Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,313cataloged exploits
34,834CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,797GitHub PoC 13,885VulnCheck XDB 8,484Nuclei 4,237Metasploit 3,467✓ verified onlyrecentpopularrisk
21,797 exploits
Referência
CVE-2017-7938
Stack-based buffer overflow in DMitry (Deepmagic Information Gathering Tool) version 1.3a (Unix) allows attackers to cau
33RISK
open ↗Referência
CVE-2014-0865
RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics relies on client-
23RISK
open ↗Referência
CVE-2019-15742
A local privilege-escalation vulnerability exists in the Poly Plantronics Hub before 3.14 for Windows client application
38RISK
open ↗Referência
CVE-2018-4206
An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. macOS before 10.13.4 Security Update 2
23RISK
open ↗Referência
CVE-2018-6410
An issue was discovered in Appnitro MachForm before 4.2.3. There is a download.php SQL injection via the q parameter.
23RISK
open ↗Referência
CVE-2006-3362
Unrestricted file upload vulnerability in connectors/php/connector.php in FCKeditor mcpuk file manager, as used in (1) G
23RISK
open ↗Referência
CVE-2023-22629
An issue was discovered in TitanFTP through 1.94.1205. The move-file function has a path traversal vulnerability in the
61RISK
open ↗Referência
CVE-2016-6174
applications/core/modules/front/system/content.php in Invision Power Services IPS Community Suite (aka Invision Power Bo
28RISK
open ↗Referência
CVE-2025-34087
Pi-Hole AdminLTE Whitelist (now 'Web Allowlist') Remote Command Execution
63RISK
open ↗Referência
CVE-2025-34087
Pi-Hole AdminLTE Whitelist (now 'Web Allowlist') Remote Command Execution
63RISK
open ↗Referência
CVE-2019-6498
GattLib 0.2 has a stack-based buffer over-read in gattlib_connect in dbus/gattlib.c because strncpy is misused.
23RISK
open ↗Referência✓ VexDay Proof
XChat 2.6.7 (Windows) - Remote Denial of Service
Unspecified vulnerability in Xchat 2.6.7 and earlier allows remote attackers to cause a denial of service (crash) via un
23RISK
open ↗Referência
CVE-2009-3808
MixSense DJ Studio 1.0.0.1 allows remote attackers to cause a denial of service (application crash) and possibly execute
23RISK
open ↗Referência✓ VexDay Proof
Mambo Module MambWeather 1.8.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in Savant2/Savant2_Plugin_options.php in the MambWeather 1.8.1 and earlier compo
23RISK
open ↗Referência✓ VexDay Proof
Enigma 2 Coppermine Bridge - 'boarddir' Remote File Inclusion
PHP remote file inclusion vulnerability in E2_header.inc.php in Enigma2 Coppermine Bridge 1.0 allows remote attackers to
23RISK
open ↗Referência✓ VexDay Proof
GNU/Linux mbse-bbs 0.70.0 - Local Buffer Overflow
Stack-based buffer overflow in mbse-bbs 0.70 and earlier allows local users to execute arbitrary code via a long string
23RISK
open ↗Referência✓ VexDay Proof
XM Easy Personal FTP Server 5.30 - 'ABOR' Format String Denial of Service
Multiple buffer overflows in XM Easy Personal FTP Server 5.3.0 allow remote attackers to execute arbitrary code via unsp
23RISK
open ↗Referência
CVE-2016-9566
base/logging.c in Nagios Core before 4.2.4 allows local users with access to an account in the nagios group to gain root
23RISK
open ↗Referência
CVE-2018-7704
SecurEnvoy SecurMail before 9.2.501 allows remote authenticated users to read arbitrary e-mail messages via the option1
23RISK
open ↗Referência
CVE-2026-18645
danpros HTMLy Admin Content Endpoint admin.php add_content path traversal
30RISK
open ↗Referência
CVE-2026-18644
danpros HTMLy Delete Username Endpoint htmly.php unlink path traversal
30RISK
open ↗Referência
CVE-2026-18641
Sangfor Operation and Maintenance Security Management System Login Endpoint portal_login com.sbr.fort.foreignDP.DpLoginController os command injection
30RISK
open ↗Referência
CVE-2026-18632
langgenius dify Jinja2 jinja2_transformer.py jinja2.Template special elements used in a template engine
30RISK
open ↗Referência
CVE-2026-18631
jeequan jeepay PreAuthorize SysLogController.java WebSecurityConfig authorization
30RISK
open ↗Referência
CVE-2026-67599
ClearOS 7.9 OS Command Injection via Log Viewer filter parameter
38RISK
open ↗Referência
CVE-2026-18616
GL-iNet GL-MT3000 wg-server.so Native Plugin glc server.set_peer command injection
45RISK
open ↗Referência
CVE-2011-5148
Multiple incomplete blacklist vulnerabilities in the Simple File Upload (mod_simplefileuploadv1.3) module before 1.3.5 f
23RISK
open ↗Referência
CVE-2018-9128
DVD X Player Standard 5.5.3.9 has a Buffer Overflow via a crafted .plf file, a related issue to CVE-2007-3068.
23RISK
open ↗Referência
CVE-2018-9128
DVD X Player Standard 5.5.3.9 has a Buffer Overflow via a crafted .plf file, a related issue to CVE-2007-3068.
23RISK
open ↗Referência
CVE-2018-9128
DVD X Player Standard 5.5.3.9 has a Buffer Overflow via a crafted .plf file, a related issue to CVE-2007-3068.
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.