Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,025cataloged exploits
35,280CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,446Referência 22,166GitHub PoC 14,080VulnCheck XDB 8,604Nuclei 4,255Metasploit 3,474✓ verified onlyrecentpopularrisk
22,166 exploits
Referência✓ VexDay Proof
PHP Coupon Script 3.0 - 'bus' SQL Injection
SQL injection vulnerability in index.php in PHP Coupon Script 3.0 allows remote attackers to execute arbitrary SQL comma
23RISK
open ↗Referência✓ VexDay Proof
Newswriter SW 1.4.2 - 'main.inc.php' Remote File Inclusion
PHP remote file inclusion vulnerability in include/main.inc.php in Sebastian Baumann and Philipp Wolfer Newswriter SW 1.
23RISK
open ↗Referência
CVE-2012-2586
Multiple cross-site scripting (XSS) vulnerabilities in Mailtraq 2.17.3.3150 allow remote attackers to inject arbitrary w
23RISK
open ↗Referência
CVE-2021-32403
Intelbras Router RF 301K Firmware 1.1.2 is vulnerable to Cross Site Request Forgery (CSRF) due to lack of security mecha
23RISK
open ↗Referência✓ VexDay Proof
xml2owl 0.1.1 - 'showcode.php' Remote Command Execution
showCode.php in xml2owl 0.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the path
23RISK
open ↗Referência
CVE-2012-2578
Multiple cross-site scripting (XSS) vulnerabilities in SmarterMail 9.2 allow remote attackers to inject arbitrary web sc
23RISK
open ↗Referência
CVE-2014-5100
Multiple cross-site request forgery (CSRF) vulnerabilities in Omeka before 2.2.1 allow remote attackers to hijack the au
23RISK
open ↗Referência
CVE-2014-5100
Multiple cross-site request forgery (CSRF) vulnerabilities in Omeka before 2.2.1 allow remote attackers to hijack the au
23RISK
open ↗Referência✓ VexDay Proof
PHPMyCart 1.3 - 'cat' SQL Injection
SQL injection vulnerability in shop.php in Conkurent PHPMyCart allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗Referência
CVE-2017-14620
SmarterStats Version 11.3.6347 will Render the Referer Field of HTTP Logfiles from URL /Data/Reports/ReferringURLsWithQu
23RISK
open ↗Referência✓ VexDay Proof
Mambo 4.6.4 - 'Output.php' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/Cache/Lite/Output.php in the Cache_Lite package in Mambo 4.6.4 and e
43RISK
open ↗Referência✓ VexDay Proof
Micro CMS 0.3.5 - Remote Add/Delete/Password Change
microcms-admin-home.php in Implied by Design Micro CMS (Micro-CMS) 3.5 (aka 0.3.5) does not require authentication as an
23RISK
open ↗Referência
CVE-2018-18419
Stored XSS has been discovered in the upload section of ARDAWAN.COM User Management 1.1, as demonstrated by a .jpg filen
23RISK
open ↗Referência
CVE-2026-9677
Shariff for WordPress <= 1.0.11 - Admin+ Stored Cross-Site Scripting
33RISK
open ↗Referência
CVE-2017-10129
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version
23RISK
open ↗Referência
CVE-2010-0674
StatCounteX 3.1 stores sensitive information under the web root with insufficient access control, which allows remote at
23RISK
open ↗Referência
CVE-2010-0674
StatCounteX 3.1 stores sensitive information under the web root with insufficient access control, which allows remote at
23RISK
open ↗Referência
CVE-2012-6048
Guitar Pro 6.1.1 r10791 allows remote attackers to cause a denial of service (crash) via a long string in a gpx file.
23RISK
open ↗Referência
CVE-2010-0939
Visialis ABB Forum 1.1 stores sensitive information under the web root with insufficient access control, which allows re
23RISK
open ↗Referência
CVE-2010-0939
Visialis ABB Forum 1.1 stores sensitive information under the web root with insufficient access control, which allows re
23RISK
open ↗Referência
CVE-2010-0765
fipsForum 2.6 stores sensitive information under the web root with insufficient access control, which allows remote atta
23RISK
open ↗Referência
CVE-2004-1580
SQL injection vulnerability in index.php in CubeCart 2.0.1 allows remote attackers to execute arbitrary SQL commands via
23RISK
open ↗Referência✓ VexDay Proof
vhostadmin 0.1 - 'MODULES_DIR' Remote File Inclusion
PHP remote file inclusion vulnerability in modules/mail/main.php in Inter7 vHostAdmin 1.0 allows remote attackers to exe
23RISK
open ↗Referência
CVE-2018-11532
An issue was discovered in the ChangUonDyU Advanced Statistics plugin 1.0.2 for MyBB. changstats.php has XSS, as demonst
23RISK
open ↗Referência
CVE-2009-2263
Directory traversal vulnerability in index.php in Awesome PHP Mega File Manager 1.0 allows remote attackers to include a
23RISK
open ↗Referência
CVE-2010-2721
SQL injection vulnerability in index.php in RightInPoint Lyrics Script 3.0 allows remote attackers to execute arbitrary
23RISK
open ↗Referência
CVE-2010-2721
SQL injection vulnerability in index.php in RightInPoint Lyrics Script 3.0 allows remote attackers to execute arbitrary
23RISK
open ↗Referência✓ VexDay Proof
jGallery 1.3 - 'index.php' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in jGallery 1.3 allows remote attackers to execute arbitrary PHP co
23RISK
open ↗Referência✓ VexDay Proof
Squirrelcart 1.x - 'cart.php' Remote File Inclusion
PHP remote file inclusion vulnerability in popup_window.php in Squirrelcart 1.x.x and earlier allows remote attackers to
23RISK
open ↗Referência✓ VexDay Proof
PEEL CMS 3.x - Admin Hash Extraction / Arbitrary File Upload
PEEL, possibly 3.x and earlier, allows remote attackers to obtain configuration information via a direct request to phpi
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.