Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,647cataloged exploits
34,986CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,899GitHub PoC 14,014VulnCheck XDB 8,571Nuclei 4,248Metasploit 3,472✓ verified onlyrecentpopularrisk
21,899 exploits
Referência
CVE-2017-10046
Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (
23RISK
open ↗Referência
CVE-2017-9260
The TDStretchSSE::calcCrossCorr function in source/SoundTouch/sse_optimized.cpp in SoundTouch 1.9.2 allows remote attack
23RISK
open ↗Referência
CVE-2010-1265
SQL injection vulnerability in Adam Corley dcsFlashGames (com_dcs_flashgames) allows remote attackers to execute arbitra
23RISK
open ↗Referência
CVE-2015-4065
Cross-site scripting (XSS) vulnerability in shared/shortcodes/inbound-shortcodes.php in the Landing Pages plugin before
23RISK
open ↗Referência
CVE-2017-6989
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
23RISK
open ↗Referência
CVE-2010-1265
SQL injection vulnerability in Adam Corley dcsFlashGames (com_dcs_flashgames) allows remote attackers to execute arbitra
23RISK
open ↗Referência✓ VexDay Proof
Free File Hosting 1.1 - 'forgot_pass.php' File Inclusion
PHP remote file inclusion vulnerability in forgot_pass.php in Free File Hosting 1.1 and earlier allows remote attackers
23RISK
open ↗Referência✓ VexDay Proof
Exhibit Engine 1.22 - 'styles.php' Remote File Inclusion
PHP remote file inclusion vulnerability in styles.php in Exhibit Engine (EE) 1.22 and earlier allows remote attackers to
23RISK
open ↗Referência✓ VexDay Proof
DZCP (deV!L_z Clanportal) 1.4.5 - Remote File Disclosure
inc/filebrowser/browser.php in deV!L`z Clanportal (DZCP) 1.4.5 and earlier allows remote attackers to obtain MySQL data
23RISK
open ↗Referência
CVE-2017-8479
The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2,
23RISK
open ↗Referência
CVE-2026-14843
Events Made Easy < 3.1.4 - Unauthenticated Person Data Modification via IDOR
33RISK
open ↗Referência
CVE-2017-8481
The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2,
23RISK
open ↗Referência
CVE-2006-1747
PHP remote file inclusion vulnerability in Virtual War (VWar) 1.5.0 allows remote attackers to execute arbitrary PHP cod
23RISK
open ↗Referência
CVE-2005-4696
The Microsoft Wireless Zero Configuration system (WZCS) stores WEP keys and pair-wise Master Keys (PMK) of the WPA pre-s
23RISK
open ↗Referência
CVE-2018-10310
A persistent cross-site scripting vulnerability has been identified in the web interface of the Catapult UK Cookie Conse
23RISK
open ↗Referência
CVE-2018-10310
A persistent cross-site scripting vulnerability has been identified in the web interface of the Catapult UK Cookie Conse
23RISK
open ↗Referência
CVE-2014-9311
Cross-site scripting (XSS) vulnerability in admin.php in the Shareaholic plugin before 7.6.1.0 for WordPress allows remo
23RISK
open ↗Referência
CVE-2018-17428
An issue was discovered in OPAC EasyWeb Five 5.7. There is SQL injection via the w2001/index.php?scelta=campi biblio par
23RISK
open ↗Referência
CVE-2019-11416
A CSRF issue was discovered on Intelbras IWR 3000N 1.5.0 devices, leading to complete control of the router, as demonstr
23RISK
open ↗Referência
CVE-2019-11416
A CSRF issue was discovered on Intelbras IWR 3000N 1.5.0 devices, leading to complete control of the router, as demonstr
23RISK
open ↗Referência✓ VexDay Proof
SoftBB 0.1 - 'cmd' Remote Command Execution
Multiple SQL injection vulnerabilities in SoftBB 0.1, and possibly earlier, allow remote attackers to execute arbitrary
23RISK
open ↗Referência
CVE-2013-4950
Cross-site scripting (XSS) vulnerability in view.php in Machform 2 allows remote attackers to inject arbitrary web scrip
23RISK
open ↗Referência
CVE-2010-1270
SQL injection vulnerability in auktion.php in Multi Auktions Komplett System 2 allows remote attackers to execute arbitr
23RISK
open ↗Referência✓ VexDay Proof
W3Filer 2.1.3 - Remote Stack Overflow (PoC)
Stack-based buffer overflow in W3Filer 2.1.3 allows remote FTP servers to cause a denial of service (application hang or
23RISK
open ↗Referência
CVE-2011-5228
Cross-site scripting (XSS) vulnerability in the Search module (quickstart/search) in appRain CMF 0.1.5 allows remote att
23RISK
open ↗Referência✓ VexDay Proof
Live for Speed S1/S2/Demo - '.mpr replay' Local Buffer Overflow
Buffer overflow in Live for Speed (LFS) S2 ALPHA PATCH 0.5x allows user-assisted remote attackers to execute arbitrary c
23RISK
open ↗Referência
CVE-2012-2939
Multiple unrestricted file upload vulnerabilities in Travelon Express 6.2.2 allow remote authenticated users to execute
23RISK
open ↗Referência✓ VexDay Proof
rgboard 3.0.12 - Remote File Inclusioni / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in rg_search.php in Rgboard 3.0.12, and possibly earlier versions, allows remot
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.