Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,008cataloged exploits
34,638CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,662GitHub PoC 13,743VulnCheck XDB 8,460Nuclei 4,233Metasploit 3,467✓ verified onlyrecentpopularrisk
21,662 exploits
Referência
Authenticated low-privileged RCE in Coolify via unsanitized shell commands in the Git Repository field.
Coolify Git Repository Field Command Injection in Project Deployment Workflow
48RISK
open ↗Referência
CVE-2015-2275
Cross-site scripting (XSS) vulnerability in WoltLab Community Gallery 2.0 before 2014-12-26 allows remote attackers to i
23RISK
open ↗Referência
CVE-2015-2275
Cross-site scripting (XSS) vulnerability in WoltLab Community Gallery 2.0 before 2014-12-26 allows remote attackers to i
23RISK
open ↗Referência
X.Org X Server 1.20.4 - Local Stack Overflow
"" In X.Org X Server 1.20.4, there is a stack-based buffer overflow in the function XQueryKeymap. For example, by sendin
23RISK
open ↗Referência
BSA Radar 1.6.7234.24750 - Persistent Cross-Site Scripting
The Firstname and Lastname parameters in Global RADAR BSA Radar 1.6.7234.24750 and earlier are vulnerable to stored cros
23RISK
open ↗Referência
CVE-2022-39285
Stored Cross-Site Scripting Vulnerability In File Parameter in zoneminder
41RISK
open ↗Referência
CVE-2015-1028
Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2730B router (rev C1) with firmware GE_1.01 allow remo
23RISK
open ↗Referência
CVE-2020-14943
The Firstname and Lastname parameters in Global RADAR BSA Radar 1.6.7234.24750 and earlier are vulnerable to stored cros
23RISK
open ↗Referência
CVE-2006-4853
SQL injection vulnerability in kategorix.asp in Haberx 1.02 through 1.1 allows remote attackers to execute arbitrary SQL
23RISK
open ↗Referência✓ VexDay Proof
Neon Labs Website 3.2 - 'nl.php?g_strRootDir' Remote File Inclusion
PHP remote file inclusion vulnerability in lib/nl/nl.php in Neon Labs Website (nlws) 3.2 and earlier allows remote attac
23RISK
open ↗Referência✓ VexDay Proof
TeamCalPro 3.1.000 - Multiple Local/Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in TeamCal Pro 3.1.000 and earlier allow remote attackers to execute
23RISK
open ↗Referência✓ VexDay Proof
Ultra Office - ActiveX Control Arbitrary File Corruption
The Ultra.OfficeControl ActiveX control in OfficeCtrl.ocx 2.0.2008.801 and earlier in Ultra Shareware Ultra Office Contr
23RISK
open ↗Referência✓ VexDay Proof
Pixie CMS - Cross-Site Scripting / SQL Injection
Cross-site scripting (XSS) vulnerability in index.php in Pixie CMS 1.01a allows remote attackers to inject arbitrary web
23RISK
open ↗Referência
CVE-2014-0870
Multiple cross-site scripting (XSS) vulnerabilities in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 be
23RISK
open ↗Referência
CVE-2017-9095
XXE in Diving Log 6.0 allows attackers to remotely view local files through a crafted dive.xml file that is mishandled d
23RISK
open ↗Referência✓ VexDay Proof
pafileDB 2.0.1 - 'mxBB'/'phpBB' Remote File Inclusion
PHP remote file inclusion vulnerability in pafiledb_constants.php in Download Manager (mxBB pafiledb) integration, as us
23RISK
open ↗Referência
CVE-2007-2373
SQL injection vulnerability in viewcat.php in the WF-Links (wflinks) 1.03 and earlier module for XOOPS allows remote att
23RISK
open ↗Referência
CVE-2019-0735
An elevation of privilege vulnerability exists when the Windows Client Server Run-Time Subsystem (CSRSS) fails to proper
23RISK
open ↗Referência
CVE-2016-7188
The Standard Collector Service in Windows Diagnostics Hub in Microsoft Windows 10 Gold, 1511, and 1607 mishandles librar
23RISK
open ↗Referência
CVE-2016-0093
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, W
23RISK
open ↗Referência
CVE-2016-0094
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, W
23RISK
open ↗Referência
CVE-2017-17062
The backend component in Open-Xchange OX App Suite before 7.6.3-rev35, 7.8.x before 7.8.2-rev38, 7.8.3 before 7.8.3-rev4
23RISK
open ↗Referência
CVE-2017-17062
The backend component in Open-Xchange OX App Suite before 7.6.3-rev35, 7.8.x before 7.8.2-rev38, 7.8.3 before 7.8.3-rev4
23RISK
open ↗Referência✓ VexDay Proof
Microsoft Windows - DHCP Client Broadcast (MS06-036)
Buffer overflow in the DHCP Client service for Microsoft Windows 2000 SP4, Windows XP SP1 and SP2, and Server 2003 up to
45RISK
open ↗Referência
CVE-2017-17612
Hot Scripts Clone 3.1 has SQL Injection via the /categories subctid or mctid parameter.
23RISK
open ↗Referência
CVE-2017-17612
Hot Scripts Clone 3.1 has SQL Injection via the /categories subctid or mctid parameter.
23RISK
open ↗Referência
CVE-2017-17612
Hot Scripts Clone 3.1 has SQL Injection via the /categories subctid or mctid parameter.
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.