Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,607cataloged exploits
34,986CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,899GitHub PoC 13,974VulnCheck XDB 8,571Nuclei 4,248Metasploit 3,472✓ verified onlyrecentpopularrisk
21,899 exploits
Referência✓ VexDay Proof
pl-PHP Beta 0.9 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in login.php in pL-PHP beta 0.9 allow remote attackers to execute arbitrary SQL c
23RISK
open ↗Referência✓ VexDay Proof
pl-PHP Beta 0.9 - Multiple Vulnerabilities
Directory traversal vulnerability in admin.php in pL-PHP beta 0.9 allows remote attackers to include and execute arbitra
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component mosmedia 1.0.8 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in the Avant-Garde Solutions MOSMedia (com_mosmedia) 1.08 and earlier
23RISK
open ↗Referência✓ VexDay Proof
Mambo Module Weather - 'absolute_path' Remote File Inclusion
PHP remote file inclusion vulnerability in mod_weather.php in the Antonis Ventouris Weather module for Mambo and Joomla!
23RISK
open ↗Referência
CVE-2017-0147
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open ↗Referência
CVE-2017-1000353
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code exe
100RISK
open ↗Referência
CVE-2020-10220
An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php
60RISK
open ↗Referência
CVE-2020-10220
An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php
60RISK
open ↗Referência
CVE-2020-10220
An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php
60RISK
open ↗Referência
CVE-2022-22965
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open ↗Referência
CVE-2022-22965
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open ↗Referência
CVE-2017-8687
The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
23RISK
open ↗Referência
CVE-2022-0543
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific
100RISK
open ↗Referência
CVE-2023-46604
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISK
open ↗Referência
CVE-2020-37225
Powie's WHOIS Domain Check 0.9.31 Persistent Cross-Site Scripting
33RISK
open ↗Referência
CVE-2020-37223
IObit Uninstaller 9.5.0.15 Unquoted Service Path Privilege Escalation
41RISK
open ↗Referência✓ VexDay Proof
aForum 1.32 - 'CommonAbsDir' Remote File Inclusion
PHP remote file inclusion vulnerability in common/func.php in aForum 1.32 and earlier allows remote attackers to execute
23RISK
open ↗Referência✓ VexDay Proof
telltarget 1.3.3 - 'tt_docroot' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in telltarget CMS 1.3.3 allow remote attackers to execute arbitrary P
28RISK
open ↗Referência✓ VexDay Proof
TutorialCMS 1.00 - 'search.php?search' SQL Injection
Multiple SQL injection vulnerabilities in TutorialCMS (aka Photoshop Tutorials) 1.00 and earlier allow remote attackers
23RISK
open ↗Referência✓ VexDay Proof
TutorialCMS 1.00 - 'search.php?search' SQL Injection
Multiple cross-site scripting (XSS) vulnerabilities in TutorialCMS (aka Photoshop Tutorials) 1.00 and earlier allow remo
23RISK
open ↗Referência✓ VexDay Proof
Miplex2 - 'SmartyFU.class.php' Remote File Inclusion
PHP remote file inclusion vulnerability in lib/smarty/SmartyFU.class.php in Miplex2 Alpha 1 allows remote attackers to e
23RISK
open ↗Referência✓ VexDay Proof
PHPLojaFacil 0.1.5 - 'path_local' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Crie seu PHPLojaFacil 0.1.5 allow remote attackers to execute arbi
23RISK
open ↗Referência
CVE-2009-5093
Directory traversal vulnerability in gastbuch.php in Gästebuch (Gastebuch) 1.6 allows remote attackers to read arbitrary
23RISK
open ↗Referência✓ VexDay Proof
Original 0.11 - 'config.inc.php?x[1]' Remote File Inclusion
PHP remote file inclusion vulnerability in inc/config.inc.php in Jakub Steiner (aka jimmac) original 0.11 allows remote
23RISK
open ↗Referência✓ VexDay Proof
NagiosQL 2005 2.00 - 'prepend_adm.php' Remote File Inclusion
PHP remote file inclusion vulnerability in functions/prepend_adm.php in NagiosQL 2005 2.00 allows remote attackers to ex
23RISK
open ↗Referência✓ VexDay Proof
Snaps! Gallery 1.4.4 - Remote User Pass Change
Admin/users.php in Snaps! Gallery 1.4.4 allows remote attackers to change arbitrary usernames and passwords via the (1)
28RISK
open ↗Referência✓ VexDay Proof
XOOPS Module resmanager 1.21 - Blind SQL Injection
SQL injection vulnerability in edit_day.php in the ResManager 1.2.1 and earlier module for Xoops allows remote attackers
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.