Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,137cataloged exploits
35,961CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,657GitHub PoC 14,424VulnCheck XDB 8,773Nuclei 4,340Metasploit 3,485✓ verified onlyrecentpopularrisk
22,657 exploits
Referência
CVE-2018-15884
RICOH MP C4504ex devices allow HTML Injection via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn parameter.
23RISK
open ↗Referência
CVE-2009-4118
The StartServiceCtrlDispatcher function in the cvpnd service (cvpnd.exe) in Cisco VPN client for Windows before 5.0.06.0
23RISK
open ↗Referência
CVE-2018-16252
FsPro Labs Event Log Explorer 4.6.1.2115 has ".elx" FileType XML External Entity Injection.
23RISK
open ↗Referência
CVE-2019-13657
CA Performance Management 3.5.x, 3.6.x before 3.6.9, and 3.7.x before 3.7.4 have a default credential vulnerability that
48RISK
open ↗Referência
CVE-2019-13657
CA Performance Management 3.5.x, 3.6.x before 3.6.9, and 3.7.x before 3.7.4 have a default credential vulnerability that
48RISK
open ↗Referência
CVE-2013-7193
Multiple SQL injection vulnerabilities in C2C Forward Auction Creator 2.0 allow remote attackers to execute arbitrary SQ
23RISK
open ↗Referência✓ VexDay Proof
ASP.NET w3wp - COM Components Remote Crash
Microsoft w3wp (aka w3wp.exe) does not properly handle when the AspCompat directive is not used when referencing COM com
35RISK
open ↗Referência✓ VexDay Proof
Mini Blog 1.0.1 - 'index.php' Multiple Local File Inclusions
Multiple directory traversal vulnerabilities in index.php in Mini Blog 1.0.1 allow remote attackers to include and execu
23RISK
open ↗Referência✓ VexDay Proof
AJ Auction - Authentication Bypass
AJ Square AJ Auction Pro Platinum Skin #1 sends a redirect but does not exit when it is called directly, which allows re
23RISK
open ↗Referência
CVE-2026-40521
FrontAccounting < 2.4.20 Path Traversal RCE via attachment upload
41RISK
open ↗Referência✓ VexDay Proof
Enthrallweb eClassifieds 1.0 - Remote User Pass Change
myprofile.asp in Enthrallweb eClassifieds does not properly validate the MM_recordId parameter during profile updates, w
23RISK
open ↗Referência✓ VexDay Proof
Tuned Studios Templates - Local File Inclusion
Multiple directory traversal vulnerabilities in index.php in Tuned Studios (1) Subwoofer, (2) Freeze Theme, (3) Orange C
23RISK
open ↗Referência
CVE-2009-3317
PHP remote file inclusion vulnerability in pages/pageHeader.php in OpenSiteAdmin 0.9.7 BETA allows remote attackers to e
23RISK
open ↗Referência
CVE-2026-19034
Shibby Tomato qoslimittc_stop.sh new_qoslimit_stop os command injection
41RISK
open ↗Referência✓ VexDay Proof
Alstrasoft AskMe Pro 2.1 - Multiple SQL Injections
SQL injection vulnerability in profile.php in AlstraSoft AskMe Pro 2.1 and earlier allows remote attackers to execute ar
23RISK
open ↗Referência
CVE-2014-5284
host-deny.sh in OSSEC before 2.8.1 writes to temporary files with predictable filenames without verifying ownership, whi
23RISK
open ↗Referência✓ VexDay Proof
AssoCIateD CMS 1.1.3 - 'ROOT_PATH' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in AssoCIateD (aka ACID) CMS 1.1.3 allow remote attackers to execute
23RISK
open ↗Referência
CVE-2018-9173
Cross-site scripting (XSS) vulnerability in admin/template/js/uploadify/uploadify.swf in GetSimple CMS 3.3.13 allows rem
23RISK
open ↗Referência
CVE-2016-5195
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open ↗Referência
CVE-2016-5195
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open ↗Referência
CVE-2010-1706
Multiple SQL injection vulnerabilities in login.php in 2daybiz Auction Script allow remote attackers to execute arbitrar
23RISK
open ↗Referência
CVE-2010-1706
Multiple SQL injection vulnerabilities in login.php in 2daybiz Auction Script allow remote attackers to execute arbitrar
23RISK
open ↗Referência✓ VexDay Proof
Phaos 0.9.2 - 'basename()' Remote Command Execution
Directory traversal vulnerability in include_lang.php in Phaos 0.9.2 allows remote attackers to include arbitrary local
23RISK
open ↗Referência✓ VexDay Proof
PHP Crawler 0.8 - Remote File Inclusion
PHP remote file inclusion vulnerability in footer.php in PHP-Crawler 0.8 allows remote attackers to execute arbitrary PH
23RISK
open ↗Referência✓ VexDay Proof
MyBlog 0.9.8 - Insecure Cookie Handling
add.php in MyBlog 0.9.8 and earlier allows remote attackers to bypass authentication and gain administrative access by s
23RISK
open ↗Referência✓ VexDay Proof
Fuzzylime CMS 3.03 - 'track.php' Local File Inclusion
Directory traversal vulnerability in code/track.php in FuzzyLime 3.03 allows remote attackers to include and execute arb
23RISK
open ↗Referência✓ VexDay Proof
Maran PHP Shop - 'admin.php' Insecure Cookie Handling
admin.php in Maran PHP Shop allows remote attackers to bypass authentication and gain administrative access by setting t
23RISK
open ↗Referência✓ VexDay Proof
NuralStorm Webmail 0.98b - 'process.php' Remote File Inclusion
PHP remote file inclusion vulnerability in process.php in NuralStorm Webmail 0.98b and earlier, when register_globals is
23RISK
open ↗Referência✓ VexDay Proof
OpenForum 0.66 Beta - Remote Reset Admin Password
OpenForum 0.66 Beta allows remote attackers to bypass authentication and reset passwords of other users via a direct req
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.