Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,056cataloged exploits
35,925CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,640GitHub PoC 14,392VulnCheck XDB 8,755Nuclei 4,333Metasploit 3,478✓ verified onlyrecentpopularrisk
22,640 exploits
Referência
CVE-2021-21465
The BW Database Interface allows an attacker with low privileges to execute any crafted database queries, exposing the b
48RISK
open ↗Referência
CVE-2018-14840
uploads/.htaccess in Subrion CMS 4.2.1 allows XSS because it does not block .html file uploads (but does block, for exam
23RISK
open ↗Referência✓ VexDay Proof
@lex Guestbook 4.0.2 - Remote Command Execution
SQL injection vulnerability in index.php in @lex Guestbook 4.0.2 and earlier, when magic_quotes_gpc is disabled, allows
23RISK
open ↗Referência✓ VexDay Proof
Acidcat CMS 3.4.1 - Multiple Vulnerabilities
Acidcat CMS 3.4.1 does not restrict access to the FCKEditor component, which allows remote attackers to upload arbitrary
23RISK
open ↗Referência✓ VexDay Proof
JBlog 1.0 - Create / Delete Admin Authentication Bypass
admin/ajoutaut.php in JBlog 1.0 does not require authentication, which allows remote attackers to create arbitrary accou
23RISK
open ↗Referência✓ VexDay Proof
EDraw Flowchart ActiveX Control 2.0 - Insecure Method
Absolute path traversal vulnerability in the EDraw Flowchart ActiveX control in EDImage.ocx 2.0.2005.1104 allows remote
23RISK
open ↗Referência✓ VexDay Proof
Google Chrome 0.2.149.27 - Inspect Element Denial of Service
Google Chrome 0.2.149.27 allows user-assisted remote attackers to cause a denial of service (browser crash) via an IMG t
23RISK
open ↗Referência✓ VexDay Proof
bloofox 0.3 - SQL Injection / File Disclosure
Directory traversal vulnerability in file.php in bloofoxCMS 0.3 allows remote attackers to read arbitrary files via a ..
23RISK
open ↗Referência
CVE-2015-5520
Cross-site scripting (XSS) vulnerability in the Users module in Orchard 1.7.3 through 1.8.2 and 1.9.x before 1.9.1 allow
23RISK
open ↗Referência
CVE-2009-4563
Cross-site request forgery (CSRF) vulnerability in zp-core/admin-options.php in Zenphoto 1.2.5 allows remote attackers t
23RISK
open ↗Referência
CVE-2026-10172
Bdtask Multi-Store Inventory Management System Component Module.php upload unrestricted upload
33RISK
open ↗Referência
CVE-2017-6979
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS
23RISK
open ↗Referência
CVE-2026-10157
Open5GS NGAP PathSwitchRequest Message ngap-handler.c improper authentication
33RISK
open ↗Referência
CVE-2009-4729
Multiple cross-site scripting (XSS) vulnerabilities in x10 Adult Media Script 1.7 allow remote attackers to inject arbit
23RISK
open ↗Referência
CVE-2017-11176
The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon entry into the retr
23RISK
open ↗Referência
CVE-2016-4315
Cross-site request forgery (CSRF) vulnerability in WSO2 Carbon 4.4.5 allows remote attackers to hijack the authenticatio
23RISK
open ↗Referência
CVE-2008-6888
Cross-site scripting (XSS) vulnerability in signup.asp in Pre Classified Listings 1.0 allows remote attackers to inject
23RISK
open ↗Referência
CVE-2016-1000123
Unauthenticated SQL Injection in Huge-IT Video Gallery v1.0.9 for Joomla
23RISK
open ↗Referência
CVE-2010-1312
Directory traversal vulnerability in the iJoomla News Portal (com_news_portal) component 1.5.x for Joomla! allows remote
43RISK
open ↗Referência
CVE-2010-1313
Directory traversal vulnerability in the Seber Cart (com_sebercart) component 1.0.0.12 and 1.0.0.13 for Joomla!, when ma
38RISK
open ↗Referência✓ VexDay Proof
LunarPoll 1.0 - 'show.php?PollDir' Remote File Inclusion
PHP remote file inclusion vulnerability in show.php in LunarPoll, when register_globals is enabled, allows remote attack
23RISK
open ↗Referência✓ VexDay Proof
Sciurus Hosting Panel - Remote Code Injection
Direct static code injection vulnerability in acp/savenews.php in Sciurus Hosting Panel, possibly 2.0.3, allows remote a
23RISK
open ↗Referência✓ VexDay Proof
Gradman 0.1.3 - 'agregar_info.php' Local File Inclusion
Directory traversal vulnerability in agregar_info.php in GradMan 0.1.3 and earlier allows remote attackers to include an
23RISK
open ↗Referência
CVE-2018-18548
ajenticp (aka Ajenti Docker control panel) for Ajenti through v1.2.23.13 has XSS via a filename that is mishandled in Fi
23RISK
open ↗Referência
CVE-2018-18548
ajenticp (aka Ajenti Docker control panel) for Ajenti through v1.2.23.13 has XSS via a filename that is mishandled in Fi
23RISK
open ↗Referência
CVE-2010-2254
SQL injection vulnerability in the Shape5 Bridge of Hope template for Joomla! allows remote attackers to execute arbitra
23RISK
open ↗Referência
CVE-2010-2254
SQL injection vulnerability in the Shape5 Bridge of Hope template for Joomla! allows remote attackers to execute arbitra
23RISK
open ↗Referência
CVE-2006-0944
Archangel Weblog 0.90.02 allows remote attackers to bypass authentication by setting the ba_admin cookie to 1.
23RISK
open ↗Referência
CVE-2013-2760
Buffer overflow in Groovy Media Player 3.2.0 allows remote attackers to execute arbitrary code via a long string in a .m
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.