Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,137cataloged exploits
35,961CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,657GitHub PoC 14,424VulnCheck XDB 8,773Nuclei 4,340Metasploit 3,485✓ verified onlyrecentpopularrisk
22,657 exploits
Referência
CVE-2014-5104
Multiple SQL injection vulnerabilities in ol-commerce 2.1.1 allow remote attackers to execute arbitrary SQL commands via
23RISK
open ↗Referência
CVE-2017-5223
An issue was discovered in PHPMailer before 5.2.22. PHPMailer's msgHTML method applies transformations to an HTML docume
23RISK
open ↗Referência✓ VexDay Proof
MFORUM 0.1a - Arbitrary Add Admin
Multiple SQL injection vulnerabilities in usercp.php in mForum 0.1a, when magic_quotes_gpc is disabled, allow remote att
23RISK
open ↗Referência
CVE-2015-5465
Silicon Integrated Systems WindowsXP Display Manager (aka VGA Driver Manager and VGA Display Manager) 6.14.10.3930 allow
23RISK
open ↗Referência
CVE-2026-58057
Flowise - Custom MCP Environment Variable Denylist Bypass via Case Sensitivity
28RISK
open ↗Referência
CVE-2009-3511
Multiple PHP remote file inclusion vulnerabilities in justVisual 1.2 allow remote attackers to execute arbitrary PHP cod
23RISK
open ↗Referência
CVE-2013-3721
SQL injection vulnerability in awards.php in PsychoStats 3.2.2b allows remote attackers to execute arbitrary SQL command
23RISK
open ↗Referência✓ VexDay Proof
sma-db 0.3.12 - Remote File Inclusion / Cross-Site Scripting
PHP remote file inclusion vulnerability in format.php in SMA-DB 0.3.12 allows remote attackers to execute arbitrary PHP
23RISK
open ↗Referência✓ VexDay Proof
Shop-Script 2.0 - 'index.php' Remote File Disclosure
Directory traversal vulnerability in index.php in Shop-Script 2.0 and possibly other versions allows remote attackers to
23RISK
open ↗Referência
Flatpress Add Blog 1.0.3 - Persistent Cross-Site Scripting
FlatPress 1.0.3 is affected by cross-site scripting (XSS) in the Blog Content component. This vulnerability can allow an
23RISK
open ↗Referência
Collabtive 3.1 - 'address' Persistent Cross-Site Scripting
Collabtive 3.1 allows XSS when an authenticated user enters an XSS payload into the address section of the profile edit
23RISK
open ↗Referência
CVE-2018-5479
FoxSash ImgHosting 1.5 (according to footer information) is vulnerable to XSS attacks. The affected function is its sear
23RISK
open ↗Referência
CVE-2011-0503
Cross-site request forgery (CSRF) vulnerability in VaM Shop 1.6, 1.6.1, and probably earlier versions allows remote atta
23RISK
open ↗Referência
CVE-2010-4914
PHP remote file inclusion vulnerability in tools/phpmailer/class.phpmailer.php in PHP Classifieds 7.3 allows remote atta
23RISK
open ↗Referência
CVE-2010-1106
PHP remote file inclusion vulnerability in cgi/index.php in AdvertisementManager 3.1.0 allows remote attackers to execut
23RISK
open ↗Referência
CVE-2014-4943
The PPPoL2TP feature in net/l2tp/l2tp_ppp.c in the Linux kernel through 3.15.6 allows local users to gain privileges by
23RISK
open ↗Referência
CVE-2026-4163
Wavlink WL-WN579A3 POST Request wireless.cgi GuestWifi command injection
48RISK
open ↗Referência✓ VexDay Proof
DesktopOnNet 3 Beta - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in DesktopOnNet 3 Beta allow remote attackers to execute arbitrary PH
23RISK
open ↗Referência
CVE-2014-9237
SQL injection vulnerability in Proticaret E-Commerce 3.0 allows remote attackers to execute arbitrary SQL commands via a
23RISK
open ↗Referência✓ VexDay Proof
Avlc Forum - 'vlc_forum.php' SQL Injection
SQL injection vulnerability in vlc_forum.php in Avlc Forum as of 20080715 allows remote attackers to execute arbitrary S
23RISK
open ↗Referência
CVE-2009-4156
PHP remote file inclusion vulnerability in modules/pms/index.php in Ciamos CMS 0.9.5 and earlier allows remote attackers
23RISK
open ↗Referência
CVE-2026-63086
text-generation-inference 3.3.7 SSRF via fetch_image in multimodal chat completions
33RISK
open ↗Referência✓ VexDay Proof
Ad Manager Pro 2.6 - 'ipath' Remote File Inclusion
PHP remote file inclusion vulnerability in Ad Manager Pro 2.6 allows remote attackers to execute arbitrary PHP code via
23RISK
open ↗Referência✓ VexDay Proof
LulieBlog 1.0.1 - Remote Authentication Bypass
LulieBlog 1.0.1 and 1.0.2 does not restrict access to (1) article_suppr.php, (2) comment_accepter.php, and (3) comment_r
23RISK
open ↗Referência
CVE-2026-15475
MiniTool Partition Wizard Signed Kernel Driver pwdrvio.sys access control
33RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.