Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,957cataloged exploits
32,195CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 20,003GitHub PoC 13,307VulnCheck XDB 8,182Nuclei 4,217Metasploit 3,462✓ verified onlyrecentpopularrisk
22,786 exploits
Exploit-DB
Freelance Website Script 2.0.6 - 'pr_id' / 'catid' SQL Injection
Freelance Website Script 2.0.6 has SQL Injection via the jobdetails.php pr_id parameter or the searchbycat_list.php cati
23RISK
open ↗Exploit-DB
MLM Forced Matrix 2.0.9 - 'newid' SQL Injection
MLM Forced Matrix 2.0.9 has SQL Injection via the news-detail.php newid parameter.
23RISK
open ↗Exploit-DB
Advanced World Database 2.0.5 - SQL Injection
Advanced World Database 2.0.5 has SQL Injection via the city.php country or state parameter, or the state.php country pa
23RISK
open ↗Exploit-DB
Apple macOS - 'getrusage' Stack Leak Through struct Padding
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RISK
open ↗Exploit-DB
Entrepreneur Bus Booking Script 3.0.4 - 'sourcebus' SQL Injection
Entrepreneur Bus Booking Script 3.0.4 has SQL Injection via the booker_details.php sourcebus parameter.
23RISK
open ↗Exploit-DB
Linux Kernel - 'mincore()' Heap Page Disclosure (PoC)
The walk_hugetlb_range function in mm/pagewalk.c in the Linux kernel before 4.14.2 mishandles holes in hugetlb ranges, w
23RISK
open ↗Exploit-DB
Multireligion Responsive Matrimonial 4.7.2 - 'succid' SQL Injection
Multireligion Responsive Matrimonial 4.7.2 has SQL Injection via the success-story.php succid parameter.
23RISK
open ↗Exploit-DB
Vanguard 1.4 - SQL Injection
Vanguard Marketplace Digital Products PHP 1.4 has SQL Injection via the PATH_INFO to the /p URI.
23RISK
open ↗Exploit-DB
Multivendor Penny Auction Clone Script 1.0 - SQL Injection
Multivendor Penny Auction Clone Script 1.0 has SQL Injection via the PATH_INFO to the /detail URI.
23RISK
open ↗Exploit-DB
Hot Scripts Clone 3.1 - 'subctid' / 'mctid' SQL Injection
Hot Scripts Clone 3.1 has SQL Injection via the /categories subctid or mctid parameter.
23RISK
open ↗Exploit-DB
Laundry Booking Script 1.0 - 'list?city' SQL Injection
Laundry Booking Script 1.0 has SQL Injection via the /list city parameter.
23RISK
open ↗Exploit-DB
Online Exam Test Application Script 1.6 - 'exams.php?sort' SQL Injection
Online Exam Test Application Script 1.6 has SQL Injection via the exams.php sort parameter.
23RISK
open ↗Exploit-DB
Linux Kernel - 'The Huge Dirty Cow' Overwriting The Huge Zero Page (2)
The Linux Kernel versions 2.6.38 through 4.14 have a problematic use of pmd_mkdirty() in the touch_pmd() function inside
23RISK
open ↗Exploit-DB
Single Theater Booking Script 3.2.1 - 'findcity.php?q' SQL Injection
Single Theater Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
23RISK
open ↗Exploit-DB
MLM Forex Market Plan Script 2.0.4 - 'newid' / 'eventid' SQL Injection
MLM Forex Market Plan Script 2.0.4 has SQL Injection via the news_detail.php newid parameter or the event_detail.php eve
23RISK
open ↗Exploit-DB
Responsive Events & Movie Ticket Booking Script 3.2.1 - 'findcity.php?q' SQL Injection
Responsive Events And Movie Ticket Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
23RISK
open ↗Exploit-DB
Professional Service Script 1.0 - 'service-list?city' SQL Injection
Professional Service Script 1.0 has SQL Injection via the service-list city parameter.
23RISK
open ↗Exploit-DB
Readymade Video Sharing Script 3.2 - SQL Injection
Readymade Video Sharing Script 3.2 has SQL Injection via the single-video-detail.php report_videos array parameter.
23RISK
open ↗Exploit-DB
Apple macOS/iOS - Kernel Double Free due to IOSurfaceRootUserClient not Respecting MIG Ownership Rules
An issue was discovered in certain Apple products. iOS before 11.2 is affected. tvOS before 11.2 is affected. watchOS be
43RISK
open ↗Exploit-DB
Facebook Clone Script 1.0 - 'id' / 'send' SQL Injection
Facebook Clone Script 1.0 has SQL Injection via the friend-profile.php id parameter.
23RISK
open ↗Exploit-DB
Multiplex Movie Theater Booking Script 3.1.5 - 'moid' / 'eid' SQL Injection
Multiplex Movie Theater Booking Script 3.1.5 has SQL Injection via the trailer-detail.php moid parameter, show-time.php
23RISK
open ↗Exploit-DB
Muslim Matrimonial Script 3.02 - 'succid' SQL Injection
Muslim Matrimonial Script 3.02 has SQL Injection via the success-story.php succid parameter.
23RISK
open ↗Exploit-DB
Apple macOS XNU Kernel - Memory Disclosure due to bug in Kernel API for Detecting Kernel Memory Disclosures
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RISK
open ↗Exploit-DB
Responsive Realestate Script 3.2 - 'property-list?tbud' SQL Injection
Responsive Realestate Script 3.2 has SQL Injection via the property-list tbud parameter.
23RISK
open ↗Exploit-DB
Groupon Clone Script 3.01 - 'state_id' / 'search' SQL Injection
Groupon Clone Script 3.01 has SQL Injection via the city_ajax.php state_id parameter.
23RISK
open ↗Exploit-DB
Yoga Class Script 1.0 - 'list?city' SQL Injection
Yoga Class Script 1.0 has SQL Injection via the /list city parameter.
23RISK
open ↗Exploit-DB
Car Rental Script 2.0.4 - 'val' SQL Injection
Car Rental Script 2.0.4 has SQL Injection via the countrycode1.php val parameter.
23RISK
open ↗Exploit-DB
Secure E-commerce Script 2.0.1 - 'searchcat' / 'searchmain' SQL Injection
Secure E-commerce Script 2.0.1 has SQL Injection via the category.php searchmain or searchcat parameter, or the single_d
23RISK
open ↗Exploit-DB
Resume Clone Script 2.0.5 - SQL Injection
Resume Clone Script 2.0.5 has SQL Injection via the preview.php id parameter.
23RISK
open ↗Exploit-DB
Basic Job Site Script 2.0.5 - SQL Injection
Basic Job Site Script 2.0.5 has SQL Injection via the keyword parameter to /job.
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.