Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,900cataloged exploits
35,840CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,600GitHub PoC 14,323VulnCheck XDB 8,722Nuclei 4,320Metasploit 3,477✓ verified onlyrecentpopularrisk
22,573 exploits
Referência
CVE-2011-1092
Integer overflow in ext/shmop/shmop.c in PHP before 5.3.6 allows context-dependent attackers to cause a denial of servic
28RISK
open ↗Referência
CVE-2014-7200
Cross-site scripting (XSS) vulnerability in pi1/class.tx_dmmjobcontrol_pi1.php in the JobControl (dmmjobcontrol) extensi
23RISK
open ↗Referência
CVE-2014-9258
SQL injection vulnerability in ajax/getDropdownValue.php in GLPI before 0.85.1 allows remote authenticated users to exec
23RISK
open ↗Referência
CVE-2023-46805
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a re
100RISK
open ↗Referência
CVE-2023-22527
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RISK
open ↗Referência✓ VexDay Proof
Zervit Web Server 0.02 - Remote Buffer Overflow (PoC)
Buffer overflow in the http_parse_hex function in libz/misc.c in Zervit Webserver 0.02 allows remote attackers to cause
23RISK
open ↗Referência✓ VexDay Proof
Elecard AVC HD Player - '.XPL' Stack Buffer Overflow (SEH) (PoC)
Stack-based buffer overflow in Elecard AVC HD Player allows remote attackers to execute arbitrary code via a long MP3 fi
23RISK
open ↗Referência
CVE-2011-3496
service.exe in Measuresoft ScadaPro 4.0.0 and earlier allows remote attackers to execute arbitrary commands via shell me
28RISK
open ↗Referência
CVE-2011-3833
Unrestricted file upload vulnerability in ftp_upload_file.php in Support Incident Tracker (aka SiT!) 3.65 allows remote
43RISK
open ↗Referência
CVE-2021-42013
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open ↗Referência
CVE-2021-42013
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open ↗Referência
CVE-2021-42013
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open ↗Referência
CVE-2026-9575
itsourcecode Student Transcript Processing System index.php sql injection
33RISK
open ↗Referência
CVE-2026-9574
itsourcecode Student Transcript Processing System trans.php sql injection
33RISK
open ↗Referência
CVE-2026-9573
itsourcecode Student Transcript Processing System index.php sql injection
33RISK
open ↗Referência
CVE-2026-7293
SourceCodester Pizzafy Ecommerce System ajax.php delete_category sql injection
33RISK
open ↗Referência
CVE-2015-0936
Ceragon FibeAir IP-10 have a default SSH public key in the authorized_keys file for the mateidu user, which allows remot
60RISK
open ↗Referência
CVE-2009-4751
SQL injection vulnerability in anzeiger/start.php in Swinger Club Portal allows remote attackers to execute arbitrary SQ
23RISK
open ↗Referência
CVE-2009-4752
PHP remote file inclusion vulnerability in anzeiger/start.php in Swinger Club Portal allows remote attackers to execute
23RISK
open ↗Referência
CVE-2013-4864
MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to send HTTP requests to intranet servers via the url
23RISK
open ↗Referência
CVE-2013-4864
MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to send HTTP requests to intranet servers via the url
23RISK
open ↗Referência
CVE-2013-4865
Cross-site request forgery (CSRF) vulnerability in upgrade_step2.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows
23RISK
open ↗Referência
CVE-2013-5045
Microsoft Internet Explorer 10 and 11 allows local users to bypass the Protected Mode protection mechanism, and conseque
43RISK
open ↗Referência✓ VexDay Proof
BaoFeng - ActiveX 'OnBeforeVideoDownload()' Remote Buffer Overflow
Stack-based buffer overflow in the MPS.StormPlayer.1 ActiveX control in mps.dll 3.9.4.27 in Baofeng Storm allows remote
50RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.