Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,137cataloged exploits
35,961CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,657GitHub PoC 14,424VulnCheck XDB 8,773Nuclei 4,340Metasploit 3,485✓ verified onlyrecentpopularrisk
22,657 exploits
Referência
CVE-2010-3482
Multiple SQL injection vulnerabilities in cms_write.php in Primitive CMS 1.0.9 allow remote authenticated administrators
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component MailTo - 'article' SQL Injection
SQL injection vulnerability in the MailTo (aka com_mailto) component in Joomla! allows remote attackers to execute arbit
23RISK
open ↗Referência
CVE-2009-3349
SQL injection vulnerability in Datavore Gyro 5.0 allows remote attackers to execute arbitrary SQL commands via the cid p
23RISK
open ↗Referência
CVE-2010-0723
SQL injection vulnerability in news.php in Ero Auktion 2.0 and 2010 allows remote attackers to execute arbitrary SQL com
23RISK
open ↗Referência
CVE-2010-0723
SQL injection vulnerability in news.php in Ero Auktion 2.0 and 2010 allows remote attackers to execute arbitrary SQL com
23RISK
open ↗Referência
CVE-2010-0723
SQL injection vulnerability in news.php in Ero Auktion 2.0 and 2010 allows remote attackers to execute arbitrary SQL com
23RISK
open ↗Referência
CVE-2010-0723
SQL injection vulnerability in news.php in Ero Auktion 2.0 and 2010 allows remote attackers to execute arbitrary SQL com
23RISK
open ↗Referência✓ VexDay Proof
NuStore 1.0 - 'Products.asp' SQL Injection
SQL injection vulnerability in Products.asp in NuStore 1.0 allows remote attackers to execute arbitrary SQL commands via
23RISK
open ↗Referência✓ VexDay Proof
gxine 0.5.6 - HTTP Plugin Remote Buffer Overflow (PoC)
Buffer overflow in the HTTP Plugin (xineplug_inp_http.so) for xine-lib 1.1.1 allows remote attackers to cause a denial o
28RISK
open ↗Referência
CVE-2017-14344
This vulnerability allows local attackers to escalate privileges on Jungo WinDriver 12.4.0 and earlier. An attacker must
23RISK
open ↗Referência✓ VexDay Proof
1024 CMS 1.3.1 - Local File Inclusion / SQL Injection
SQL injection vulnerability in admin/ops/findip/ajax/search.php in 1024 CMS 1.3.1 allows remote attackers to execute arb
23RISK
open ↗Referência
CVE-2026-10559
SourceCodester Pizzafy Ecommerce System index.php file inclusion
33RISK
open ↗Referência
CVE-2010-3483
cms_write.php in Primitive CMS 1.0.9 does not properly restrict access, which allows remote attackers to gain administra
23RISK
open ↗Referência
CVE-2013-2712
Cross-site scripting (XSS) vulnerability in services/get_article.php in KrisonAV CMS before 3.0.2 allows remote attacker
23RISK
open ↗Referência
CVE-2024-48445
An issue in compop.ca ONLINE MALL v.3.5.3 allows a remote attacker to execute arbitrary code via the rid, tid, et, and t
48RISK
open ↗Referência
CVE-2014-0793
Multiple cross-site scripting (XSS) vulnerabilities in the StackIdeas Komento (com_komento) component before 1.7.3 for J
23RISK
open ↗Referência
CVE-2014-10018
Cross-site scripting (XSS) vulnerability in webconfig/wlan/country.html/country in the Teracom T2-B-Gawv1.4U10Y-BI modem
23RISK
open ↗Referência
CVE-2010-1146
The Linux kernel 2.6.33.2 and earlier, when a ReiserFS filesystem exists, does not restrict read or write access to the
23RISK
open ↗Referência✓ VexDay Proof
Anata CMS 1.0b5 - 'change.php' Arbitrary Add Admin
change.php in Ananta CMS 1.0b5, with magic_quotes_gpc disabled, allows remote attackers to gain administrator privileges
23RISK
open ↗Referência
CVE-2012-2569
Cross-site scripting (XSS) vulnerability in Synametrics Technologies Xeams 4.4 Build 5720 allows remote attackers to inj
23RISK
open ↗Referência
CVE-2026-5995
Totolink A7100RU CGI cstecgi.cgi setMiniuiHomeInfoShow os command injection
48RISK
open ↗Referência
CVE-2026-5996
Totolink A7100RU CGI cstecgi.cgi setAdvancedInfoShow os command injection
48RISK
open ↗Referência
CVE-2010-0678
PHP remote file inclusion vulnerability in includes/moderation.php in Katalog Stron Hurricane 1.3.5, and possibly earlie
23RISK
open ↗Referência
CVE-2010-0678
PHP remote file inclusion vulnerability in includes/moderation.php in Katalog Stron Hurricane 1.3.5, and possibly earlie
23RISK
open ↗Referência✓ VexDay Proof
Igloo 0.1.9 - 'Wiki.php' Remote File Inclusion
PHP remote file inclusion vulnerability in Wiki.php in Barnraiser Igloo 0.1.9 and earlier allows remote attackers to exe
23RISK
open ↗Referência
CVE-2008-3513
SQL injection vulnerability in the Book Catalog module 1.0 for PHP-Nuke allows remote attackers to execute arbitrary SQL
23RISK
open ↗Referência✓ VexDay Proof
ASPPortal 4.0.0 - 'default1.asp' SQL Injection
SQL injection vulnerability in default1.asp in ASPPortal 4.0.0 beta and earlier allows remote attackers to execute arbit
23RISK
open ↗Referência
CVE-2012-5700
Multiple cross-site scripting (XSS) vulnerabilities in Baby Gekko before 1.2.2f allow remote attackers to inject arbitra
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.