Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
75,652cataloged exploits
34,545CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,581GitHub PoC 13,708VulnCheck XDB 8,225Nuclei 4,228Metasploit 3,467✓ verified onlyrecentpopularrisk
21,554 exploits
Referência
CVE-2015-4682
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows remote authenticated users to obtain the installation
23RISK
open ↗Referência
CVE-2015-4682
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows remote authenticated users to obtain the installation
23RISK
open ↗Referência
CVE-2008-1866
admin/modif_config.php in Blog Pixel Motion (aka PixelMotion) does not require admin authentication, which allows remote
23RISK
open ↗Referência
CVE-2016-3962
Stack-based buffer overflow in the NTP time-server interface on Meinberg IMS-LANTIME M3000, IMS-LANTIME M1000, IMS-LANTI
23RISK
open ↗Referência
CVE-2010-3153
Untrusted search path vulnerability in Adobe InDesign CS4 6.0, InDesign CS5 7.0.2 and earlier, Adobe InDesign Server CS5
28RISK
open ↗Referência
CVE-2017-6096
A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/list
23RISK
open ↗Referência
CVE-2017-6097
A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/camp
23RISK
open ↗Referência
CVE-2013-2586
XAMPP 1.8.1 does not properly restrict access to xampp/lang.php, which allows remote attackers to modify xampp/lang.tmp
23RISK
open ↗Referência
CVE-2015-5287
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain perm
38RISK
open ↗Referência
CVE-2018-8550
An elevation of privilege exists in Windows COM Aggregate Marshaler, aka "Windows COM Elevation of Privilege Vulnerabili
23RISK
open ↗Referência
CVE-2010-1092
Multiple SQL injection vulnerabilities in login.php in ScriptsFeed Business Directory Software allow remote attackers to
23RISK
open ↗Referência
CVE-2017-18001
Trustwave Secure Web Gateway (SWG) through 11.8.0.27 allows remote attackers to append an arbitrary public key to the de
28RISK
open ↗Referência
CVE-2017-7783
If a long user name is used in a username/password combination in a site URL (such as " http://UserName:Password@example
28RISK
open ↗Referência
CVE-2017-16353
GraphicsMagick 1.3.26 is vulnerable to a memory information disclosure vulnerability found in the DescribeImage function
28RISK
open ↗Referência
CVE-2017-8870
Buffer overflow in AudioCoder 0.8.46 allows remote attackers to execute arbitrary code via a crafted .m3u file.
43RISK
open ↗Referência✓ VexDay Proof
Blog:CMS 4.1.3 - 'NP_UserSharing.php' Remote File Inclusion
PHP remote file inclusion vulnerability in admin/plugins/NP_UserSharing.php in BLOG:CMS 4.1.3 and earlier allows remote
23RISK
open ↗Referência✓ VexDay Proof
Jupiter CMS 1.1.5 - '/index.php' Local/Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in Jupiter CMS 1.1.5, when PHP 5.0.0 or later is used, allows remot
23RISK
open ↗Referência✓ VexDay Proof
AMX Corp. VNC ActiveX Control - 'AmxVnc.dll 1.0.13.0' Remote Buffer Overflow
Multiple buffer overflows in the AMX NetLinx VNC (AmxVnc) ActiveX control in AmxVnc.dll 1.0.13.0 allow remote attackers
28RISK
open ↗Referência✓ VexDay Proof
PHPress 0.2.0 - 'adisplay.php?lang' Local File Inclusion
PHP remote file inclusion vulnerability in adisplay.php in PhPress 0.2.0 allows remote attackers to execute arbitrary PH
23RISK
open ↗Referência
CVE-2011-4813
Directory traversal vulnerability in clientarea.php in WHMCompleteSolution (WHMCS) 3.x.x allows remote attackers to read
23RISK
open ↗Referência
CVE-2009-3182
Unrestricted file upload vulnerability in admin/editor/filemanager/browser.html in Anantasoft Gazelle CMS 1.0 allows rem
23RISK
open ↗Referência
CVE-2014-2559
Multiple cross-site request forgery (CSRF) vulnerabilities in twitget.php in the Twitget plugin before 3.3.3 for WordPre
23RISK
open ↗Referência
CVE-2015-1575
Multiple cross-site scripting (XSS) vulnerabilities in u5CMS before 3.9.4 allow remote attackers to inject arbitrary web
23RISK
open ↗Referência
CVE-2015-1575
Multiple cross-site scripting (XSS) vulnerabilities in u5CMS before 3.9.4 allow remote attackers to inject arbitrary web
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.