Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
75,589cataloged exploits
34,508CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,554GitHub PoC 13,689VulnCheck XDB 8,216Nuclei 4,223Metasploit 3,464✓ verified onlyrecentpopularrisk
21,554 exploits
Referência✓ VexDay Proof
SysInfo 1.21 - 'sysinfo.cgi' Remote Command Execution
sysinfo.cgi in sysinfo 1.21 allows remote attackers to obtain the installation path via the debugger action.
23RISK
open ↗Referência
CVE-2019-1010124
WebAppick WooCommerce Product Feed 2.2.18 and earlier is affected by: Cross Site Scripting (XSS). The impact is: XSS to
23RISK
open ↗Referência✓ VexDay Proof
Lms 1.8.9 - Vala Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in LAN Management System (LMS) 1.8.9 Vala and earlier allow remote at
28RISK
open ↗Referência
CVE-2018-17376
SQL Injection exists in the Reverse Auction Factory 4.3.8 component for Joomla! via the filter_order_Dir, cat, or filter
23RISK
open ↗Referência
CVE-2018-17376
SQL Injection exists in the Reverse Auction Factory 4.3.8 component for Joomla! via the filter_order_Dir, cat, or filter
23RISK
open ↗Referência
CVE-2018-17377
SQL Injection exists in the Questions 1.4.3 component for Joomla! via the term, userid, users, or groups parameter.
23RISK
open ↗Referência
CVE-2018-6947
An uninitialised stack variable in the nxfuse component that is part of the Open Source DokanFS library shipped with NoM
23RISK
open ↗Referência
CVE-2018-6947
An uninitialised stack variable in the nxfuse component that is part of the Open Source DokanFS library shipped with NoM
23RISK
open ↗Referência✓ VexDay Proof
Focus/SIS 1.0/2.2 - Remote File Inclusion
PHP remote file inclusion vulnerability in modules/Discipline/CategoryBreakdownTime.php in Focus/SIS 1.0 allows remote a
23RISK
open ↗Referência
CVE-2018-17382
SQL Injection exists in the Jobs Factory 2.0.4 component for Joomla! via the filter_letter parameter.
23RISK
open ↗Referência
CVE-2018-17382
SQL Injection exists in the Jobs Factory 2.0.4 component for Joomla! via the filter_letter parameter.
23RISK
open ↗Referência
CVE-2018-18763
SaltOS 3.1 r8126 allows action=ajax&query=numbers&page=usuarios&action2=[SQL] SQL Injection.
23RISK
open ↗Referência✓ VexDay Proof
Fuju News 1.0 - Authentication Bypass / SQL Injection
SQL injection vulnerability in archiv2.php in Fuju News 1.0 allows remote attackers to execute arbitrary SQL commands vi
23RISK
open ↗Referência
CVE-2021-26929
An XSS issue was discovered in Horde Groupware Webmail Edition through 5.2.22 (where the Horde_Text_Filter library befor
23RISK
open ↗Referência
CVE-2021-26929
An XSS issue was discovered in Horde Groupware Webmail Edition through 5.2.22 (where the Horde_Text_Filter library befor
23RISK
open ↗Referência✓ VexDay Proof
D-Bus Daemon < 1.2.4 - 'libdbus' Denial of Service
The dbus_signature_validate function in the D-bus library (libdbus) before 1.2.4 allows remote attackers to cause a deni
23RISK
open ↗Referência
CVE-2023-39026
Directory Traversal vulnerability in FileMage Gateway Windows Deployments v.1.10.8 and before allows a remote attacker t
43RISK
open ↗Referência
CVE-2020-6756
languageOptions.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows unauthenticated attackers to re
53RISK
open ↗Referência
CVE-2021-27370
The Contact page in Monica 2.19.1 allows stored XSS via the Last Name field.
23RISK
open ↗Referência
CVE-2015-6568
Wolf CMS before 0.8.3.1 allows unrestricted file rename and PHP Code Execution because admin/plugin/file_manager/browse/
28RISK
open ↗Referência
CVE-2015-6568
Wolf CMS before 0.8.3.1 allows unrestricted file rename and PHP Code Execution because admin/plugin/file_manager/browse/
28RISK
open ↗Referência✓ VexDay Proof
Joomla! Component ionFiles 4.4.2 - File Disclosure
Directory traversal vulnerability in download.php in the ionFiles (com_ionfiles) 4.4.2 component for Joomla! allows remo
43RISK
open ↗Referência
CVE-2010-1345
Directory traversal vulnerability in the Cookex Agency CKForms (com_ckforms) component 1.3.3 for Joomla! allows remote a
43RISK
open ↗Referência
CVE-2010-1346
SQL injection vulnerability in admin/login.php in Mini CMS RibaFS 1.0, when magic_quotes_gpc is disabled, allows remote
23RISK
open ↗Referência
CVE-2019-11537
In osTicket before 1.12, XSS exists via /upload/file.php, /upload/scp/users.php?do=import-users, and /upload/scp/ajax.ph
23RISK
open ↗Referência
CVE-2010-1349
Integer overflow in Opera 10.10 through 10.50 allows remote attackers to execute arbitrary code via a large Content-Leng
28RISK
open ↗Referência✓ VexDay Proof
Fuju News 1.0 - Authentication Bypass / SQL Injection
edit_kategorie.php in Fuju News 1.0 allows remote attackers to bypass authentication by setting the authorized cookie.
23RISK
open ↗Referência
CVE-2018-18804
Bakeshop Inventory System 1.0 has SQL injection via the login screen, related to include/publicfunction.vb.
23RISK
open ↗Referência
CVE-2018-18804
Bakeshop Inventory System 1.0 has SQL injection via the login screen, related to include/publicfunction.vb.
23RISK
open ↗Referência✓ VexDay Proof
osTicket 1.11 - Cross-Site Scripting / Local File Inclusion
In osTicket before 1.12, XSS exists via /upload/file.php, /upload/scp/users.php?do=import-users, and /upload/scp/ajax.ph
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.