Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,056cataloged exploits
35,925CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,640GitHub PoC 14,392VulnCheck XDB 8,755Nuclei 4,333Metasploit 3,478✓ verified onlyrecentpopularrisk
22,640 exploits
Referência
CVE-2014-10031
Buffer overflow in the IMAPd service in Qualcomm Eudora WorldMail 9.0.333.0 allows remote attackers to execute arbitrary
23RISK
open ↗Referência
CVE-2017-14960
xDashboard in OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 has SQL I
23RISK
open ↗Referência✓ VexDay Proof
PHP Jokesite 2.0 - 'cat_id' SQL Injection
SQL injection vulnerability in jokes_category.php in PHP-Jokesite 2.0 allows remote attackers to execute arbitrary SQL c
23RISK
open ↗Referência
CVE-2010-1299
Multiple PHP remote file inclusion vulnerabilities in DynPG CMS 4.1.0, and possibly earlier, when magic_quotes_gpc is di
28RISK
open ↗Referência
CVE-2009-4578
Cross-site scripting (XSS) vulnerability in the Facileforms (com_facileforms) component for Joomla! and Mambo allows rem
23RISK
open ↗Referência
CVE-2014-3738
Cross-site scripting (XSS) vulnerability in Zenoss 4.2.5 allows remote attackers to inject arbitrary web script or HTML
23RISK
open ↗Referência
CVE-2014-9610
Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication an
23RISK
open ↗Referência
CVE-2014-9610
Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication an
23RISK
open ↗Referência✓ VexDay Proof
Samsung DVR SHR2040 - HTTPd Remote Denial of Service Denial of Service (PoC)
The web interface in Samsung DVR SHR2040 allows remote attackers to cause a denial of service (crash) via a malformed HT
23RISK
open ↗Referência✓ VexDay Proof
Google Chrome - 'ChromeHTML://' Remote Parameter Injection
Argument injection vulnerability in Google Chrome 1.0.154.36 on Windows XP SP3 allows remote attackers to execute arbitr
23RISK
open ↗Referência
CVE-2015-1578
Multiple open redirect vulnerabilities in u5CMS before 3.9.4 allow remote attackers to redirect users to arbitrary web s
23RISK
open ↗Referência✓ VexDay Proof
acFTP FTP Server 1.4 - 'USER' Remote Buffer Overflow (PoC)
acFTP 1.4 allows remote attackers to cause a denial of service (application crash) via a long string with "{" (brace) ch
23RISK
open ↗Referência✓ VexDay Proof
SimpCMS 04.10.2007 - 'site' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in SimpCMS Light 04.10.2007 and earlier allows remote attackers to
23RISK
open ↗Referência✓ VexDay Proof
Siemens C450IP/C475IP - Remote Denial of Service
Siemens C450 IP and C475 IP VoIP devices allow remote attackers to cause a denial of service (disconnected calls and dev
23RISK
open ↗Referência✓ VexDay Proof
maGAZIn 2.0 - 'PHPThumb.php?src' Remote File Disclosure
Directory traversal vulnerability in phpThumb.php in PinkCrow Designs Gallery or maGAZIn 2.0 allows remote attackers to
23RISK
open ↗Referência✓ VexDay Proof
SunLight CMS 5.3 - 'root' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in SunLight CMS 5.3 allow remote attackers to execute arbitrary PHP c
23RISK
open ↗Referência✓ VexDay Proof
Bitweaver R2 CMS - Arbitrary File Upload / Disclosure
Directory traversal vulnerability in wiki/edit.php in Bitweaver R2 CMS allows remote attackers to obtain sensitive infor
23RISK
open ↗Referência
CVE-2010-5239
Untrusted search path vulnerability in DAEMON Tools Lite 4.35.6.0091 and Pro Standard 4.36.0309.0160 allows local users
23RISK
open ↗Referência
CVE-2011-0049
Directory traversal vulnerability in the _list_file_get function in lib/Majordomo.pm in Majordomo 2 before 20110131 allo
60RISK
open ↗Referência
CVE-2017-15974
tPanel 2009 allows SQL injection for Authentication Bypass via 'or 1=1 or ''=' to login.php.
23RISK
open ↗Referência
CVE-2017-15974
tPanel 2009 allows SQL injection for Authentication Bypass via 'or 1=1 or ''=' to login.php.
23RISK
open ↗Referência
CVE-2019-17624
"" In X.Org X Server 1.20.4, there is a stack-based buffer overflow in the function XQueryKeymap. For example, by sendin
23RISK
open ↗Referência
CVE-2018-0968
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RISK
open ↗Referência
Authenticated low-privileged RCE in Coolify via unsanitized shell commands in the Git Repository field.
Coolify Git Repository Field Command Injection in Project Deployment Workflow
48RISK
open ↗Referência
CVE-2022-39285
Stored Cross-Site Scripting Vulnerability In File Parameter in zoneminder
41RISK
open ↗Referência
CVE-2015-1028
Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2730B router (rev C1) with firmware GE_1.01 allow remo
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.