Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,214cataloged exploits
36,016CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,697GitHub PoC 14,449VulnCheck XDB 8,773Nuclei 4,349Metasploit 3,488✓ verified onlyrecentpopularrisk
22,657 exploits
Referência✓ VexDay Proof
Alstrasoft Article Manager Pro 1.6 - Authentication Bypass
SQL injection vulnerability in admin/admin.php in AlstraSoft Article Manager Pro 1.6 allows remote attackers to execute
23RISK
open ↗Referência
CVE-2016-9111
Incorrect access control mechanisms in Citrix Receiver Desktop Lock 4.5 allow an attacker to bypass the authentication r
23RISK
open ↗Referência
CVE-2016-9111
Incorrect access control mechanisms in Citrix Receiver Desktop Lock 4.5 allow an attacker to bypass the authentication r
23RISK
open ↗Referência★ 7
CVE-2025-0364: BigAnt Server RCE Exploit
BigAntSoft BigAnt Server Account Registration Bypass to File Upload RCE
48RISK
open ↗Referência
CVE-2010-2143
Directory traversal vulnerability in index.php in Symphony CMS 2.0.7 allows remote attackers to read arbitrary files and
23RISK
open ↗Referência✓ VexDay Proof
Click N Print Coupons 2006.01 - 'key' SQL Injection
SQL injection vulnerability in coupon_detail.asp in Website Designs For Less Click N' Print Coupons 2005.01 and earlier
23RISK
open ↗Referência✓ VexDay Proof
otscms 2.1.5 - SQL Injection / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in forum.php in Open Tibia Server CMS (OTSCMS) 2.1.5 and earlier allows remote
23RISK
open ↗Referência✓ VexDay Proof
creative Guestbook 1.0 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in Guestbook.php in Creative Guestbook 1.0 allows remote attackers to inject ar
23RISK
open ↗Referência
CVE-2009-3368
Cross-site scripting (XSS) vulnerability in the Hotel Booking Reservation System (aka HBS or com_hbssearch) component fo
23RISK
open ↗Referência
CVE-2014-6420
Cross-site scripting (XSS) vulnerability in Livefyre LiveComments 3.0 allows remote attackers to inject arbitrary web sc
23RISK
open ↗Referência✓ VexDay Proof
dnGuestbook 2.0 - SQL Injection
SQL injection vulnerability in admin.php in Design Nation DNGuestbook 2.0 allows remote attackers to execute arbitrary S
23RISK
open ↗Referência
CVE-2005-4415
Cross-site scripting (XSS) vulnerability in index.php in TML CMS 0.5 allows remote attackers to inject arbitrary web scr
23RISK
open ↗Referência
CVE-2019-9701
DLP 15.5 MP1 and all prior versions may be susceptible to a cross-site scripting (XSS) vulnerability, a type of issue th
23RISK
open ↗Referência
CVE-2024-53586
An issue in the relPath parameter of WebFileSys version 2.31.0 allows attackers to perform directory traversal via a cra
33RISK
open ↗Referência
CVE-2015-7358
The IsDriveLetterAvailable method in Driver/Ntdriver.c in TrueCrypt 7.0, VeraCrypt before 1.15, and CipherShed, when run
23RISK
open ↗Referência
CVE-2015-7358
The IsDriveLetterAvailable method in Driver/Ntdriver.c in TrueCrypt 7.0, VeraCrypt before 1.15, and CipherShed, when run
23RISK
open ↗Referência
CVE-2020-13927
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but th
100RISK
open ↗Referência
CVE-2018-10711
The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Str
23RISK
open ↗Referência
CVE-2009-3222
Cross-site scripting (XSS) vulnerability in index.php in FreeWebScriptz Honest Traffic (FWSHT) 1.x allows remote attacke
23RISK
open ↗Referência
CVE-2009-4403
Cross-site scripting (XSS) vulnerability in index.php in Rumba XML 1.8 allows remote attackers to inject arbitrary web s
23RISK
open ↗Referência✓ VexDay Proof
A-Link WL54AP3 / WL54AP2 - Cross-Site Request Forgery / Cross-Site Scripting
Multiple cross-site request forgery (CSRF) vulnerabilities in the management interface on the A-LINK WL54AP3 and WL54AP2
23RISK
open ↗Referência
CVE-2014-9226
The management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center Security:
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.