Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,313cataloged exploits
34,834CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,797GitHub PoC 13,885VulnCheck XDB 8,484Nuclei 4,237Metasploit 3,467✓ verified onlyrecentpopularrisk
21,797 exploits
Referência
CVE-2009-3213
Stack-based buffer overflow in broid 1.0 Beta 3a allows remote attackers to cause a denial of service (application crash
23RISK
open ↗Referência
CVE-2013-2577
Buffer overflow in XnView before 2.04 allows remote attackers to execute arbitrary code via a crafted PCT file.
28RISK
open ↗Referência
CVE-2010-3591
Unspecified vulnerability in the Oracle Document Capture component in Oracle Fusion Middleware 10.1.3.4 and 10.1.3.5 all
28RISK
open ↗Referência
CVE-2019-8925
An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. An Absolute Path Traversal vulnerabi
28RISK
open ↗Referência
CVE-2019-8925
An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. An Absolute Path Traversal vulnerabi
28RISK
open ↗Referência✓ VexDay Proof
Mambo Component com_loudmouth 4.0j - Remote File Inclusion
PHP remote file inclusion vulnerability in includes/abbc/abbc.class.php in the LoudMouth Component for Mambo 4.0j, and p
23RISK
open ↗Referência
eBrigade ERP 4.5 - Arbitrary File Download
eBrigade through 4.5 allows Arbitrary File Download via ../ directory traversal in the showfile.php file parameter, as d
23RISK
open ↗Referência
CVE-2016-1846
The nvCommandQueue::GetHandleIndex method in the NVIDIA Graphics Drivers subsystem in Apple OS X before 10.11.5 allows a
23RISK
open ↗Referência
CVE-2016-1846
The nvCommandQueue::GetHandleIndex method in the NVIDIA Graphics Drivers subsystem in Apple OS X before 10.11.5 allows a
23RISK
open ↗Referência
CVE-2017-11333
The vorbis_analysis_wrote function in lib/block.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial
23RISK
open ↗Referência
CVE-2009-3535
Directory traversal vulnerability in image.php in Clear Content 1.1 allows remote attackers to read arbitrary files via
23RISK
open ↗Referência
CVE-2009-3535
Directory traversal vulnerability in image.php in Clear Content 1.1 allows remote attackers to read arbitrary files via
23RISK
open ↗Referência
CVE-2014-8375
SQL injection vulnerability in GBgallery.php in the GB Gallery Slideshow plugin 1.5 for WordPress allows remote administ
23RISK
open ↗Referência✓ VexDay Proof
MiniBB keyword_replacer 1.0 - 'pathToFiles' File Inclusion
PHP remote file inclusion vulnerability in addon_keywords.php in Keyword Replacer (keyword_replacer) 1.0 and earlier, a
23RISK
open ↗Referência
CVE-2018-1123
procps-ng before version 3.3.15 is vulnerable to a denial of service in ps via mmap buffer overflow. Inbuilt protection
28RISK
open ↗Referência
CVE-2026-67612
OpenEMR 8.2.0 Stored XSS via import_template.php Template Management
30RISK
open ↗Referência✓ VexDay Proof
PHPbbBook 1.3 - 'bbcode.php?l' Local File Inclusion
Directory traversal vulnerability in bbcode.php in PHPbbBook 1.3 and 1.3h allows remote attackers to include and execute
23RISK
open ↗Referência
CVE-2016-1610
Directory traversal vulnerability in the email-template feature in Novell Filr before 1.2 Security Update 3 and 2.0 befo
28RISK
open ↗Referência
CVE-2026-67611
OpenEMR 8.2.0 OAuth2 Password Grant Authentication Bypass via SMART Configuration
38RISK
open ↗Referência✓ VexDay Proof
RunCMS 1.5.2 - 'debug_show.php' SQL Injection
SQL injection vulnerability in class/debug/debug_show.php in RunCms 1.5.2 and earlier allows remote attackers to execute
23RISK
open ↗Referência✓ VexDay Proof
Elecard AVC HD Player - '.XPL' Stack Buffer Overflow (SEH) (PoC)
Stack-based buffer overflow in Elecard AVC HD Player allows remote attackers to execute arbitrary code via a long MP3 fi
23RISK
open ↗Referência
CVE-2009-4757
Stack-based buffer overflow in BrotherSoft EW-MusicPlayer 0.8 allows remote attackers to cause a denial of service (appl
23RISK
open ↗Referência
CVE-2026-67610
OpenEMR 8.2.0 OAuth2 Dynamic Client Registration Unauthorized FHIR Access
38RISK
open ↗Referência
CVE-2026-18605
CheckMAL AppCheck Pro Kernel Mini-Filter Driver AppCheckD.sys uncontrolled search path
38RISK
open ↗Referência✓ VexDay Proof
QuickTicket 1.5 - 'qti_usr.php' SQL Injection
Multiple SQL injection vulnerabilities in QuickTicket 1.2 build:20070621 and QuickTalk Forum 1.3 allow remote attackers
23RISK
open ↗Referência✓ VexDay Proof
Microsoft Visual 6 - 'VDT70.dll NotSafe' Remote Stack Overflow
Stack-based buffer overflow in a certain ActiveX control in VDT70.DLL in Microsoft Visual Database Tools Database Design
28RISK
open ↗Referência
CVE-2026-39932
OpenEMR 8.2.0 Remote Code Execution via CategoryTree eval() Injection
45RISK
open ↗Referência
CVE-2026-18601
GL.iNet GL-MT3000 ovpn-client.so Native Plugin glc ovpn-client.check_config command injection
45RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.