Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,647cataloged exploits
34,986CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,899GitHub PoC 14,014VulnCheck XDB 8,571Nuclei 4,248Metasploit 3,472✓ verified onlyrecentpopularrisk
21,899 exploits
Referência
CVE-2018-13032
ECESSA ShieldLink SL175EHQ 10.7.4 devices have CSRF to add superuser accounts via the cgi-bin/pl_web.cgi/util_configlogi
23RISK
open ↗Referência
CVE-2017-0358
ntfs-3g: Modprobe influence vulnerability via environment variables
56RISK
open ↗Referência
CVE-2017-0358
ntfs-3g: Modprobe influence vulnerability via environment variables
56RISK
open ↗Referência
CVE-2017-14841
Mojoomla Annual Maintenance Contract (AMC) Management System allows Arbitrary File Upload in profilesetting image handli
23RISK
open ↗Referência✓ VexDay Proof
LearnLoop 2.0beta7 - 'sFilePath' Remote File Disclosure
Directory traversal vulnerability in include/file_download.php in LearnLoop 2.0 beta7 allows remote attackers to read ar
23RISK
open ↗Referência
CVE-2022-29727
Survey Sparrow Enterprise Survey Software 2022 has a Stored cross-site scripting (XSS) vulnerability in the Signup param
23RISK
open ↗Referência
CVE-2012-5099
Cross-site scripting (XSS) vulnerability in list.php in PHPB2B 4.1 and earlier allows remote attackers to inject arbitra
23RISK
open ↗Referência✓ VexDay Proof
PHPortal 1.2 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in sablonlar/gunaysoft/gunaysoft.php in PHPortal 1.2 Beta allow remot
23RISK
open ↗Referência✓ VexDay Proof
Pritlog 0.4 - 'Filename' Remote File Disclosure
Directory traversal vulnerability in index.php in Pritlog 0.4 and earlier, when magic_quotes_gpc is disabled, allows rem
23RISK
open ↗Referência
Veeam ONE Reporter 9.5.0.3201 - Multiple Cross-Site Request Forgery
Veeam ONE Reporter 9.5.0.3201 allows CSRF.
23RISK
open ↗Referência
PilusCart 1.4.1 - Cross-Site Request Forgery (Add Admin)
PilusCart 1.4.1 is vulnerable to index.php?module=users&action=newUser CSRF, leading to the addition of a new user as ad
23RISK
open ↗Referência
CVE-2017-16356
Reflected XSS in Kubik-Rubik SIGE (aka Simple Image Gallery Extended) before 3.3.0 allows attackers to execute JavaScrip
23RISK
open ↗Referência
CVE-2017-16356
Reflected XSS in Kubik-Rubik SIGE (aka Simple Image Gallery Extended) before 3.3.0 allows attackers to execute JavaScrip
23RISK
open ↗Referência
CVE-2018-9238
proberv.php in Yahei-PHP Proberv 0.4.7 has XSS via the funName parameter.
23RISK
open ↗Referência
CVE-2010-1948
Directory traversal vulnerability in scr/soustab.php in openMairie Openfoncier 2.00, when register_globals is enabled, a
23RISK
open ↗Referência
CVE-2018-13849
edit_requests.php in yTakkar Instagram-clone through 2018-04-23 has XSS via an onmouseover payload because of an inadequ
23RISK
open ↗Referência
CVE-2018-9857
PHP Scripts Mall Match Clone Script 1.0.4 has XSS via the search field to searchbyid.php (aka the "View Search By Id" sc
23RISK
open ↗Referência
CVE-2018-19828
Artica Integria IMS 5.0.83 has XSS via the search_string parameter.
23RISK
open ↗Referência✓ VexDay Proof
MonGoose 2.4 (Windows) - WebServer Directory Traversal
Directory traversal vulnerability in Mongoose 2.4 allows remote attackers to read arbitrary files via a .. (dot dot) in
23RISK
open ↗Referência
CVE-2009-4671
Login.php in RoomPHPlanning 1.6 allows remote attackers to bypass authentication and obtain administrative access by set
23RISK
open ↗Referência✓ VexDay Proof
Quick.CMS.Lite 0.3 - Cookie sLanguage Local File Inclusion
Directory traversal vulnerability in general.php in OpenSolution Quick.Cms.Lite 0.3 allows remote attackers to include a
23RISK
open ↗Referência
CVE-2009-3966
Arcade Trade Script 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the a
23RISK
open ↗Referência✓ VexDay Proof
phpBurningPortal 1.0.1 - 'lang_path' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in phpBurningPortal quiz-modul 1.0.1, and possibly earlier, allow rem
23RISK
open ↗Referência
CVE-2016-8812
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA GeForce Experience R340 before GFE 2.11.4.125 and R375 before G
23RISK
open ↗Referência
CVE-2014-1459
SQL injection vulnerability in dg-admin/index.php in doorGets CMS 5.2 and earlier allows remote authenticated administra
23RISK
open ↗Referência
CVE-2014-1459
SQL injection vulnerability in dg-admin/index.php in doorGets CMS 5.2 and earlier allows remote authenticated administra
23RISK
open ↗Referência
CVE-2010-1948
Directory traversal vulnerability in scr/soustab.php in openMairie Openfoncier 2.00, when register_globals is enabled, a
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.