Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,008cataloged exploits
34,638CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,662GitHub PoC 13,743VulnCheck XDB 8,460Nuclei 4,233Metasploit 3,467✓ verified onlyrecentpopularrisk
21,662 exploits
Referência
CVE-2011-4832
Directory traversal vulnerability in CaupoShop Pro 2.x, CaupoShop Classic 3.01, and CaupoShop Pro 3.70 and earlier allow
23RISK
open ↗Referência✓ VexDay Proof
Integramod Portal 2.x - 'functions_portal.php' Remote File Inclusion
Absolute path traversal vulnerability in includes/functions_portal.php in IntegraMOD Portal 2.x and earlier, when magic_
23RISK
open ↗Referência✓ VexDay Proof
WinFTP Server 2.0.2 - 'PASV' Remote Denial of Service
WinFtp Server 2.0.2 allows remote attackers to cause a denial of service (crash) via long (1) PASV, (2) LIST, (3) USER,
23RISK
open ↗Referência✓ VexDay Proof
TLM CMS 1.1 - 'i-accueil.php?chemin' Remote File Inclusion
PHP remote file inclusion vulnerability in i-accueil.php in TLM CMS 1.1 and earlier allows remote attackers to execute a
23RISK
open ↗Referência✓ VexDay Proof
CS-Gallery 2.0 - 'index.php?album' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in Christian Schneider CS-Gallery 2.0 and earlier allows remote att
23RISK
open ↗Referência✓ VexDay Proof
JChit counter 1.0.0 - 'imgsrv.php?ac' Remote File Disclosure
Directory traversal vulnerability in imgsrv.php in jchit counter 1.0.0 allows remote attackers to read arbitrary files v
23RISK
open ↗Referência✓ VexDay Proof
MiniWeb HTTP Server 0.8.x - Remote Denial of Service
http.c in MiniWeb Http Server 0.8.x allows remote attackers to cause a denial of service (application crash) via a negat
23RISK
open ↗Referência✓ VexDay Proof
Picturesolution 2.1 - 'config.php?path' Remote File Inclusion
PHP remote file inclusion vulnerability in install/config.php in Picturesolution 2.1 and earlier allows remote attackers
23RISK
open ↗Referência✓ VexDay Proof
kontakt formular 1.4 - Remote File Inclusion
PHP remote file inclusion vulnerability in includes/function.php in Kontakt Formular 1.4 allows remote attackers to exec
23RISK
open ↗Referência✓ VexDay Proof
Admidio 1.4.8 - 'getfile.php' Remote File Disclosure
Directory traversal vulnerability in modules/download/get_file.php in Admidio 1.4.8 allows remote attackers to read arbi
23RISK
open ↗Referência✓ VexDay Proof
ibase 2.03 - Remote File Disclosure
Directory traversal vulnerability in download.php in Interface Medien ibase 2.03 and earlier allows remote attackers to
23RISK
open ↗Referência✓ VexDay Proof
Quick 'n Easy Mail Server 3.3 (Demo) - Remote Denial of Service (PoC)
Pablo Software Solutions Quick 'n Easy Mail Server 3.3 allows remote attackers to cause a denial of service (daemon outa
23RISK
open ↗Referência✓ VexDay Proof
vidshare pro - SQL Injection / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in search.php in VidSharePro allows remote attackers to inject arbitrary web sc
23RISK
open ↗Referência
OpenCart 3.0.3.6 - 'subject' Stored Cross-Site Scripting
OpenCart 3.0.3.6 is affected by cross-site scripting (XSS) in the Subject field of mail. This vulnerability can allow an
23RISK
open ↗Referência
CVE-2015-5075
Cross-site request forgery (CSRF) vulnerability in X2Engine X2CRM before 5.2 allows remote attackers to hijack the authe
23RISK
open ↗Referência
CVE-2015-5075
Cross-site request forgery (CSRF) vulnerability in X2Engine X2CRM before 5.2 allows remote attackers to hijack the authe
23RISK
open ↗Referência
CVE-2009-4809
Directory traversal vulnerability in thumbnail.ghp in Easy File Sharing (EFS) Web Server 4.8 allows remote attackers to
23RISK
open ↗Referência
CVE-2018-10619
An unquoted search path or element in RSLinx Classic Versions 3.90.01 and prior and FactoryTalk Linx Gateway Versions 3.
23RISK
open ↗Referência
CVE-2010-2848
Directory traversal vulnerability in assets/captcha/includes/alikon/playcode.php in the InterJoomla ArtForms (com_artfor
23RISK
open ↗Referência
CVE-2010-2848
Directory traversal vulnerability in assets/captcha/includes/alikon/playcode.php in the InterJoomla ArtForms (com_artfor
23RISK
open ↗Referência
CVE-2011-5026
Cross-site scripting (XSS) vulnerability in the addPost function in data/functions.php in Winn GuestBook before 2.4.8d a
23RISK
open ↗Referência
CVE-2018-2698
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th
23RISK
open ↗Referência
CVE-2011-4803
SQL injection vulnerability in wptouch/ajax.php in the WPTouch plugin for WordPress allows remote attackers to execute a
23RISK
open ↗Referência
CVE-2013-5757
Absolute path traversal vulnerability in Yealink VoIP Phone SIP-T38G allows remote authenticated users to read arbitrary
23RISK
open ↗Referência
CVE-2017-7725
concrete5 8.1.0 places incorrect trust in the HTTP Host header during caching, if the administrator did not define a "ca
23RISK
open ↗Referência
CVE-2017-7725
concrete5 8.1.0 places incorrect trust in the HTTP Host header during caching, if the administrator did not define a "ca
23RISK
open ↗Referência✓ VexDay Proof
CzarNews 1.14 - 'tpath' Remote File Inclusion
PHP remote file inclusion vulnerability in CzarNews 1.12 through 1.14 allows remote attackers to execute arbitrary PHP c
23RISK
open ↗Referência✓ VexDay Proof
phpQuiz 0.1.2 - SQL Injection / Code Execution
Direct static code injection vulnerability in cfgphpquiz/install.php in Walter Beschmout PhpQuiz 1.2 and earlier allows
23RISK
open ↗Referência✓ VexDay Proof
netForo! 0.1 - 'down.php?file_to_download' Remote File Disclosure
Directory traversal vulnerability in down.php in netForo! 0.1g allows remote attackers to read arbitrary files via a ..
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.