Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,316cataloged exploits
34,835CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,797GitHub PoC 13,885VulnCheck XDB 8,484Nuclei 4,239Metasploit 3,468✓ verified onlyrecentpopularrisk
21,797 exploits
Referência
CVE-2009-4206
SQL injection vulnerability in admin.link.modify.php in Million Dollar Text Links 1.0 and earlier allows remote attacker
23RISK
open ↗Referência
CVE-2020-8495
In Kronos Web Time and Attendance (webTA) 3.8.x and later 3.x versions before 4.0, the com.threeis.webta.H491delegate se
41RISK
open ↗Referência
CVE-2014-3848
The iMember360 plugin before 3.9.001 for WordPress does not properly restrict access, which allows remote attackers to o
23RISK
open ↗Referência
CVE-2014-3848
The iMember360 plugin before 3.9.001 for WordPress does not properly restrict access, which allows remote attackers to o
23RISK
open ↗Referência
CVE-2006-5521
PHP remote file inclusion vulnerability in DNS/RR.php in Net_DNS 0.03 and earlier allows remote attackers to execute arb
23RISK
open ↗Referência
CVE-2009-4208
SQL injection vulnerability in the os_news module in Open-school (OS) 1.0 allows remote attackers to execute arbitrary S
23RISK
open ↗Referência
CVE-2013-4865
Cross-site request forgery (CSRF) vulnerability in upgrade_step2.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows
23RISK
open ↗Referência✓ VexDay Proof
vp-asp shopping cart 6.09 - SQL Injection / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in shopcustadmin.asp in VP-ASP Shopping Cart 6.09 and earlier allows remote att
23RISK
open ↗Referência✓ VexDay Proof
Anthologia 0.5.2 - 'index.php?ads_file' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in Anthologia 0.5.2 allows remote attackers to execute arbitrary PH
23RISK
open ↗Referência✓ VexDay Proof
PHP-Generics 1.0.0 Beta - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in PHP-Generics 1.0 beta allow remote attackers to execute arbitrary
23RISK
open ↗Referência✓ VexDay Proof
Glossword 1.8.1 - 'custom_vars.php' Remote File Inclusion
PHP remote file inclusion vulnerability in custom_vars.php in GlossWord 1.8.1 allows remote attackers to execute arbitra
23RISK
open ↗Referência✓ VexDay Proof
PHP Real Estate Classifieds - Remote File Inclusion
PHP remote file inclusion vulnerability in admin/header.php in PHP Real Estate Classifieds Premium Plus allows remote at
23RISK
open ↗Referência✓ VexDay Proof
CounterPath X-Lite 3.x - SIP phone Remote Denial of Service
CounterPath X-Lite 3.0 34025, and possibly eyeBeam, allows remote attackers to cause a denial of service (device crash)
23RISK
open ↗Referência✓ VexDay Proof
Joomla! 1.5.x - 'Token' Remote Admin Change Password
components/com_user/models/reset.php in Joomla! 1.5 through 1.5.5 does not properly validate reset tokens, which allows
23RISK
open ↗Referência✓ VexDay Proof
wbstreet 1.0 - SQL Injection / File Disclosure
Wbstreet (aka PHPSTREET Webboard) 1.0 stores sensitive information under the web root with insufficient access control,
23RISK
open ↗Referência
CVE-2019-15253
Cisco Digital Network Architecture Center Stored Cross-Site Scripting Vulnerability
33RISK
open ↗Referência
CVE-2017-0287
Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT
23RISK
open ↗Referência
CVE-2011-4807
Directory traversal vulnerability in main.php in phpAlbum 0.4.1.16 and earlier allows remote attackers to read arbitrary
23RISK
open ↗Referência
CVE-2006-5191
PHP remote file inclusion vulnerability in includes/functions_static_topics.php in the Nivisec Static Topics module for
23RISK
open ↗Referência
CVE-2019-8390
qdPM 9.1 suffers from Cross-site Scripting (XSS) in the search[keywords] parameter.
38RISK
open ↗Referência
CVE-2019-13236
In system/workplace/ in Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple Reflected and Stored XSS issues in the man
23RISK
open ↗Referência
CVE-2019-8390
qdPM 9.1 suffers from Cross-site Scripting (XSS) in the search[keywords] parameter.
38RISK
open ↗Referência
CVE-2010-5032
SQL injection vulnerability in the BF Quiz (com_bfquiztrial) component before 1.3.1 for Joomla! allows remote attackers
23RISK
open ↗Referência✓ VexDay Proof
k_fileManager 1.2 - 'dwl_include_path' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in index.php in Knusperleicht FileManager 1.2 and earlier allow remot
23RISK
open ↗Referência
CVE-2020-25820
BigBlueButton before 2.2.7 allows remote authenticated users to read local files and conduct SSRF attacks via an uploade
28RISK
open ↗Referência
CVE-2009-4221
SQL injection vulnerability in classified.php in phpBazar 2.1.1fix and earlier allows remote attackers to execute arbitr
23RISK
open ↗Referência
CVE-2018-14592
The CWJoomla CW Article Attachments PRO extension before 2.0.7 and CW Article Attachments FREE extension before 1.0.6 fo
23RISK
open ↗Referência
CVE-2009-4221
SQL injection vulnerability in classified.php in phpBazar 2.1.1fix and earlier allows remote attackers to execute arbitr
23RISK
open ↗Referência✓ VexDay Proof
DBGuestbook 1.1 - 'dbs_base_path' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in DBGuestbook 1.1 allow remote attackers to execute arbitrary PHP co
23RISK
open ↗Referência✓ VexDay Proof
phpTrafficA 1.4.2 - 'pageid' SQL Injection
Directory traversal vulnerability in index.php in phpTrafficA 1.4.2 and earlier allows remote attackers to include arbit
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.