Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,058cataloged exploits
35,300CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,175GitHub PoC 14,096VulnCheck XDB 8,607Nuclei 4,255Metasploit 3,474✓ verified onlyrecentpopularrisk
22,166 exploits
Referência✓ VexDay Proof
Mambo Component com_Musica - 'id' SQL Injection
SQL injection vulnerability in the com_musica module in Joomla! and Mambo allows remote attackers to execute arbitrary S
23RISK
open ↗Referência✓ VexDay Proof
SFS EZ Software - 'id' SQL Injection
SQL injection vulnerability in software-description.php in Scripts For Sites (SFS) Hotscripts-like Site allows remote at
23RISK
open ↗Referência
snapd < 2.37 (Ubuntu) - 'dirty_sock' Local Privilege Escalation (1)
Local privilege escalation via snapd socket
53RISK
open ↗Referência
CVE-2019-7440
JioFi 4G M2S 1.0.2 devices have CSRF via the SSID name and Security Key field under Edit Wi-Fi Settings (aka a SetWiFi_S
23RISK
open ↗Referência
CVE-2019-8452
A hard-link created from log file archive of Check Point ZoneAlarm up to 15.4.062 or Check Point Endpoint Security clien
23RISK
open ↗Referência
CVE-2026-8211
codelibs Fess JSP File AdminDesignAction.java update code injection
33RISK
open ↗Referência
CVE-2026-16205
Pluck CMS Albums albums.admin.php htmlspecialchars_decode cross site scripting
33RISK
open ↗Referência
CVE-2014-8998
lib/message.php in X7 Chat 2.0.0 through 2.0.5.1 allows remote authenticated users to execute arbitrary PHP code via a c
50RISK
open ↗Referência
CVE-2014-8998
lib/message.php in X7 Chat 2.0.0 through 2.0.5.1 allows remote authenticated users to execute arbitrary PHP code via a c
50RISK
open ↗Referência
CVE-2014-9004
Cross-site scripting (XSS) vulnerability in vldPersonals before 2.7.1 allows remote attackers to inject arbitrary web sc
23RISK
open ↗Referência
CVE-2014-9014
Directory traversal vulnerability in the ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin b
28RISK
open ↗Referência
CVE-2026-9515
Totolink CA750-PoE Setting cstecgi.cgi setUnloadUserData os command injection
38RISK
open ↗Referência
CVE-2026-9514
Totolink CA750-PoE Setting cstecgi.cgi setNetworkDiag os command injection
38RISK
open ↗Referência✓ VexDay Proof
Active Web Helpdesk 2 - 'categoryId' Blind SQL Injection
SQL injection vulnerability in default.aspx in Active Web Helpdesk 2.0 allows remote attackers to execute arbitrary SQL
23RISK
open ↗Referência
CVE-2011-4825
Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinym
50RISK
open ↗Referência
CVE-2014-9456
Buffer overflow in NotePad++ 6.6.9 allows remote attackers to have unspecified impact via a long Time attribute in an Ev
28RISK
open ↗Referência
CVE-2026-9468
dazeb cline-mcp-memory-bank index.ts handleInitializeMemoryBank path traversal
33RISK
open ↗Referência✓ VexDay Proof
Quick Tree View .NET 3.1 - Database Disclosure
Quick Tree View .NET 3.1 stores sensitive information under the web root with insufficient access control, which allows
23RISK
open ↗Referência
CVE-2019-9162
In the Linux kernel before 4.20.12, net/ipv4/netfilter/nf_nat_snmp_basic_main.c in the SNMP NAT module has insufficient
23RISK
open ↗Referência
CVE-2014-9613
Multiple SQL injection vulnerabilities in Netsweeper before 2.6.29.10 allow remote attackers to execute arbitrary SQL co
23RISK
open ↗Referência
CVE-2014-9641
The tmeext.sys driver before 2.0.0.1015 in Trend Micro Antivirus Plus, Internet Security, and Maximum Security allows lo
23RISK
open ↗Referência
CVE-2011-4829
SQL injection vulnerability in the com_listing component in Barter Sites component 1.3 for Joomla! allows remote attacke
23RISK
open ↗Referência
CVE-2019-9193
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISK
open ↗Referência
CVE-2019-9193
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISK
open ↗Referência
CVE-2019-9213
In the Linux kernel before 4.20.14, expand_downwards in mm/mmap.c lacks a check for the mmap minimum address, which make
38RISK
open ↗Referência
CVE-2019-9213
In the Linux kernel before 4.20.14, expand_downwards in mm/mmap.c lacks a check for the mmap minimum address, which make
38RISK
open ↗Referência
CVE-2019-9491
Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to
28RISK
open ↗Referência
Bolt CMS 3.6.4 - Cross-Site Scripting
Bolt 3.6.4 has XSS via the slug, teaser, or title parameter to editcontent/pages, a related issue to CVE-2017-11128 and
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.