Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,020cataloged exploits
35,276CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,446Referência 22,166GitHub PoC 14,080VulnCheck XDB 8,604Nuclei 4,251Metasploit 3,473✓ verified onlyrecentpopularrisk
21,899 exploits
Referência✓ VexDay Proof
Poppler 0.8.4 - libpoppler Uninitialized pointer Code Execution
The Page destructor in Page.cc in libpoppler in Poppler 0.8.4 and earlier deletes a pageWidgets object even if it is not
28RISK
open ↗Referência✓ VexDay Proof
CMS Mini 0.2.2 - Multiple Local File Inclusions
Multiple directory traversal vulnerabilities in view/index.php in CMS Mini 0.2.2 allow remote attackers to read arbitrar
23RISK
open ↗Referência
CVE-2012-3840
Multiple cross-site scripting (XSS) vulnerabilities in index.php/users/form/user_id in MyClientBase 0.12 allow remote at
23RISK
open ↗Referência
CVE-2022-23046
PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a su
28RISK
open ↗Referência
CVE-2015-1518
SQL injection vulnerability in the search_post function in includes/search.php in Redaxscript before 2.3.0 allows remote
23RISK
open ↗Referência
CVE-2015-1518
SQL injection vulnerability in the search_post function in includes/search.php in Redaxscript before 2.3.0 allows remote
23RISK
open ↗Referência
CVE-2010-2685
siteadmin/adduser.php in Customer Paradigm PageDirector CMS does not properly restrict access, which allows remote attac
23RISK
open ↗Referência
CVE-2010-2685
siteadmin/adduser.php in Customer Paradigm PageDirector CMS does not properly restrict access, which allows remote attac
23RISK
open ↗Referência✓ VexDay Proof
WebText 0.4.5.2 - Remote Code Execution
Direct static code injection vulnerability in WebText CMS 0.4.5.2 and earlier allows remote attackers to inject arbitrar
23RISK
open ↗Referência
CVE-2015-1467
Multiple SQL injection vulnerabilities in Translations in Fork CMS before 3.8.6 allow remote authenticated users to exec
23RISK
open ↗Referência
CVE-2015-6805
Cross-site scripting (XSS) vulnerability in the MDC Private Message plugin 1.0.0 for WordPress allows remote authenticat
23RISK
open ↗Referência
CVE-2017-6982
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. The issue involves the "Notifications"
23RISK
open ↗Referência✓ VexDay Proof
FTP Explorer 1.0.1 Build 047 - Remote CPU Consumption (Denial of Service)
FTP Explorer 1.0.1 Build 047, and other versions before 1.0.1.52, allows remote servers to cause a denial of service (CP
23RISK
open ↗Referência
CVE-2010-0983
PHP remote file inclusion vulnerability in include/mail.inc.php in Rezervi 3.0.2 and earlier, when register_globals is e
23RISK
open ↗Referência
CVE-2010-0983
PHP remote file inclusion vulnerability in include/mail.inc.php in Rezervi 3.0.2 and earlier, when register_globals is e
23RISK
open ↗Referência
CVE-2018-0821
AppContainer in Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows
23RISK
open ↗Referência✓ VexDay Proof
XCMS 1.1 - 'Galerie.php' Local File Inclusion
Multiple directory traversal vulnerabilities in Module/Galerie.php in XCMS 1.1 allow remote attackers to include and exe
23RISK
open ↗Referência
CVE-2017-9418
SQL injection vulnerability in the WP-Testimonials plugin 3.4.1 for WordPress allows an authenticated user to execute ar
23RISK
open ↗Referência
CVE-2010-2908
SQL injection vulnerability in the Joomdle (com_joomdle) component 0.24 and earlier for Joomla! allows remote attackers
23RISK
open ↗Referência
CVE-2010-2908
SQL injection vulnerability in the Joomdle (com_joomdle) component 0.24 and earlier for Joomla! allows remote attackers
23RISK
open ↗Referência
CVE-2012-3836
Multiple cross-site scripting (XSS) vulnerabilities in Baby Gekko before 1.2.0 allow remote attackers to inject arbitrar
23RISK
open ↗Referência
CVE-2012-5899
Cross-site scripting (XSS) vulnerability in admin/action/objects.php in SAMEDIA LandShop 0.9.2 allows remote attackers t
23RISK
open ↗Referência✓ VexDay Proof
MODx CMS 0.9.6.2 - Remote File Inclusion / Cross-Site Scripting
PHP remote file inclusion vulnerability in assets/snippets/reflect/snippet.reflect.php in MODx CMS 0.9.6.2 and earlier,
23RISK
open ↗Referência✓ VexDay Proof
AJSquare Free Polling Script - 'DB' Multiple Vulnerabilities
AJ Square Free Polling Script (AJPoll) Database version allows remote attackers to bypass authentication and reset poll
23RISK
open ↗Referência✓ VexDay Proof
PHPortal 1.0 - Insecure Cookie Handling
uye_paneli.php in phPortal 1.0 allows remote attackers to bypass authentication and obtain administrative access by sett
23RISK
open ↗Referência
CVE-2012-5350
SQL injection vulnerability in the Pay With Tweet plugin before 1.2 for WordPress allows remote authenticated users with
23RISK
open ↗Referência
CVE-2010-4851
Multiple SQL injection vulnerabilities in Eclime 1.1.2b allow remote attackers to execute arbitrary SQL commands via the
23RISK
open ↗Referência
CVE-2010-4851
Multiple SQL injection vulnerabilities in Eclime 1.1.2b allow remote attackers to execute arbitrary SQL commands via the
23RISK
open ↗Referência
CVE-2010-1497
Cross-site scripting (XSS) vulnerability in download_proc.php in dl_stats before 2.0 allows remote attackers to inject a
23RISK
open ↗Referência
CVE-2010-1497
Cross-site scripting (XSS) vulnerability in download_proc.php in dl_stats before 2.0 allows remote attackers to inject a
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.