Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
75,902cataloged exploits
34,597CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,624GitHub PoC 13,727VulnCheck XDB 8,410Nuclei 4,231Metasploit 3,467✓ verified onlyrecentpopularrisk
21,624 exploits
Referência✓ VexDay Proof
RevilloC MailServer 1.x - 'RCPT TO' Remote Denial of Service
Multiple heap-based buffer overflows in RevilloC MailServer 1.21 and earlier allow remote attackers to cause a denial of
23RISK
open ↗Referência✓ VexDay Proof
OpenH323 Opal SIP Protocol - Remote Denial of Service
The Open Phone Abstraction Library (opal), as used by (1) Ekiga before 2.0.10 and (2) OpenH323 before 2.2.4, allows remo
28RISK
open ↗Referência
CVE-2014-9349
Multiple cross-site scripting (XSS) vulnerabilities in admin/robots.lib.php in RobotStats 1.0 allow remote attackers to
23RISK
open ↗Referência
CVE-2014-9349
Multiple cross-site scripting (XSS) vulnerabilities in admin/robots.lib.php in RobotStats 1.0 allow remote attackers to
23RISK
open ↗Referência
CVE-2010-1341
SQL injection vulnerability in index.php in Systemsoftware Community Black Forum allows remote attackers to execute arbi
23RISK
open ↗Referência
CVE-2018-12520
An issue was discovered in ntopng 3.4 before 3.4.180617. The PRNG involved in the generation of session IDs is not seede
28RISK
open ↗Referência
CVE-2012-0407
Integer overflow in the DPA_Utilities library in EMC Data Protection Advisor (DPA) 5.5 through 5.8 SP1 allows remote att
23RISK
open ↗Referência
CVE-2015-5999
Multiple cross-site request forgery (CSRF) vulnerabilities in the D-Link DIR-816L Wireless Router with firmware before 2
23RISK
open ↗Referência
CVE-2015-5999
Multiple cross-site request forgery (CSRF) vulnerabilities in the D-Link DIR-816L Wireless Router with firmware before 2
23RISK
open ↗Referência✓ VexDay Proof
SysInfo 1.21 - 'sysinfo.cgi' Remote Command Execution
sysinfo.cgi in sysinfo 1.21 allows remote attackers to obtain the installation path via the debugger action.
23RISK
open ↗Referência
CVE-2019-1010124
WebAppick WooCommerce Product Feed 2.2.18 and earlier is affected by: Cross Site Scripting (XSS). The impact is: XSS to
23RISK
open ↗Referência✓ VexDay Proof
Lms 1.8.9 - Vala Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in LAN Management System (LMS) 1.8.9 Vala and earlier allow remote at
28RISK
open ↗Referência
CVE-2018-17376
SQL Injection exists in the Reverse Auction Factory 4.3.8 component for Joomla! via the filter_order_Dir, cat, or filter
23RISK
open ↗Referência
CVE-2018-17376
SQL Injection exists in the Reverse Auction Factory 4.3.8 component for Joomla! via the filter_order_Dir, cat, or filter
23RISK
open ↗Referência
CVE-2018-17377
SQL Injection exists in the Questions 1.4.3 component for Joomla! via the term, userid, users, or groups parameter.
23RISK
open ↗Referência
CVE-2018-6947
An uninitialised stack variable in the nxfuse component that is part of the Open Source DokanFS library shipped with NoM
23RISK
open ↗Referência
CVE-2018-6947
An uninitialised stack variable in the nxfuse component that is part of the Open Source DokanFS library shipped with NoM
23RISK
open ↗Referência✓ VexDay Proof
Focus/SIS 1.0/2.2 - Remote File Inclusion
PHP remote file inclusion vulnerability in modules/Discipline/CategoryBreakdownTime.php in Focus/SIS 1.0 allows remote a
23RISK
open ↗Referência
CVE-2018-17382
SQL Injection exists in the Jobs Factory 2.0.4 component for Joomla! via the filter_letter parameter.
23RISK
open ↗Referência
CVE-2018-17382
SQL Injection exists in the Jobs Factory 2.0.4 component for Joomla! via the filter_letter parameter.
23RISK
open ↗Referência
CVE-2018-18763
SaltOS 3.1 r8126 allows action=ajax&query=numbers&page=usuarios&action2=[SQL] SQL Injection.
23RISK
open ↗Referência✓ VexDay Proof
Fuju News 1.0 - Authentication Bypass / SQL Injection
SQL injection vulnerability in archiv2.php in Fuju News 1.0 allows remote attackers to execute arbitrary SQL commands vi
23RISK
open ↗Referência
CVE-2021-26929
An XSS issue was discovered in Horde Groupware Webmail Edition through 5.2.22 (where the Horde_Text_Filter library befor
23RISK
open ↗Referência
CVE-2021-26929
An XSS issue was discovered in Horde Groupware Webmail Edition through 5.2.22 (where the Horde_Text_Filter library befor
23RISK
open ↗Referência✓ VexDay Proof
D-Bus Daemon < 1.2.4 - 'libdbus' Denial of Service
The dbus_signature_validate function in the D-bus library (libdbus) before 1.2.4 allows remote attackers to cause a deni
23RISK
open ↗Referência
CVE-2023-39026
Directory Traversal vulnerability in FileMage Gateway Windows Deployments v.1.10.8 and before allows a remote attacker t
43RISK
open ↗Referência
CVE-2020-6756
languageOptions.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows unauthenticated attackers to re
53RISK
open ↗Referência
CVE-2021-27370
The Contact page in Monica 2.19.1 allows stored XSS via the Last Name field.
23RISK
open ↗Referência
CVE-2015-6568
Wolf CMS before 0.8.3.1 allows unrestricted file rename and PHP Code Execution because admin/plugin/file_manager/browse/
28RISK
open ↗Referência
CVE-2015-6568
Wolf CMS before 0.8.3.1 allows unrestricted file rename and PHP Code Execution because admin/plugin/file_manager/browse/
28RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.