Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,900cataloged exploits
35,840CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,600GitHub PoC 14,323VulnCheck XDB 8,722Nuclei 4,320Metasploit 3,477✓ verified onlyrecentpopularrisk
22,573 exploits
Referência
CVE-2013-4884
Cross-site scripting (XSS) vulnerability in McAfee SuperScan 4.0 allows remote attackers to inject arbitrary web script
23RISK
open ↗Referência
CVE-2010-1877
SQL injection vulnerability in the JTM Reseller (com_jtm) component 1.9 Beta for Joomla! allows remote attackers to exec
23RISK
open ↗Referência
CVE-2015-1058
Multiple cross-site scripting (XSS) vulnerabilities in AdaptCMS 3.0.3 allow remote attackers to inject arbitrary web scr
23RISK
open ↗Referência
CVE-2014-0868
RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics relies on client-
23RISK
open ↗Referência
CVE-2010-4232
The web-based administration interface on the Camtron CMNC-200 Full HD IP Camera and TecVoz CMNC-200 Megapixel IP Camera
23RISK
open ↗Referência
CVE-2014-3740
Cross-site scripting (XSS) vulnerability in SpiceWorks before 7.2.00195 allows remote authenticated users to inject arbi
23RISK
open ↗Referência
CVE-2017-2490
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS b
23RISK
open ↗Referência
CVE-2015-5150
Multiple cross-site scripting (XSS) vulnerabilities in Zoho ManageEngine SupportCenter Plus 7.90 allow remote authentica
23RISK
open ↗Referência
CVE-2015-5150
Multiple cross-site scripting (XSS) vulnerabilities in Zoho ManageEngine SupportCenter Plus 7.90 allow remote authentica
23RISK
open ↗Referência
CVE-2022-35866
This vulnerability allows remote attackers to bypass authentication on affected installations of Vinchin Backup and Reco
48RISK
open ↗Referência
CVE-2017-17602
Advance B2B Script 2.1.3 has SQL Injection via the tradeshow-list-detail.php show_id or view-product.php pid parameter.
23RISK
open ↗Referência
CVE-2017-17602
Advance B2B Script 2.1.3 has SQL Injection via the tradeshow-list-detail.php show_id or view-product.php pid parameter.
23RISK
open ↗Referência✓ VexDay Proof
ftp Admin 0.1.0 - Local File Inclusion / Cross-Site Scripting / Authentication Bypass
index.php in FTP Admin 0.1.0 allows remote attackers to bypass authentication and obtain administrative access via a log
23RISK
open ↗Referência✓ VexDay Proof
pPIM 1.0 - Upload/Change Password
Unrestricted file upload vulnerability in upload.php in Phlatline's Personal Information Manager (pPIM) 1.0 and earlier
23RISK
open ↗Referência✓ VexDay Proof
SineCMS 2.3.4 - Calendar SQL Injection
Multiple cross-site scripting (XSS) vulnerabilities in the guestbook in SineCMS 2.3.4 and earlier allow remote attackers
23RISK
open ↗Referência✓ VexDay Proof
WordPress Plugin Photo album - SQL Injection
Multiple SQL injection vulnerabilities in wppa.php in the WP Photo Album (WPPA) before 1.1 plugin for WordPress allow re
23RISK
open ↗Referência
CVE-2010-3212
SQL injection vulnerability in index.php in Seagull 0.6.7 and earlier allows remote attackers to execute arbitrary SQL c
23RISK
open ↗Referência
CVE-2026-9577
Post Status Notifier Lite < 1.13.0 - Reflected XSS via mod Parameter
33RISK
open ↗Referência
CVE-2026-16334
itsourcecode Hospital Management System prescriptionorder.php sql injection
33RISK
open ↗Referência
CVE-2026-13156
MailerSend - Official SMTP Integration < 1.0.8 - Settings Deletion and Plugin Deactivation via CSRF
33RISK
open ↗Referência
CVE-2026-12972
PayPlus Payment Gateway < 8.2.2 - Unauthenticated Order Payment Metadata Tampering
33RISK
open ↗Referência
CVE-2026-12898
All-in-One WP Migration and Backup < 7.106 - Unauthenticated Arbitrary-Location Log File Write via Path Traversal
33RISK
open ↗Referência
CVE-2008-4141
Multiple PHP remote file inclusion vulnerabilities in x10Media x10 Automatic MP3 Script 1.5.5 allow remote attackers to
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.