Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,020cataloged exploits
35,276CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,446Referência 22,166GitHub PoC 14,080VulnCheck XDB 8,604Nuclei 4,251Metasploit 3,473✓ verified onlyrecentpopularrisk
21,899 exploits
Referência✓ VexDay Proof
Polaring 0.04.03 - 'general.php' Remote File Inclusion
PHP remote file inclusion vulnerability in view/general.php in Kristian Niemi Polaring 00.04.03 and earlier allows remot
23RISK
open ↗Referência✓ VexDay Proof
paBugs 2.0 Beta 3 - 'class.mysql.php' Remote File Inclusion
PHP remote file inclusion vulnerability in class.mysql.php in Matt Humphrey paBugs 2.0 Beta 3 and earlier allows remote
23RISK
open ↗Referência✓ VexDay Proof
Ninja Blog 4.8 - Remote Information Disclosure
Directory traversal vulnerability in entries/index.php in Ninja Blog 4.8, when magic_quotes_gpc is disabled, allows remo
23RISK
open ↗Referência✓ VexDay Proof
phpYabs 0.1.2 - 'Azione' Remote File Inclusion
PHP remote file inclusion vulnerability in moduli/libri/index.php in phpyabs 0.1.2 allows remote attackers to execute ar
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component EXP Shop - 'catid' SQL Injection
SQL injection vulnerability in the EXP Shop (com_expshop) component 1.0 for Joomla! allows remote attackers to execute a
23RISK
open ↗Referência
CVE-2006-0074
SQL injection vulnerability in profile.php in PHPenpals allows remote attackers to execute arbitrary SQL commands via th
23RISK
open ↗Referência
CVE-2016-4314
Directory traversal vulnerability in the LogViewer Admin Service in WSO2 Carbon 4.4.5 allows remote authenticated admini
28RISK
open ↗Referência
CVE-2016-4315
Cross-site request forgery (CSRF) vulnerability in WSO2 Carbon 4.4.5 allows remote attackers to hijack the authenticatio
23RISK
open ↗Referência
CVE-2016-4316
Multiple cross-site scripting (XSS) vulnerabilities in WSO2 Carbon 4.4.5 allow remote attackers to inject arbitrary web
23RISK
open ↗Referência
CVE-2016-4338
The mysql user parameter configuration script (userparameter_mysql.conf) in the agent in Zabbix before 2.0.18, 2.2.x bef
28RISK
open ↗Referência
CVE-2016-4338
The mysql user parameter configuration script (userparameter_mysql.conf) in the agent in Zabbix before 2.0.18, 2.2.x bef
28RISK
open ↗Referência
CVE-2010-1657
Directory traversal vulnerability in the SmartSite (com_smartsite) component 1.0.0 for Joomla! allows remote attackers t
43RISK
open ↗Referência
CVE-2016-4437
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attack
100RISK
open ↗Referência
CVE-2010-1657
Directory traversal vulnerability in the SmartSite (com_smartsite) component 1.0.0 for Joomla! allows remote attackers t
43RISK
open ↗Referência
CVE-2016-4437
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attack
100RISK
open ↗Referência
CVE-2010-1658
Directory traversal vulnerability in the Code-Garage NoticeBoard (com_noticeboard) component 1.3 for Joomla! allows remo
43RISK
open ↗Referência
CVE-2010-1658
Directory traversal vulnerability in the Code-Garage NoticeBoard (com_noticeboard) component 1.3 for Joomla! allows remo
43RISK
open ↗Referência
CVE-2010-1661
Multiple SQL injection vulnerabilities in PHP-Quick-Arcade (PHPQA) 3.0.21 allow remote attackers to execute arbitrary SQ
23RISK
open ↗Referência
CVE-2010-1681
Buffer overflow in VISIODWG.DLL before 10.0.6880.4 in Microsoft Office Visio allows user-assisted remote attackers to ex
50RISK
open ↗Referência✓ VexDay Proof
phpMyAgenda 3.1 - '/templates/header.php3' Local File Inclusion
Directory traversal vulnerability in templates/header.php3 in phpMyAgenda 3.1 and earlier allows remote attackers to inc
23RISK
open ↗Referência
CVE-2010-2622
SQL injection vulnerability in the Joomanager component, possibly 1.1.1, for Joomla! allows remote attackers to execute
23RISK
open ↗Referência✓ VexDay Proof
TorrentFlux 2.2 - 'maketorrent.php' Remote Command Execution
maketorrent.php in TorrentFlux 2.2 allows remote authenticated users to execute arbitrary commands via shell metacharact
23RISK
open ↗Referência✓ VexDay Proof
project alumni 1.0.9 - 'index.php?act' Local File Inclusion
Directory traversal vulnerability in index.php in Project Alumni 1.0.9 allows remote attackers to include and execute ar
23RISK
open ↗Referência✓ VexDay Proof
Power Editor 2.0 - Remote File Disclosure / Edit
Multiple directory traversal vulnerabilities in editor.php in ScriptsEZ.net Power Editor 2.0 allow remote attackers to r
23RISK
open ↗Referência✓ VexDay Proof
AJ HYIP ACME - 'news.php' SQL Injection
SQL injection vulnerability in news.php in AJ Square aj-hyip (aka AJ HYIP Acme) allows remote attackers to execute arbit
23RISK
open ↗Referência
CVE-2026-58460
react-native-receive-sharing-intent Path Traversal via _display_name
41RISK
open ↗Referência
CVE-2026-58467
Cockpit CMS 2.14.0 - Path Traversal Local File Inclusion via index.php
41RISK
open ↗Referência
CVE-2026-59102
Forgejo < 15.0.3 - Stored XSS via Actions Run Full Name Rendering
28RISK
open ↗Referência
CVE-2026-59100
LobeChat 2.2.9 - Broken Object Level Authorization via Chat-Group Agent Operations
28RISK
open ↗Referência
CVE-2026-59099
Apereo CAS 7.3.0 < 8.0.0-RC6 - AES-GCM Nonce Reuse Information Disclosure
48RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.