Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,313cataloged exploits
34,834CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,797GitHub PoC 13,885VulnCheck XDB 8,484Nuclei 4,237Metasploit 3,467✓ verified onlyrecentpopularrisk
21,797 exploits
Referência
CVE-2018-5974
SQL Injection exists in the SimpleCalendar 3.1.9 component for Joomla! via the catid array parameter.
23RISK
open ↗Referência
CVE-2026-13390
The Events Calendar < 6.16.5.1 - Unauthenticated Event Aggregator Import Status Manipulation
33RISK
open ↗Referência
CVE-2026-13332
Masteriyo LMS < 2.3.1 - Unauthenticated Arbitrary User Session Termination (Denial of Service)
48RISK
open ↗Referência✓ VexDay Proof
BBClone 0.31 - 'selectlang.php' Remote File Inclusion
PHP remote file inclusion vulnerability in lib/selectlang.php in BBClone 0.31 allows remote attackers to execute arbitra
23RISK
open ↗Referência
CVE-2026-13152
Custom Fields Account Registration For WooCommerce < 1.4 - Unauthenticated Privilege Escalation
41RISK
open ↗Referência✓ VexDay Proof
Google Chrome 1.0.154.53 - Null Pointer Remote Crash
Google Chrome 1.0.154.53 allows remote attackers to cause a denial of service (NULL pointer dereference and application
23RISK
open ↗Referência✓ VexDay Proof
AT Contenator 1.0 - 'Root_To_Script' Remote File Inclusion
PHP remote file inclusion vulnerability in _admin/nav.php in AT Contenator 1.0 and earlier allows remote attackers to ex
23RISK
open ↗Referência
CVE-2009-4256
Multiple SQL injection vulnerabilities in cource.php in AlefMentor 2.0 and 2.2 allow remote attackers to execute arbitra
23RISK
open ↗Referência
CVE-2018-5970
SQL Injection exists in the JGive 2.0.9 component for Joomla! via the filter_org_ind_type or campaign_countries paramete
23RISK
open ↗Referência
CVE-2026-12493
Clover Payment Gateway by Zaytech for WooCommerce < 1.3.6 - Unauthenticated Payment Bypass via check_order
41RISK
open ↗Referência✓ VexDay Proof
IntelliTamper 2.07 - HTTP Header Remote Code Execution
Stack-based buffer overflow in IntelliTamper 2.07 allows remote web sites to execute arbitrary code via a long HTTP Serv
23RISK
open ↗Referência
CVE-2017-13260
In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead
23RISK
open ↗Referência✓ VexDay Proof
cPanel 11.x - 'Fantastico' Local File Inclusion
Directory traversal vulnerability in includes/xml.php in the Netenberg Fantastico De Luxe module before 2.10.4 r19 for c
23RISK
open ↗Referência
CVE-2026-12394
MemberGlut < 1.1.5 - Unauthenticated Privilege Escalation to Administrator
48RISK
open ↗Referência
CVE-2026-12255
MainWP Child < 6.1.2 - Unauthenticated Administrator Authentication Bypass via Passwordless Site Registration
41RISK
open ↗Referência
CVE-2026-66006
lakeFS Unauthenticated Operator Metadata Overwrite via setup_comm_prefs
33RISK
open ↗Referência
CVE-2013-5756
Directory traversal vulnerability in Yealink VoIP Phone SIP-T38G allows remote authenticated users to read arbitrary fil
23RISK
open ↗Referência
CVE-2015-7293
Multiple cross-site request forgery (CSRF) vulnerabilities in Zope Management Interface 4.3.7 and earlier, and Plone bef
23RISK
open ↗Referência
CVE-2015-7293
Multiple cross-site request forgery (CSRF) vulnerabilities in Zope Management Interface 4.3.7 and earlier, and Plone bef
23RISK
open ↗Referência
CVE-2017-11330
The DivFixppCore::avi_header_fix function in DivFix++Core.cpp in DivFix++ v0.34 allows remote attackers to cause a denia
23RISK
open ↗Referência
CVE-2008-7185
GNOME Rhythmbox 0.11.5 allows remote attackers to cause a denial of service (segmentation fault and crash) via a playlis
23RISK
open ↗Referência
CVE-2021-37531
SAP NetWeaver Knowledge Management XML Forms versions - 7.10, 7.11, 7.30, 7.31, 7.40, 7.50, contains an XSLT vulnerabili
48RISK
open ↗Referência
CVE-2007-5982
Multiple cross-site scripting (XSS) vulnerabilities in X7 Chat 2.0.4, 2.0.5, and possibly other versions allow remote at
23RISK
open ↗Referência
CVE-2015-1482
Ansible Tower (aka Ansible UI) before 2.0.5 allows remote attackers to bypass authentication and obtain sensitive inform
23RISK
open ↗Referência
CVE-2015-1482
Ansible Tower (aka Ansible UI) before 2.0.5 allows remote attackers to bypass authentication and obtain sensitive inform
23RISK
open ↗Referência
CVE-2010-3213
Cross-site request forgery (CSRF) vulnerability in Microsoft Outlook Web Access (owa/ev.owa) 2007 through SP2 allows rem
23RISK
open ↗Referência
CVE-2014-6030
Multiple SQL injection vulnerabilities in ClassApps SelectSurvey.NET before 4.125.002 allow (1) remote attackers to exec
23RISK
open ↗Referência
CVE-2009-4264
PHP remote file inclusion vulnerability in components/core/connect.php in AROUNDMe 1.1 and earlier, when register_global
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.