Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,607cataloged exploits
34,986CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,899GitHub PoC 13,974VulnCheck XDB 8,571Nuclei 4,248Metasploit 3,472✓ verified onlyrecentpopularrisk
21,899 exploits
Referência✓ VexDay Proof
Microsoft Windows - GDI (EMR_COLORMATCHTOTARGETW) (MS08-021)
Stack-based buffer overflow in GDI in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, and Server 200
35RISK
open ↗Referência✓ VexDay Proof
Affiliate Market 0.1 Beta - Cross-Site Scripting / SQL Injection
SQL injection vulnerability in shop/detail.php in Affiliate Market (affmarket) 0.1 BETA allows remote attackers to execu
23RISK
open ↗Referência✓ VexDay Proof
Dovecot IMAP 1.0.10 < 1.1rc2 - Remote Email Disclosure
Argument injection vulnerability in Dovecot 1.0.x before 1.0.13, and 1.1.x before 1.1.rc3, when using blocking passdbs,
23RISK
open ↗Referência
CVE-2020-0618
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page
100RISK
open ↗Referência
CVE-2020-0618
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page
100RISK
open ↗Referência
CVE-2022-30333
RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) o
100RISK
open ↗Referência
CVE-2020-7247
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISK
open ↗Referência
CVE-2020-7247
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISK
open ↗Referência
CVE-2020-7247
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISK
open ↗Referência
CVE-2020-7247
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISK
open ↗Referência
CVE-2020-7247
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISK
open ↗Referência✓ VexDay Proof
phpBB Mod FileBase 2.0 - 'id' SQL Injection
SQL injection vulnerability in filebase.php in the Filebase mod for phpBB allows remote attackers to execute arbitrary S
23RISK
open ↗Referência
CVE-2023-32560
An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disrup
78RISK
open ↗Referência
CVE-2023-32560
An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disrup
78RISK
open ↗Referência✓ VexDay Proof
Bloo 1.00 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in index.php in Bloo 1.00 and earlier allow remote attackers to execute arbitrary
23RISK
open ↗Referência
CVE-2020-7209
LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2.
60RISK
open ↗Referência
CVE-2020-7209
LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2.
60RISK
open ↗Referência
CVE-2026-61514
Puwell IP Camera 2.x - 4.x Unauthenticated Access via TCP Port 23456
48RISK
open ↗Referência
CVE-2026-61515
Puwell IP Camera 2.x - 4.x Unauthenticated Command Injection via DebugShell
48RISK
open ↗Referência
CVE-2026-16548
Bit Assist < 1.8.2 - Unauthenticated Arbitrary File Upload via Response Endpoint
33RISK
open ↗Referência
CVE-2026-16547
REST API Log < 1.7.1 - Unauthenticated Sensitive Log Data Disclosure via Download Endpoint
33RISK
open ↗Referência
CVE-2026-16546
Wired Impact Volunteer Management < 2.8.2 - Subscriber+ Arbitrary RSVP Removal via wivm_remove_rsvp
33RISK
open ↗Referência
CVE-2026-16295
Clearfy < 2.4.3 - Subscriber+ Sensitive Information Disclosure via Factory Page-Action Dispatcher
33RISK
open ↗Referência✓ VexDay Proof
Versant Object Database 7.0.1.3 - Commands Execution
Untrusted search path and argument injection vulnerability in the VersantD service in Versant Object Database 7.0.1.3 an
23RISK
open ↗Referência✓ VexDay Proof
EasyCalendar 4.0tr - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in MyioSoft EasyCalendar 4.0tr and earlier allow remote attackers to execute arbi
23RISK
open ↗Referência
CVE-2026-61524
WebsiteBaker CMS < 2.13.10 File Upload RCE via Module Installation
41RISK
open ↗Referência
CVE-2019-11539
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1R
100RISK
open ↗Referência
CVE-2019-11539
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1R
100RISK
open ↗Referência✓ VexDay Proof
Knowledge Base Mod 2.0.2 - 'phpBB' Remote File Inclusion
PHP remote file inclusion vulnerability in /includes/kb_constants.php in Knowledge Base Mod for PHPbb 2.0.2 and earlier
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.