Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,647cataloged exploits
34,986CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,899GitHub PoC 14,014VulnCheck XDB 8,571Nuclei 4,248Metasploit 3,472✓ verified onlyrecentpopularrisk
21,899 exploits
Referência✓ VexDay Proof
PNPHPBB2 < 1.2i - 'ModName' Multiple Local File Inclusions
Multiple directory traversal vulnerabilities in PNphpBB2 1.2i and earlier allow remote attackers to include and execute
28RISK
open ↗Referência
CVE-2026-10157
Open5GS NGAP PathSwitchRequest Message ngap-handler.c improper authentication
33RISK
open ↗Referência
CVE-2026-10156
Open5GS nf-instances Endpoint nnrf-handler.c handle_amf_info resource consumption
33RISK
open ↗Referência
CVE-2026-10155
Bdtask Multi-Store Inventory Management System Accounts Report Accounts.php accounts_report_search sql injection
33RISK
open ↗Referência
CVE-2026-10153
westboy CicadasCMS AbstractCacheManager.java search cross site scripting
33RISK
open ↗Referência✓ VexDay Proof
plxAutoReminder 3.7 - 'id' SQL Injection
SQL injection vulnerability in members.php in plx Auto Reminder 3.7 allows remote authenticated users to execute arbitra
23RISK
open ↗Referência
CVE-2018-11776
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISK
open ↗Referência✓ VexDay Proof
phpskelsite 1.4 - Local File Inclusion / Remote File Inclusion / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in phpSkelSite 1.4 allows remote attackers to inject arbitrary web
23RISK
open ↗Referência✓ VexDay Proof
w3blabor CMS 3.3.0 - Authentication Bypass
SQL injection vulnerability in admin/index.php in w3b>cms (aka w3blabor CMS) before 3.4.0, when magic_quotes_gpc is disa
23RISK
open ↗Referência✓ VexDay Proof
FreeBSD 7.0-RELEASE - Telnet Daemon Privilege Escalation
sys_term.c in telnetd in FreeBSD 7.0-RELEASE and other 7.x versions deletes dangerous environment variables with a metho
23RISK
open ↗Referência
CVE-2014-7169
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of
100RISK
open ↗Referência✓ VexDay Proof
Simple PHP News 1.0 - Remote Command Execution
Static code injection vulnerability in post.php in Simple PHP News 1.0 final allows remote attackers to inject arbitrary
23RISK
open ↗Referência✓ VexDay Proof
4Site CMS 2.6 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in 4Site CMS 2.6 and earlier allow remote attackers to execute arbitrary SQL comm
23RISK
open ↗Referência✓ VexDay Proof
Adobe Acrobat Reader - JBIG2 Local Buffer Overflow (PoC) (2)
Buffer overflow in Adobe Reader 9.0 and earlier, and Acrobat 9.0 and earlier, allows remote attackers to execute arbitra
60RISK
open ↗Referência✓ VexDay Proof
ravennuke 2.3.0 - Multiple Vulnerabilities
SQL injection vulnerability in the Resend_Email module in Raven Web Services RavenNuke 2.30 allows remote authenticated
23RISK
open ↗Referência
CVE-2009-4624
SQL injection vulnerability in download.php in Nicecoder iDesk allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗Referência
CVE-2020-8515
DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow
100RISK
open ↗Referência
CVE-2018-7600
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open ↗Referência
CVE-2018-7600
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open ↗Referência✓ VexDay Proof
ravennuke 2.3.0 - Multiple Vulnerabilities
avatarlist.php in the Your Account module, reached through modules.php, in Raven Web Services RavenNuke 2.30 allows remo
23RISK
open ↗Referência✓ VexDay Proof
Techno Dreams Guestbook 1.0 - 'key' SQL Injection
SQL injection vulnerability in guestbookview.asp in Techno Dreams Guest Book 1.0 earlier allows remote attackers to exec
23RISK
open ↗Referência✓ VexDay Proof
Techno Dreams Announcement - 'key' SQL Injection
SQL injection vulnerability in MainAnnounce2.asp in Techno Dreams Announcement allows remote attackers to execute arbitr
23RISK
open ↗Referência
CVE-2026-10116
Open5GS ue-authentications Endpoint ogs-timer.c ogs_sbi_xact_add denial of service
33RISK
open ↗Referência
CVE-2026-10114
Open5GS Shared NF-profile nnrf-handler.c handle_scp_info out-of-bounds write
33RISK
open ↗Referência
CVE-2026-10112
sambitraj STUDENT-MANAGEMENT-SYSTEM Dashboard cross site scripting
33RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.