Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,008cataloged exploits
34,638CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,662GitHub PoC 13,743VulnCheck XDB 8,460Nuclei 4,233Metasploit 3,467✓ verified onlyrecentpopularrisk
21,662 exploits
Referência
CVE-2014-2008
SQL injection vulnerability in confirm.php in the mPAY24 payment module before 1.6 for PrestaShop allows remote attacker
23RISK
open ↗Referência
CVE-2013-5317
Cross-site scripting (XSS) vulnerability in RiteCMS 1.0.0 allows remote authenticated users to inject arbitrary web scri
23RISK
open ↗Referência
CVE-2013-5317
Cross-site scripting (XSS) vulnerability in RiteCMS 1.0.0 allows remote authenticated users to inject arbitrary web scri
23RISK
open ↗Referência
CVE-2013-7194
Multiple cross-site scripting (XSS) vulnerabilities in www/administrator.php in eFront 3.6.14 (build 18012) allow remote
23RISK
open ↗Referência
CVE-2013-7194
Multiple cross-site scripting (XSS) vulnerabilities in www/administrator.php in eFront 3.6.14 (build 18012) allow remote
23RISK
open ↗Referência
CVE-2014-5276
Multiple cross-site scripting (XSS) vulnerabilities in Pro Chat Rooms Text Chat Rooms 8.2.0 allow remote authenticated u
23RISK
open ↗Referência
CVE-2017-16841
LanSweeper 6.0.100.75 has XSS via the description parameter to /Calendar/CalendarActions.aspx.
23RISK
open ↗Referência
CVE-2014-4162
Multiple cross-site request forgery (CSRF) vulnerabilities in the Zyxel P-660HW-T1 (v3) wireless router allow remote att
23RISK
open ↗Referência
CVE-2014-4162
Multiple cross-site request forgery (CSRF) vulnerabilities in the Zyxel P-660HW-T1 (v3) wireless router allow remote att
23RISK
open ↗Referência
CVE-2009-4224
Multiple PHP remote file inclusion vulnerabilities in SweetRice 0.5.4, 0.5.3, and earlier allow remote attackers to exec
23RISK
open ↗Referência
CVE-2009-4224
Multiple PHP remote file inclusion vulnerabilities in SweetRice 0.5.4, 0.5.3, and earlier allow remote attackers to exec
23RISK
open ↗Referência
CVE-2009-2231
MIDAS 1.43 allows remote attackers to bypass authentication and obtain administrative access via an admin account record
23RISK
open ↗Referência
CVE-2014-7281
Cross-site request forgery (CSRF) vulnerability in Shenzhen Tenda Technology Tenda A32 Router with firmware 5.07.53_CN a
23RISK
open ↗Referência
CVE-2014-7281
Cross-site request forgery (CSRF) vulnerability in Shenzhen Tenda Technology Tenda A32 Router with firmware 5.07.53_CN a
23RISK
open ↗Referência
CVE-2012-1900
Cross-site request forgery (CSRF) vulnerability in admin/index.php in RazorCMS 1.2.1 and earlier allows remote attackers
23RISK
open ↗Referência
CVE-2012-1900
Cross-site request forgery (CSRF) vulnerability in admin/index.php in RazorCMS 1.2.1 and earlier allows remote attackers
23RISK
open ↗Referência
CVE-2015-7865
nvSCPAPISvr.exe in the Stereoscopic 3D Driver Service in the NVIDIA GPU graphics driver R340 before 341.92, R352 before
23RISK
open ↗Referência
CVE-2015-7865
nvSCPAPISvr.exe in the Stereoscopic 3D Driver Service in the NVIDIA GPU graphics driver R340 before 341.92, R352 before
23RISK
open ↗Referência
CVE-2018-25080
MobileDetect Example session_example.php initLayoutType cross site scripting
28RISK
open ↗Referência
CVE-2009-4546
globepersonnel_login.asp in Logoshows BBS 2.0 allows remote attackers to bypass authentication and gain administrative a
23RISK
open ↗Referência✓ VexDay Proof
empris r20020923 - 'phormationdir' Remote File Inclusion
PHP remote file inclusion vulnerability in sql_fcnsOLD.php in Emergenices Personnel Information System (Empris) 20020923
23RISK
open ↗Referência✓ VexDay Proof
registroTL - 'main.php' Remote File Inclusion
registroTL stores sensitive information under the web root with insufficient access control, which allows remote attacke
23RISK
open ↗Referência✓ VexDay Proof
AS-GasTracker 1.0.0 - Insecure Cookie Handling
AustinSmoke GasTracker (AS-GasTracker) 1.0.0 allows remote attackers to bypass authentication and gain privileges by set
23RISK
open ↗Referência✓ VexDay Proof
phpscripts Ranking Script - Insecure Cookie Handling
phpscripts Ranking Script allows remote attackers to bypass authentication and gain administrative access by sending an
23RISK
open ↗Referência
CVE-2018-19041
The Media File Manager plugin 1.4.2 for WordPress allows XSS via the dir parameter of an mrelocator_getdir action to the
23RISK
open ↗Referência
CVE-2022-47877
A Stored cross-site scripting vulnerability in Jedox 2020.2.5 allows remote, authenticated users to inject arbitrary web
48RISK
open ↗Referência
CVE-2017-12971
Cross-site scripting (XSS) vulnerability in Apache2Triad 1.5.4 allows remote attackers to inject arbitrary web script or
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.