Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,313cataloged exploits
34,834CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,797GitHub PoC 13,885VulnCheck XDB 8,484Nuclei 4,237Metasploit 3,467✓ verified onlyrecentpopularrisk
21,797 exploits
Referência
CVE-2014-3220
F5 BIG-IQ Cloud and Security 4.0.0 through 4.1.0 allows remote authenticated users to change the password of arbitrary u
28RISK
open ↗Referência
CVE-2021-24405
Easy Cookie Policy <= 1.6.2 - Broken Access Control to Stored Cross-Site Scripting
28RISK
open ↗Referência✓ VexDay Proof
Web Content System 2.7.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in manage/javascript/formjavascript.php in Ay System Solutions Web Content Syste
23RISK
open ↗Referência
CVE-2025-7097
Comodo Internet Security Premium Manifest File cis_update_x64.xml os command injection
48RISK
open ↗Referência
CVE-2025-7097
Comodo Internet Security Premium Manifest File cis_update_x64.xml os command injection
48RISK
open ↗Referência
CVE-2026-15231
TaxoPress < 3.51.0 - Contributor+ Private Post Disclosure via IDOR
28RISK
open ↗Referência
CVE-2018-12052
SQL Injection exists in PHP Scripts Mall Schools Alert Management Script via the q Parameter in get_sec.php.
23RISK
open ↗Referência
CVE-2026-14557
SoftMarket <= 1.0.0 - Unauthenticated Account Takeover via Email Verification Bypass
48RISK
open ↗Referência✓ VexDay Proof
Adobe JRun 4 - 'logfile' (Authenticated) Directory Traversal
Directory traversal vulnerability in logging/logviewer.jsp in the Management Console in Adobe JRun Application Server 4
23RISK
open ↗Referência
CVE-2024-23749
KiTTY versions 0.76.1.13 and before is vulnerable to command injection via the filename variable, occurs due to insuffic
41RISK
open ↗Referência✓ VexDay Proof
eFront 3.5.1 / build 2710 - Arbitrary File Upload
Unrestricted file upload vulnerability in filesystem3.class.php in eFront 3.5.1 build 2710 and earlier allows remote att
23RISK
open ↗Referência
CVE-2026-13340
SVG Support < 2.5.17 - Author+ Stored XSS via .svgz Sanitization Bypass
33RISK
open ↗Referência
CVE-2019-11537
In osTicket before 1.12, XSS exists via /upload/file.php, /upload/scp/users.php?do=import-users, and /upload/scp/ajax.ph
23RISK
open ↗Referência
CVE-2026-14214
Amelia < 2.4.4 - Amelia Manager+ Arbitrary User-Field Modification via Mass Assignment
23RISK
open ↗Referência
CVE-2026-14195
Brizy – Page Builder < 2.8.18 - Contributor+ Sensitive Information Disclosure via get_post_info
23RISK
open ↗Referência
CVE-2018-18804
Bakeshop Inventory System 1.0 has SQL injection via the login screen, related to include/publicfunction.vb.
23RISK
open ↗Referência
CVE-2018-18804
Bakeshop Inventory System 1.0 has SQL injection via the login screen, related to include/publicfunction.vb.
23RISK
open ↗Referência
CVE-2026-13729
Podlove Podcast Publisher < 4.5.3 - Podcast Contributor/Group/Role Creation and Deletion via CSRF
23RISK
open ↗Referência
CVE-2018-13045
SQL injection vulnerability in the "Bazar" page in Yeswiki Cercopitheque 2018-06-19-1 and earlier allows attackers to ex
23RISK
open ↗Referência
CVE-2018-13045
SQL injection vulnerability in the "Bazar" page in Yeswiki Cercopitheque 2018-06-19-1 and earlier allows attackers to ex
23RISK
open ↗Referência
CVE-2026-13725
Dynamic Pricing With Discount Rules for WooCommerce < 5.0.0 - Reflected XSS via wdpAjax
23RISK
open ↗Referência✓ VexDay Proof
Cmaps v8.0 - SQL injection
SQL injection vulnerability found in Maximilian Vogt companymaps (cmaps) v.8.0 allows a remote attacker to execute arbit
53RISK
open ↗Referência
CVE-2014-9331
Cross-site request forgery (CSRF) vulnerability in ZOHO ManageEngine Desktop Central before 9 build 90130 allows remote
23RISK
open ↗Referência
CVE-2014-9331
Cross-site request forgery (CSRF) vulnerability in ZOHO ManageEngine Desktop Central before 9 build 90130 allows remote
23RISK
open ↗Referência
CVE-2026-13604
Pixelavo < 1.5.4 - Unauthenticated Facebook CAPI Event Injection via pixelavo_event AJAX
23RISK
open ↗Referência
CVE-2017-6552
Livebox 3 Sagemcom SG30_sip-fr-5.15.8.1 devices have an insufficiently large default value for the maximum IPv6 routing
23RISK
open ↗Referência✓ VexDay Proof
Fuju News 1.0 - Authentication Bypass / SQL Injection
edit_kategorie.php in Fuju News 1.0 allows remote attackers to bypass authentication by setting the authorized cookie.
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.