Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,008cataloged exploits
34,638CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,662GitHub PoC 13,743VulnCheck XDB 8,460Nuclei 4,233Metasploit 3,467✓ verified onlyrecentpopularrisk
21,662 exploits
Referência
CVE-2010-2922
SQL injection vulnerability in default.asp in AKY Blog allows remote attackers to execute arbitrary SQL commands via the
23RISK
open ↗Referência
CVE-2010-4865
SQL injection vulnerability in the JE Guestbook (com_jeguestbook) component 1.0 for Joomla! allows remote attackers to e
23RISK
open ↗Referência✓ VexDay Proof
Electronic Engineering Tool (EE TOOL) 0.4.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in ip.inc.php in Electronic Engineering Tool (EE Tool) 0.4-1 and earlier allows
23RISK
open ↗Referência✓ VexDay Proof
gtcatalog 0.9.1 - 'index.php' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in Chris Mac gtcatalog (aka GimeScripts Shopping Catalog) 0.9.1 and
23RISK
open ↗Referência✓ VexDay Proof
MySource CMS 2.16.2 - 'init_mysource.php' Remote File Inclusion
PHP remote file inclusion vulnerability in web/init_mysource.php in MySource CMS 2.16.2 and earlier allows remote attack
23RISK
open ↗Referência✓ VexDay Proof
CNStats 2.9 - 'who_r.php?bj' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in CNStats 2.9 allow remote attackers to execute arbitrary PHP code v
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component MosReporter 0.9.3 - Remote File Inclusion
PHP remote file inclusion vulnerability in reporter.logic.php in the MosReporter (com_reporter) component for Mambo and
23RISK
open ↗Referência✓ VexDay Proof
Flip 3.0 - Remote Admin Creation
account.php in Adam Scheinberg Flip 3.0 and earlier allows remote attackers to create administrative accounts via the un
23RISK
open ↗Referência✓ VexDay Proof
Verlihub Control Panel 1.7.x - Local File Inclusion
Directory traversal vulnerability in index.php in Verlihub Control Panel (VHCP) 1.7 and earlier allows remote attackers
23RISK
open ↗Referência✓ VexDay Proof
Artmedic CMS 3.4 - 'index.php' Local File Inclusion
Directory traversal vulnerability in index.php in Artmedic CMS 3.4 and earlier allows remote attackers to include and ex
23RISK
open ↗Referência✓ VexDay Proof
UploadImage/UploadScript 1.0 - Remote Change Admin Password
admin.php in UploadImage 1.0 does not check for the original password before making a change to a new password, which al
23RISK
open ↗Referência✓ VexDay Proof
Chipmunk Blog - (Authentication Bypass) Add Admin
Chipmunk Blogger Script allows remote attackers to gain administrator privileges via a direct request to admin/reguser.p
23RISK
open ↗Referência✓ VexDay Proof
Syntax Desktop 2.7 - 'synTarget' Local File Inclusion
Directory traversal vulnerability in admin/modules/aa/preview.php in Syntax Desktop 2.7 allows remote attackers to inclu
23RISK
open ↗Referência✓ VexDay Proof
Catviz 0.4.0 beta1 - Local File Inclusion / Cross-Site Scripting
Multiple directory traversal vulnerabilities in index.php in Catviz 0.4.0 Beta 1 allow remote attackers to read arbitrar
23RISK
open ↗Referência
CVE-2018-13134
TP-Link Archer C1200 1.13 Build 2018/01/24 rel.52299 EU devices have XSS via the PATH_INFO to the /webpages/data URI.
23RISK
open ↗Referência
CVE-2010-2923
SQL injection vulnerability in the YouTube (com_youtube) component 1.5 for Joomla! allows remote attackers to execute ar
23RISK
open ↗Referência
Printix Client 1.3.1106.0 - Remote Code Execution (RCE)
Printix Secure Cloud Print Management through 1.3.1106.0 incorrectly uses Privileged APIs to modify values in HKEY_LOCAL
28RISK
open ↗Referência
CVE-2017-10033
Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Support Tools). Support
23RISK
open ↗Referência
CVE-2014-3216
GOM Media Player 2.2.57.5189 and earlier allows remote attackers to cause a denial of service (crash) via a crafted .ogg
23RISK
open ↗Referência
CVE-2010-2923
SQL injection vulnerability in the YouTube (com_youtube) component 1.5 for Joomla! allows remote attackers to execute ar
23RISK
open ↗Referência
CVE-2014-4699
The Linux kernel before 3.15.4 on Intel processors does not properly restrict use of a non-canonical value for the saved
23RISK
open ↗Referência
CVE-2014-4699
The Linux kernel before 3.15.4 on Intel processors does not properly restrict use of a non-canonical value for the saved
23RISK
open ↗Referência
CVE-2018-17313
On the RICOH MP C307 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding a
23RISK
open ↗Referência
CVE-2018-17310
On the RICOH MP C1803 JPN printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of add
23RISK
open ↗Referência
CVE-2018-17310
On the RICOH MP C1803 JPN printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of add
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.