Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,137cataloged exploits
35,961CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,657GitHub PoC 14,424VulnCheck XDB 8,773Nuclei 4,340Metasploit 3,485✓ verified onlyrecentpopularrisk
22,657 exploits
Referência
CVE-2010-2031
KAVSafe.sys 2010.4.14.609 and earlier, as used in Kingsoft Webshield 3.5.1.2 and earlier, allows local users to overwrit
23RISK
open ↗Referência
CVE-2013-3961
SQL injection vulnerability in edit_event.php in Simple PHP Agenda before 2.2.9 allows remote authenticated users to exe
23RISK
open ↗Referência✓ VexDay Proof
FreeStyle Wiki 3.6.2 - 'user.dat' Password Disclosure
FreeStyle Wiki (fswiki) 3.6.2 and earlier stores sensitive information under the web root with insufficient access contr
23RISK
open ↗Referência✓ VexDay Proof
Eudora 7.1.0.9 - IMAP FLAGS Remote Overwrite (SEH)
Buffer overflow in Qualcomm Eudora 7.1.0.9 allows user-assisted, remote IMAP servers to execute arbitrary code via a lon
23RISK
open ↗Referência
CVE-2023-27350
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISK
open ↗Referência
CVE-2026-15475
MiniTool Partition Wizard Signed Kernel Driver pwdrvio.sys access control
33RISK
open ↗Referência
CVE-2026-9603
SourceCodester eDoc Doctor Appointment System delete-session.php authorization
33RISK
open ↗Referência✓ VexDay Proof
Prozilla Cheat Script 2.0 - 'id' SQL Injection
SQL injection vulnerability in view_reviews.php in Prozilla Cheat Script (aka Cheats) 2.0 allows remote attackers to exe
23RISK
open ↗Referência
CVE-2015-5540
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linu
35RISK
open ↗Referência
CVE-2014-3935
SQL injection vulnerability in glossaire-aff.php in the Glossaire module 1.0 for XOOPS allows remote attackers to execut
23RISK
open ↗Referência
CVE-2009-3665
Multiple SQL injection vulnerabilities in index.php in Nullam Blog 0.1.2 allow remote attackers to execute arbitrary SQL
23RISK
open ↗Referência
CVE-2018-20472
An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. The logs web interface is vulnerable to stored XSS.
23RISK
open ↗Referência
CVE-2014-2081
Multiple SQL injection vulnerabilities in the login in web_reports/cgi-bin/InfoStation.cgi in Innovative vtls-Virtua bef
23RISK
open ↗Referência✓ VexDay Proof
Ultrastats 0.2.142 - 'players-detail.php' Blind SQL Injection
SQL injection vulnerability in players-detail.php in UltraStats 0.2.136, 0.2.140, and 0.2.142 allows remote attackers to
23RISK
open ↗Referência✓ VexDay Proof
ASP Portal - Multiple SQL Injections
Multiple SQL injection vulnerabilities in ASP Portal allow remote attackers to execute arbitrary SQL commands via the (1
23RISK
open ↗Referência✓ VexDay Proof
Pligg 9.9.5b - Arbitrary File Upload / SQL Injection
SQL injection vulnerability in evb/check_url.php in Pligg CMS 9.9.5 Beta allows remote attackers to execute arbitrary SQ
23RISK
open ↗Referência✓ VexDay Proof
k-rate - SQL Injection / Cross-Site Scripting
Multiple SQL injection vulnerabilities in Qsoft K-Rate Premium allow remote attackers to execute arbitrary SQL commands
23RISK
open ↗Referência✓ VexDay Proof
2DayBiz Template Monster Clone - 'edituser.php' Change Pass
admin/edituser.php in 2daybiz Template Monster Clone does not require administrative authentication, which allows remote
23RISK
open ↗Referência
CVE-2014-4741
SQL injection vulnerability in demo/ads.php in Artifectx xClassified 1.2 allows remote attackers to execute arbitrary SQ
23RISK
open ↗Referência
CVE-2014-9242
SQL injection vulnerability in admin/pages/modify.php in WebsiteBaker 2.8.3 allows remote attackers to execute arbitrary
23RISK
open ↗Referência
CVE-2011-4026
SQL injection vulnerability in thanks.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via
23RISK
open ↗Referência✓ VexDay Proof
PHPEasyData Pro 2.2.2 - 'index.php' SQL Injection
SQL injection vulnerability in index.php in PHPEasyData Pro 1.4.1 and 2.2.1 allows remote attackers to execute arbitrary
23RISK
open ↗Referência✓ VexDay Proof
bilboblog 2.1 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in BilboBlog 0.2.1 allow remote authenticated administrators to inje
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.