Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,056cataloged exploits
35,925CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,640GitHub PoC 14,392VulnCheck XDB 8,755Nuclei 4,333Metasploit 3,478✓ verified onlyrecentpopularrisk
22,640 exploits
Referência
CVE-2018-25080
MobileDetect Example session_example.php initLayoutType cross site scripting
28RISK
open ↗Referência
CVE-2015-2996
Multiple directory traversal vulnerabilities in SysAid Help Desk before 15.2 allow remote attackers to (1) read arbitrar
60RISK
open ↗Referência
CVE-2016-4117
Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as
100RISK
open ↗Referência
CVE-2026-73678
MindsDB Minds Platform v26.1.0 Unauthenticated RCE via scratchpad exec()
48RISK
open ↗Referência✓ VexDay Proof
empris r20020923 - 'phormationdir' Remote File Inclusion
PHP remote file inclusion vulnerability in sql_fcnsOLD.php in Emergenices Personnel Information System (Empris) 20020923
23RISK
open ↗Referência✓ VexDay Proof
registroTL - 'main.php' Remote File Inclusion
registroTL stores sensitive information under the web root with insufficient access control, which allows remote attacke
23RISK
open ↗Referência✓ VexDay Proof
DodosMail 2.0.1 - 'dodosmail.php' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in dodosmail.php in DodosMail 2.0.1 and earlier, and possibly 2.1, al
23RISK
open ↗Referência✓ VexDay Proof
Blog PixelMotion - 'sauvBase.php' Arbitrary Database Backup
admin/sauvBase.php in Blog Pixel Motion (aka Blog PixelMotion) does not require authentication, which allows remote atta
23RISK
open ↗Referência
CVE-2026-72741
Rainbond 6.9.7 Region API Cross-Enterprise IDOR via Tenant Access
41RISK
open ↗Referência✓ VexDay Proof
realm CMS 2.3 - Multiple Vulnerabilities
Realm CMS 2.3 and earlier allows remote attackers to obtain sensitive information via a direct request to _db/compact.as
23RISK
open ↗Referência✓ VexDay Proof
SimpleBlog 2.0 - 'comments.asp' SQL Injection (1)
SQL injection vulnerability in comments.asp in SimpleBlog 2.0 and earlier allows remote attackers to execute arbitrary S
23RISK
open ↗Referência
CVE-2026-19710
SourceCodester Simple Student Information System view_department.php sql injection
33RISK
open ↗Referência
CVE-2009-4675
admin/admin_info/index.php in the Mole Group Gastro Portal (Restaurant Directory) Script does not require administrative
23RISK
open ↗Referência
CVE-2026-18048
WP Photo Album Plus < 9.2.07.002 - Unauthenticated Arbitrary ZIP File Deletion via delmyzip Path Traversal
41RISK
open ↗Referência✓ VexDay Proof
Thickbox Gallery 2.0 - 'Admins.php' Admin Data Disclosure
Davlin Thickbox Gallery 2 allows remote attackers to obtain the administrative username and MD5 password hash via a dire
23RISK
open ↗Referência
CVE-2011-0886
Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface on the SMC SMCD3G-CCR (aka Comcast Busin
23RISK
open ↗Referência✓ VexDay Proof
nightfall personal diary 1.0 - Cross-Site Scripting / File Disclosure
Nightfall Personal Diary 1.0 stores sensitive information under the web root with insufficient access control, which all
23RISK
open ↗Referência✓ VexDay Proof
Frimousse 0.0.2 - 'explorerdir.php' Local Directory Traversal
Absolute path traversal vulnerability in explorerdir.php in Frimousse 0.0.2 allows remote attackers to read arbitrary fi
23RISK
open ↗Referência
CVE-2015-3036
Stack-based buffer overflow in the run_init_sbus function in the KCodes NetUSB module for the Linux kernel, as used in c
28RISK
open ↗Referência
CVE-2015-3036
Stack-based buffer overflow in the run_init_sbus function in the KCodes NetUSB module for the Linux kernel, as used in c
28RISK
open ↗Referência✓ VexDay Proof
Barman 0.0.1r3 - 'Interface.php' Remote File Inclusion
PHP remote file inclusion vulnerability in interface.php in Barman 0.0.1r3 allows remote attackers to execute arbitrary
23RISK
open ↗Referência✓ VexDay Proof
Simple Text-File Login script (SiTeFiLo) 1.0.6 - File Disclosure / Remote File Inclusion
Simple Text-File Login Script (SiTeFiLo) 1.0.6 stores sensitive information under the web root with insufficient access
23RISK
open ↗Referência✓ VexDay Proof
PHP Site Lock 2.0 - Insecure Cookie Handling
index.php in PHP Site Lock 2.0 allows remote attackers to bypass authentication and obtain administrative access by sett
23RISK
open ↗Referência✓ VexDay Proof
DM FileManager 3.9.2 - Insecure Cookie Handling
admin/login.php in DM FileManager 3.9.2 allows remote attackers to bypass authentication and gain administrative access
23RISK
open ↗Referência
CVE-2012-6555
Cross-site scripting (XSS) vulnerability in the LatestComment plugin 1.1 for Vanilla Forums allows remote attackers to i
23RISK
open ↗Referência
CVE-2025-44868
Wavlink WL-WN530H4 20220801 was found to contain a command injection vulnerability in the ping_test function of the adm.
48RISK
open ↗Referência
CVE-2010-1055
Multiple PHP remote file inclusion vulnerabilities in osDate 2.1.9 and 2.5.4, when magic_quotes_gpc is disabled and regi
23RISK
open ↗Referência
CVE-2018-16736
In the rcfilters plugin 2.1.6 for Roundcube, XSS exists via the _whatfilter and _messages parameters (in the Filters sec
23RISK
open ↗Referência
CVE-2022-35155
Bus Pass Management System v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the s
33RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.