Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,647cataloged exploits
34,986CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,899GitHub PoC 14,014VulnCheck XDB 8,571Nuclei 4,248Metasploit 3,472✓ verified onlyrecentpopularrisk
21,899 exploits
Referência✓ VexDay Proof
Centreon 1.4.2.3 - 'get_image.php' Remote File Disclosure
Directory traversal vulnerability in include/doc/get_image.php in Centreon 1.4.2.3 and earlier allows remote attackers t
23RISK
open ↗Referência✓ VexDay Proof
Podcast Generator 1.0 Beta 2 - Remote File Inclusion / File Disclosure
Multiple PHP remote file inclusion vulnerabilities in Podcast Generator 1.0 BETA 2 and earlier allow remote attackers to
28RISK
open ↗Referência✓ VexDay Proof
Mambo Component garyscookbook 1.1.1 - SQL Injection
SQL injection vulnerability in the Garys Cookbook (com_garyscookbook) 1.1.1 and earlier component for Mambo and Joomla!
23RISK
open ↗Referência
CVE-2010-0802
SQL injection vulnerability in index.php in (nv2) Awards 1.1.0, a modification for Invision Power Board, allows remote a
23RISK
open ↗Referência✓ VexDay Proof
DESlock+ < 3.2.6 - 'DLMFENC.sys' Local Kernel Ring0 link list zero (PoC)
DLMFENC.sys 1.0.0.26 in DESlock+ 3.2.6 and earlier allows local users to cause a denial of service (system crash) via a
23RISK
open ↗Referência
CVE-2026-70619
Odysseus Missing Admin Authorization via Embedding Endpoint Routes
41RISK
open ↗Referência
CVE-2026-70619
Odysseus Missing Admin Authorization via Embedding Endpoint Routes
41RISK
open ↗Referência
CVE-2021-44529
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execut
100RISK
open ↗Referência✓ VexDay Proof
Affiliate Market 0.1 Beta - Cross-Site Scripting / SQL Injection
SQL injection vulnerability in shop/detail.php in Affiliate Market (affmarket) 0.1 BETA allows remote attackers to execu
23RISK
open ↗Referência✓ VexDay Proof
Dovecot IMAP 1.0.10 < 1.1rc2 - Remote Email Disclosure
Argument injection vulnerability in Dovecot 1.0.x before 1.0.13, and 1.1.x before 1.1.rc3, when using blocking passdbs,
23RISK
open ↗Referência
CVE-2020-0618
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page
100RISK
open ↗Referência
CVE-2020-0618
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page
100RISK
open ↗Referência
CVE-2022-30333
RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) o
100RISK
open ↗Referência
CVE-2020-7247
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISK
open ↗Referência
CVE-2020-7247
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISK
open ↗Referência
CVE-2020-7247
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISK
open ↗Referência
CVE-2020-7247
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISK
open ↗Referência
CVE-2020-7247
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISK
open ↗Referência✓ VexDay Proof
phpBB Mod FileBase 2.0 - 'id' SQL Injection
SQL injection vulnerability in filebase.php in the Filebase mod for phpBB allows remote attackers to execute arbitrary S
23RISK
open ↗Referência
CVE-2023-32560
An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disrup
78RISK
open ↗Referência
CVE-2023-32560
An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disrup
78RISK
open ↗Referência✓ VexDay Proof
Bloo 1.00 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in index.php in Bloo 1.00 and earlier allow remote attackers to execute arbitrary
23RISK
open ↗Referência
CVE-2020-7209
LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2.
60RISK
open ↗Referência
CVE-2020-7209
LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2.
60RISK
open ↗Referência
CVE-2026-61514
Puwell IP Camera 2.x - 4.x Unauthenticated Access via TCP Port 23456
48RISK
open ↗Referência
CVE-2026-61515
Puwell IP Camera 2.x - 4.x Unauthenticated Command Injection via DebugShell
48RISK
open ↗Referência
CVE-2026-16548
Bit Assist < 1.8.2 - Unauthenticated Arbitrary File Upload via Response Endpoint
33RISK
open ↗Referência
CVE-2026-16547
REST API Log < 1.7.1 - Unauthenticated Sensitive Log Data Disclosure via Download Endpoint
33RISK
open ↗Referência
CVE-2026-16546
Wired Impact Volunteer Management < 2.8.2 - Subscriber+ Arbitrary RSVP Removal via wivm_remove_rsvp
33RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.