Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,866cataloged exploits
35,812CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,573GitHub PoC 14,316VulnCheck XDB 8,722Nuclei 4,320Metasploit 3,477✓ verified onlyrecentpopularrisk
22,549 exploits
Referência
CVE-2023-39115
install/aiz-uploader/upload in Campcodes Online Matrimonial Website System Script 3.3 allows XSS via a crafted SVG docum
23RISK
open ↗Referência✓ VexDay Proof
Pre Real Estate Listings - Arbitrary File Upload
Multiple SQL injection vulnerabilities in login.php in Pre Projects Pre Real Estate Listings allow remote attackers to e
23RISK
open ↗Referência✓ VexDay Proof
Tribiq CMS 5.0.9a (Beta) - Insecure Cookie Handling
Tribiq CMS 5.0.9a beta allows remote attackers to bypass authentication and gain administrative access by setting the CO
23RISK
open ↗Referência✓ VexDay Proof
XOOPS Module Tutoriais - 'viewcat.php' SQL Injection
SQL injection vulnerability in viewcat.php in the Tutoriais module for Xoops allows remote attackers to execute arbitrar
23RISK
open ↗Referência✓ VexDay Proof
7Shop 1.1 - Arbitrary File Upload
Unrestricted file upload vulnerability in includes/imageupload.php in 7Shop 1.1 and earlier allows remote attackers to e
23RISK
open ↗Referência✓ VexDay Proof
SFS EZ Link Directory - 'cat_id' SQL Injection
SQL injection vulnerability in links.php in Scripts for Sites (SFS) EZ Link Directory allows remote attackers to execute
23RISK
open ↗Referência✓ VexDay Proof
Booking Centre 2.01 - 'HotelID' SQL Injection
SQL injection vulnerability in hotel_habitaciones.php in Venalsur Booking Centre Booking System for Hotels Group 2.01 al
23RISK
open ↗Referência✓ VexDay Proof
Booking Centre 2.01 - Authentication Bypass
Multiple SQL injection vulnerabilities in admin/checklogin.php in Venalsur Booking Centre Booking System for Hotels Grou
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component Ice Gallery 0.5b2 - 'catid' Blind SQL Injection
SQL injection vulnerability in the Ice Gallery (com_ice) component 0.5 beta 2 for Joomla! allows remote attackers to exe
23RISK
open ↗Referência
CVE-2012-1921
Cross-site request forgery (CSRF) vulnerability in goform/admin/formWlEncrypt in Sitecom WLM-2501 allows remote attacker
23RISK
open ↗Referência✓ VexDay Proof
CMS NetCat 3.0/3.12 - Blind SQL Injection
SQL injection vulnerability in modules/poll/index.php in AIST NetCat 3.0 and 3.12 allows remote attackers to execute arb
23RISK
open ↗Referência✓ VexDay Proof
Absolute News Feed 1.0 - Remote Insecure Cookie Handling
Xigla Software Absolute News Feed 1.0 and possibly 1.5 allows remote attackers to bypass authentication and gain adminis
23RISK
open ↗Referência✓ VexDay Proof
Absolute News Manager 5.1 - Insecure Cookie Handling
Xigla Software Absolute News Manager.NET 5.1 allows remote attackers to bypass authentication and gain administrative ac
23RISK
open ↗Referência✓ VexDay Proof
Absolute Podcast 1.0 - Remote Insecure Cookie Handling
Absolute Podcast .NET 1.0 allows remote attackers to bypass authentication and gain administrative access by setting a c
23RISK
open ↗Referência✓ VexDay Proof
Absolute Poll Manager XE 4.1 - Insecure Cookie Handling
Xigla Software Absolute Poll Manager XE 4.1 allows remote attackers to bypass authentication and gain administrative acc
23RISK
open ↗Referência✓ VexDay Proof
Absolute NewsLetter 6.1 - Insecure Cookie Handling
Xigla Software Absolute Newsletter 6.0 and 6.1 allows remote attackers to bypass authentication and gain administrative
23RISK
open ↗Referência✓ VexDay Proof
Absolute Content Rotator 6.0 - Insecure Cookie Handling
Absolute Content Rotator 6.0 allows remote attackers to bypass authentication and gain administrative access by setting
23RISK
open ↗Referência✓ VexDay Proof
Active Web Mail 4 - Blind SQL Injection
SQL injection vulnerability in Active Web Mail 4.0 allows remote attackers to execute arbitrary SQL commands via the Tab
23RISK
open ↗Referência✓ VexDay Proof
ASPSiteWare Automotive Dealer 1.0/2.0 - SQL Injection
Multiple SQL injection vulnerabilities in ASP SiteWare autoDealer 1 and 2 allow remote attackers to execute arbitrary SQ
23RISK
open ↗Referência
CVE-2018-1000115
Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vuln
60RISK
open ↗Referência
CVE-2018-1000115
Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vuln
60RISK
open ↗Referência
CVE-2012-2109
SQL injection vulnerability in wp-load.php in the BuddyPress plugin 1.5.x before 1.5.5 of WordPress allows remote attack
23RISK
open ↗Referência
CVE-2024-13161
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up
100RISK
open ↗Referência
CVE-2020-8193
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14
100RISK
open ↗Referência
CVE-2020-3243
Multiple Vulnerabilities in Cisco UCS Director and Cisco UCS Director Express for Big Data
85RISK
open ↗Referência✓ VexDay Proof
Joomla! Component mosmedia 1.0.8 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in the Avant-Garde Solutions MOSMedia (com_mosmedia) 1.08 and earlier
23RISK
open ↗Referência
CVE-2018-7251
An issue was discovered in config/error.php in Anchor 0.12.3. The error log is exposed at an errors.log URI, and contain
60RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.