Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
75,652cataloged exploits
34,545CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,581GitHub PoC 13,708VulnCheck XDB 8,225Nuclei 4,228Metasploit 3,467✓ verified onlyrecentpopularrisk
21,581 exploits
Referência✓ VexDay Proof
chCounter 3.1.3 - Authentication Bypass
Multiple SQL injection vulnerabilities in stats/index.php in chCounter 3.1.3 allow remote attackers to execute arbitrary
23RISK
open ↗Referência✓ VexDay Proof
CRE Loaded 6.2 - 'products_id' SQL Injection
SQL injection vulnerability in product_info.php in CRE Loaded 6.2 allows remote attackers to execute arbitrary SQL comma
23RISK
open ↗Referência
CVE-2011-5207
Cross-site scripting (XSS) vulnerability in admin/OptionsPostsList.php in the TheCartPress plugin for WordPress before 1
23RISK
open ↗Referência✓ VexDay Proof
pastelcms 0.8.0 - Local File Inclusion / SQL Injection
SQL injection vulnerability in admin.php in PastelCMS 0.8.0, when magic_quotes_gpc is disabled, allows remote attackers
23RISK
open ↗Referência✓ VexDay Proof
TotalCalendar 2.4 - 'Include' Local File Inclusion
Directory traversal vulnerability in cms_detect.php in TotalCalendar 2.4 allows remote attackers to include and execute
23RISK
open ↗Referência✓ VexDay Proof
e107 < 0.7.15 - 'extended_user_fields' Blind SQL Injection
SQL injection vulnerability in usersettings.php in e107 0.7.15 and earlier, when "Extended User Fields" is enabled and m
23RISK
open ↗Referência✓ VexDay Proof
Quick.CMS.Lite 0.5 - 'id' SQL Injection
SQL injection vulnerability in index.php in Quick.Cms.Lite 0.5 allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗Referência
CVE-2020-37245
WordPress Plugin Supsystic Digital Publications 1.6.9 Path Traversal XSS
41RISK
open ↗Referência
CVE-2020-37236
NewsLister Authenticated Persistent Cross-Site Scripting via Admin Panel
33RISK
open ↗Referência
CVE-2020-37235
WordPress Theme Wibar 1.1.8 Stored Cross-Site Scripting via Brand Component
33RISK
open ↗Referência
CVE-2020-37233
WordPress Plugin Buddypress 6.2.0 Persistent Cross-Site Scripting
33RISK
open ↗Referência
CVE-2026-16484
SourceCodester Class and Exam Timetabling System edit_subjecta.php sql injection
33RISK
open ↗Referência
CVE-2026-42881
STIGQter: Arbitrary File Write leading to Local Code Execution via Export HTML
41RISK
open ↗Referência
CVE-2026-13147
Kirki < 6.0.12 - Unauthenticated Server-Side Request Forgery via kirki_get_apis
48RISK
open ↗Referência
CVE-2026-13142
Passwordless Login by VentraConnect < 1.4.1 - Unauthenticated Account Takeover via Email OTP Brute Force
41RISK
open ↗Referência
CVE-2026-12973
PayPlus Payment Gateway < 8.2.2 - Unauthenticated Order Key Disclosure and Order Status Modification
33RISK
open ↗Referência✓ VexDay Proof
TemaTres 1.0.3 - Blind SQL Injection
Multiple SQL injection vulnerabilities in TemaTres 1.0.3 and 1.031, when magic_quotes_gpc is disabled, allow remote atta
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.