Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,565cataloged exploits
34,981CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,899GitHub PoC 13,961VulnCheck XDB 8,542Nuclei 4,248Metasploit 3,472✓ verified onlyrecentpopularrisk
21,899 exploits
Referência
CVE-2026-7271
DV0x creative-ad-agent creative-ad-agent-server sdk-server.ts path traversal
33RISK
open ↗Referência
CVE-2026-7269
SourceCodester Pharmacy Sales and Inventory System index.php cross site scripting
33RISK
open ↗Referência
CVE-2026-7268
SourceCodester Pizzafy Ecommerce System ajax.php save_category sql injection
33RISK
open ↗Referência
CVE-2026-7267
SourceCodester Pizzafy Ecommerce System view_prod.php sql injection
33RISK
open ↗Referência
CVE-2026-7266
SourceCodester Pizzafy Ecommerce System ajax.php save_order sql injection
33RISK
open ↗Referência
CVE-2026-7265
SourceCodester Pizzafy Ecommerce System index.php category sql injection
33RISK
open ↗Referência
CVE-2026-7264
SourceCodester Pizzafy Ecommerce System ajax.php get_cart_items sql injection
33RISK
open ↗Referência
CVE-2026-7248
D-Link DI-8100 CGI Endpoint tgfile.htm tgfile_htm buffer overflow
48RISK
open ↗Referência
CVE-2026-7247
D-Link DI-8100 File Extension file_exten.asp file_exten_asp buffer overflow
41RISK
open ↗Referência
CVE-2026-7244
Totolink A8000RU CGI cstecgi.cgi setWiFiEasyGuestCfg os command injection
48RISK
open ↗Referência
CVE-2026-7243
Totolink A8000RU CGI cstecgi.cgi setRadvdCfg os command injection
48RISK
open ↗Referência
CVE-2025-10539
Improper TLS Certificate Validation RCE via Malicious Update in DeskTime Time Tracking App
33RISK
open ↗Referência
CVE-2026-7241
Totolink A8000RU CGI cstecgi.cgi setWiFiBasicCfg os command injection
48RISK
open ↗Referência
CVE-2026-7240
Totolink A8000RU CGI cstecgi.cgi setVpnAccountCfg os command injection
48RISK
open ↗Referência
CVE-2026-7227
SourceCodester Pizzafy Ecommerce System ajax.php login sql injection
33RISK
open ↗Referência✓ VexDay Proof
Remotesoft .NET Explorer 2.0.1 - Local Stack Overflow (PoC)
Stack-based buffer overflow in Remotesoft .NET Explorer 2.0.1 allows user-assisted remote attackers to cause a denial of
23RISK
open ↗Referência✓ VexDay Proof
Flip 2.01 final - 'previewtheme.php?inc_path' Remote File Inclusion
PHP remote file inclusion vulnerability in previewtheme.php in Flipsource Flip 2.01-final 1.0 and earlier allows remote
35RISK
open ↗Referência✓ VexDay Proof
Photo Galerie Standard 1.1 - 'view.php' SQL Injection
SQL injection vulnerability in view.php in Noname Media Photo Galerie Standard 1.1.1 and earlier allows remote attackers
23RISK
open ↗Referência✓ VexDay Proof
SmartFTP Client 2.0.1002 - Remote Heap Overflow Denial of Service
Heap-based buffer overflow in SmartFTP 2.0.1002 allows remote FTP servers to execute arbitrary code via a large banner.
23RISK
open ↗Referência✓ VexDay Proof
SMA-DB 0.3.9 - 'settings.php' Remote File Inclusion
PHP remote file inclusion vulnerability in theme/settings.php in bluevirus-design SMA-DB 0.3.9 and earlier allows remote
23RISK
open ↗Referência
CVE-2022-29303
SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php.
100RISK
open ↗Referência✓ VexDay Proof
Categories hierarchy phpBB Mod 2.1.2 - 'phpbb_root_path' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/class_template.php in Categories hierarchy (aka CH or mod-CH) 2.1.2
23RISK
open ↗Referência✓ VexDay Proof
Geeklog 2 - 'BaseView.php' Remote File Inclusion
PHP remote file inclusion vulnerability in MVCnPHP/BaseView.php in GeekLog 2 and earlier allows remote attackers to exec
23RISK
open ↗Referência✓ VexDay Proof
Woltlab Burning Board Lite 1.0.2pl3e - 'pms.php' SQL Injection
SQL injection vulnerability in pms.php in Woltlab Burning Board (wBB) Lite 1.0.2pl3e and earlier allows remote authentic
23RISK
open ↗Referência✓ VexDay Proof
LightRO CMS 1.0 - 'inhalt.php' Remote File Inclusion
PHP remote file inclusion vulnerability in inhalt.php in LightRO CMS 1.0 allows remote attackers to execute arbitrary PH
23RISK
open ↗Referência✓ VexDay Proof
Kisisel Site 2007 - 'tr' SQL Injection
SQL injection vulnerability in forum.asp in Kisisel Site 2007 allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗Referência✓ VexDay Proof
Alibaba Alipay - Remove ActiveX Remote Code Execution
The Alibaba Alipay PTA Module ActiveX control (PTA.DLL) allows remote attackers to execute arbitrary code via a JavaScri
23RISK
open ↗Referência✓ VexDay Proof
Advanced Poll 2.0.5-dev - Remote Admin Session Generator
admin/index.php in Advanced Poll 2.0.0 through 2.0.5-dev allows remote attackers to bypass authentication and gain admin
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.