Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,091cataloged exploits
35,949CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,657GitHub PoC 14,396VulnCheck XDB 8,755Nuclei 4,340Metasploit 3,485✓ verified onlyrecentpopularrisk
22,640 exploits
Referência
CVE-2018-11443
The parameter q is affected by Cross-site Scripting in jobcard-ongoing.php in EasyService Billing 1.0.
23RISK
open ↗Referência✓ VexDay Proof
JShop 1.x < 2.x - 'xPage' Local File Inclusion
Directory traversal vulnerability in v2demo/page.php in Jshop Server 1.x through 2.x allows remote attackers to include
23RISK
open ↗Referência
CVE-2017-6331
Prior to SEP 14 RU1 Symantec Endpoint Protection product can encounter an issue of Tamper-Protection Bypass, which is a
23RISK
open ↗Referência
CVE-2009-4748
SQL injection vulnerability in mycategoryorder.php in the My Category Order plugin 2.8 and earlier for WordPress allows
23RISK
open ↗Referência
CVE-2009-4748
SQL injection vulnerability in mycategoryorder.php in the My Category Order plugin 2.8 and earlier for WordPress allows
23RISK
open ↗Referência✓ VexDay Proof
UBBCentral UBB.Threads 6.4.x < 6.5.2 - 'thispath' Remote File Inclusion
PHP remote file inclusion vulnerability in addpost_newpoll.php in UBB.threads 6.4 through 6.5.2 and 6.5.1.1 (trial) allo
23RISK
open ↗Referência✓ VexDay Proof
VidShare Pro - Arbitrary File Upload
Unrestricted file upload vulnerability in VidSharePro allows remote authenticated users to execute arbitrary code by upl
23RISK
open ↗Referência
CVE-2015-1517
SQL injection vulnerability in Piwigo before 2.7.4, when all filters are activated, allows remote authenticated users to
23RISK
open ↗Referência
CVE-2010-0967
Multiple directory traversal vulnerabilities in Geekhelps ADMP 1.01, when magic_quotes_gpc is disabled, allow remote att
23RISK
open ↗Referência
CVE-2024-27620
An issue in Ladder v.0.0.1 thru v.0.0.21 allows a remote attacker to obtain sensitive information via a crafted request
41RISK
open ↗Referência
CVE-2010-1475
Directory traversal vulnerability in the Preventive & Reservation (com_preventive) component 1.0.5 for Joomla! allows re
38RISK
open ↗Referência✓ VexDay Proof
Sisfo Kampus 2006 - 'dwoprn.php?f' Arbitrary File Download
Directory traversal vulnerability in dwoprn.php in Sisfo Kampus 2006 (Semarang 3) allows remote attackers to read arbitr
23RISK
open ↗Referência✓ VexDay Proof
LinPHA 1.3.3 Plugin Maps - Remote Command Execution
plugins/maps/db_handler.php in LinPHA 1.3.3 and earlier does not require authentication for a settings action that modif
23RISK
open ↗Referência✓ VexDay Proof
Pet Grooming Management System 2.0 - Arbitrary Add Admin
Pet Grooming Management System 2.0 allows remote attackers to gain privileges via a direct request to useradded.php with
23RISK
open ↗Referência
CVE-2019-1364
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle o
23RISK
open ↗Referência✓ VexDay Proof
Pooya Site Builder (PSB) 6.0 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in Pooya Site Builder (PSB) 6.0 allow remote attackers to execute arbitrary SQL c
23RISK
open ↗Referência
CVE-2016-3694
Multiple SQL injection vulnerabilities in modified eCommerce Shopsoftware 2.0.0.0 revision 9678, when the easybill-modul
23RISK
open ↗Referência
CVE-2009-3366
Directory traversal vulnerability in navigation.php in An image gallery 1.0 allows remote attackers to list arbitrary di
23RISK
open ↗Referência
CVE-2011-2944
SQL injection vulnerability in login.php in MegaLab The Uploader before 2.0.5 allows remote attackers to execute arbitra
23RISK
open ↗Referência
CVE-2011-2944
SQL injection vulnerability in login.php in MegaLab The Uploader before 2.0.5 allows remote attackers to execute arbitra
23RISK
open ↗Referência
CVE-2010-1478
Directory traversal vulnerability in the Ternaria Informatica Jfeedback! (com_jfeedback) component 1.2 for Joomla! allow
38RISK
open ↗Referência✓ VexDay Proof
eFiction 3.0 - 'toplists.php' SQL Injection
SQL injection vulnerability in toplists.php in eFiction 3.0 and 3.4.3, when magic_quotes_gpc is disabled, allows remote
23RISK
open ↗Referência✓ VexDay Proof
HLStats 1.34 - 'hlstats.php' SQL Injection
HLstats 1.20 through 1.34 allows remote attackers to obtain sensitive information via playinfo mode, with certain values
23RISK
open ↗Referência
CVE-2007-3529
videos.php in PHPDirector 0.21 and earlier allows remote attackers to obtain sensitive information via an empty value of
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.