL injection vulnerability in print_raincheck.php in phpRAINCHECK 1.0.1 and earlier allows remote attackers to execute
23RISK
open ↗Referência
CVE-2015-2182
Multiple cross-site scripting (XSS) vulnerabilities in ZeusCart 4 allow remote attackers to inject arbitrary web script
23RISK
open ↗Referência
CVE-2015-2182
Multiple cross-site scripting (XSS) vulnerabilities in ZeusCart 4 allow remote attackers to inject arbitrary web script
23RISK
open ↗Referência✓ VexDay Proof
Apple Safari 3.2.2/4b - nested elements XML Parsing Remote Crash
Apple Safari 3.2.2 and 4 Beta on Windows allows remote attackers to cause a denial of service (application crash) via an
23RISK
open ↗Referência
CVE-2014-5464
Cross-site scripting (XSS) vulnerability in the nDPI traffic classification library in ntopng (aka ntop) before 1.2.1 al
23RISK
open ↗Referência
CVE-2019-12788
An issue was discovered in Photodex ProShow Producer v9.0.3797 (an application that runs with Administrator privileges).
23RISK
open ↗Referência
CVE-2014-2084
Skybox View Appliances with ISO 6.3.33-2.14, 6.3.31-2.14, 6.4.42-2.54, 6.4.45-2.56, and 6.4.46-2.57 does not properly re
23RISK
open ↗Referência
CVE-2018-20009
DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider.php SSL Provider Name or SSL Provider URL field.
38RISK
open ↗Referência✓ VexDay Proof
Sponge News 2.2 - 'sndir' Remote File Inclusion
PHP remote file inclusion vulnerability in news.php in Sponge News 2.2 and earlier allows remote attackers to execute ar
23RISK
open ↗Referência✓ VexDay Proof
5 star review - Cross-Site Scripting / SQL Injection
Cross-site scripting (XSS) vulnerability in search/index.php in Five Star Review Script allows remote attackers to injec
23RISK
open ↗Referência✓ VexDay Proof
5 star review - Cross-Site Scripting / SQL Injection
SQL injection vulnerability in recommend.php in Five Star Review Script allows remote attackers to execute arbitrary SQL
23RISK
open ↗Referência
CVE-2017-2533
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "DiskArbitra
23RISK
open ↗Referência
CVE-2021-28418
A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via settings.php and
23RISK
open ↗Referência
CVE-2018-10257
A CSV Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privile
23RISK
open ↗Referência
CVE-2018-10257
A CSV Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privile
23RISK
open ↗Referência
CVE-2021-28419
The "order_col" parameter in archive.php of SEO Panel 4.8.0 is vulnerable to time-based blind SQL injection, which leads
28RISK
open ↗Referência
CVE-2018-14327
The installer for the Alcatel OSPREY3_MINI Modem component on EE EE40VB 4G mobile broadband modems with firmware before
23RISK
open ↗Referência
CVE-2018-14327
The installer for the Alcatel OSPREY3_MINI Modem component on EE EE40VB 4G mobile broadband modems with firmware before
23RISK
open ↗Referência✓ VexDay Proof
Trawler Web CMS 1.8.1 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Trawler Web CMS 1.8.1 and earlier allow remote attackers to execut
23RISK
open ↗Referência
CVE-2023-23163
Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the editid parame
23RISK
open ↗Referência✓ VexDay Proof
ID Automation Linear Barcode - ActiveX Denial of Service
Unspecified vulnerability in the ID Automation Linear Barcode 1.6.0.5 ActiveX control in IDAutomationLinear6.dll allows
23RISK
open ↗Referência✓ VexDay Proof
Spice Classifieds - 'cat_path' SQL Injection
SQL injection vulnerability in index.php in Spice Classifieds allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.