Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
75,652cataloged exploits
34,545CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,581GitHub PoC 13,708VulnCheck XDB 8,225Nuclei 4,228Metasploit 3,467✓ verified onlyrecentpopularrisk
21,581 exploits
Referência
CVE-2022-45712
IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the rules parameter in the formAddDnsForwa
48RISK
open ↗Referência
CVE-2022-45714
IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the indexSet parameter in the formQOSRuleD
48RISK
open ↗Referência
CVE-2022-45715
IP-COM M50 V15.11.0.33(10768) was discovered to contain multiple buffer overflows via the pLanPortRange and pWanPortRang
48RISK
open ↗Referência
CVE-2022-45716
IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the indexSet parameter in the formIPMacBin
48RISK
open ↗Referência
CVE-2022-45718
IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the rules parameter in the formIPMacBindAd
48RISK
open ↗Referência
CVE-2022-45719
IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the gotoUrl parameter in the formPortalAut
48RISK
open ↗Referência
CVE-2022-45720
IP-COM M50 V15.11.0.33(10768) was discovered to contain multiple buffer overflows via the ip, mac, and remark parameters
48RISK
open ↗Referência
CVE-2022-45706
IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the hostname parameter in the formSetNetCh
48RISK
open ↗Referência
CVE-2010-4876
SQL injection vulnerability in viewpost.php in mBlogger 1.0.04 allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗Referência✓ VexDay Proof
Mambo Component 'com_a6mambocredits' 1.0.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in admin.a6mambocredits.php in the a6mambocredits component (com_a6mambocredits)
23RISK
open ↗Referência✓ VexDay Proof
PHlyMail Lite 3.4.4 - 'mod.listmail.php' Remote File Inclusion
PHP remote file inclusion vulnerability in handlers/email/mod.listmail.php in PHlyMail Lite 3.4.4 and earlier (Build 3.0
23RISK
open ↗Referência
CVE-2014-9457
SQL injection vulnerability in classes/mono_display.class.php in PMB 4.1.3 and earlier allows remote authenticated users
23RISK
open ↗Referência
CVE-2023-1258
Flow-X disclosure of sensitive information to unauthenticated users
33RISK
open ↗Referência✓ VexDay Proof
Discuz! 5.0.0 GBK - SQL Injection / Admin Credentials Disclosure
SQL injection vulnerability in admincp.php in Discuz! GBK 5.0.0 allows remote attackers to execute arbitrary SQL command
23RISK
open ↗Referência
CVE-2025-28036
TOTOLINK A950RG V4.1.2cu.5161_B20200903 was found to contain a pre-auth remote command execution vulnerability in the se
48RISK
open ↗Referência
CVE-2025-28035
TOTOLINK A830R V4.1.2cu.5182_B20201102 was found to contain a pre-auth remote command execution vulnerability in the set
48RISK
open ↗Referência
CVE-2022-41403
OpenCart 3.x Newsletter Custom Popup was discovered to contain a SQL injection vulnerability via the email parameter at
48RISK
open ↗Referência
CVE-2025-28034
TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.51
48RISK
open ↗Referência
CVE-2009-3965
SQL injection vulnerability in rating.php in New 5 star Rating 1.0 allows remote attackers to execute arbitrary SQL comm
23RISK
open ↗Referência
CVE-2022-40877
Exam Reviewer Management System 1.0 is vulnerable to SQL Injection via the ‘id’ parameter.
48RISK
open ↗Referência
CVE-2015-4669
The MySQL "root" user in Xsuite 2.x does not have a password set, which allows local users to access databases on the sy
23RISK
open ↗Referência✓ VexDay Proof
DigiRez 3.4 - 'book_id' SQL Injection
SQL injection vulnerability in info_book.asp in Digirez 3.4 and earlier allows remote attackers to execute arbitrary SQL
23RISK
open ↗Referência✓ VexDay Proof
MiaCMS 4.6.5 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in the com_content component in MiaCMS 4.6.5 allow remote attackers to execute ar
23RISK
open ↗Referência✓ VexDay Proof
Basic PHP Events Lister 1.0 - SQL Injection
SQL injection vulnerability in event.php in Mevin Productions Basic PHP Events Lister 1.0 allows remote attackers to exe
23RISK
open ↗Referência
CVE-2015-6306
Cisco AnyConnect Secure Mobility Client 4.1(8) on OS X and Linux does not verify pathnames before installation actions,
23RISK
open ↗Referência
CVE-2015-6306
Cisco AnyConnect Secure Mobility Client 4.1(8) on OS X and Linux does not verify pathnames before installation actions,
23RISK
open ↗Referência
CVE-2015-1515
The dwall.sys driver in SoftSphere DefenseWall Personal Firewall 3.24 allows local users to write data to arbitrary memo
23RISK
open ↗Referência
CVE-2023-1934
The PnPSCADA system, a product of SDG Technologies CC, is afflicted by a critical unauthenticated error-based PostgreSQL
48RISK
open ↗Referência
CVE-2015-1336
The daily mandb cleanup job in Man-db before 2.7.6.1-1 as packaged in Ubuntu and Debian allows local users with access t
23RISK
open ↗Referência
CVE-2014-9643
K7Sentry.sys in K7 Computing Ultimate Security, Anti-Virus Plus, and Total Security before 14.2.0.253 allows local users
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.