Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,058cataloged exploits
35,300CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,175GitHub PoC 14,096VulnCheck XDB 8,607Nuclei 4,255Metasploit 3,474✓ verified onlyrecentpopularrisk
22,166 exploits
Referência✓ VexDay Proof
TaskTracker 1.5 - 'Customize.asp' Remote Add Administrator
Geckovich TaskTracker Pro 1.5 and earlier allows remote attackers to add administrative or other accounts via an Add act
23RISK
open ↗Referência
CVE-2010-3437
Integer signedness error in the pkt_find_dev_from_minor function in drivers/block/pktcdvd.c in the Linux kernel before 2
23RISK
open ↗Referência
CVE-2010-4980
SQL injection vulnerability in packagedetails.php in iScripts ReserveLogic 1.0 allows remote attackers to execute arbitr
23RISK
open ↗Referência
CVE-2010-4980
SQL injection vulnerability in packagedetails.php in iScripts ReserveLogic 1.0 allows remote attackers to execute arbitr
23RISK
open ↗Referência✓ VexDay Proof
GGCMS 1.1.0 RC1 - Remote Code Execution
Directory traversal vulnerability in admin/subpages.php in GGCMS 1.1.0 RC1 and earlier allows remote attackers to inject
23RISK
open ↗Referência✓ VexDay Proof
Garennes 0.6.1 - 'repertoire_config' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Garennes 0.6.1 and earlier allow remote attackers to execute arbit
23RISK
open ↗Referência✓ VexDay Proof
GoSamba 1.0.1 - 'INCLUDE_PATH' Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in GoSamba 1.0.1 allow remote attackers to execute arbitrary PHP code
23RISK
open ↗Referência✓ VexDay Proof
Postfix 2.6-20080814 - 'symlink' Local Privilege Escalation
Postfix before 2.3.15, 2.4 before 2.4.8, 2.5 before 2.5.4, and 2.6 before 2.6-20080814, when the operating system suppor
23RISK
open ↗Referência✓ VexDay Proof
iyzi Forum 1.0b3 - Database Disclosure
iyzi Forum 1.0 beta 3 stores sensitive information under the web root with insufficient access control, which allows rem
23RISK
open ↗Referência
CVE-2021-40577
A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Online Enrollment Management System in PHP an
23RISK
open ↗Referência
CVE-2010-5057
SQL injection vulnerability in detResolucion.php in CMS Ariadna 1.1 allows remote attackers to execute arbitrary SQL com
23RISK
open ↗Referência✓ VexDay Proof
inertianews 0.02b - 'inertianews_main.php' Remote File Inclusion
PHP remote file inclusion vulnerability in inertianews_main.php in inertianews 0.02 beta allows remote attackers to exec
23RISK
open ↗Referência✓ VexDay Proof
EQdkp 1.3.1 - 'Referer Spoof' Remote Database Backup
EQdkp 1.3.1 and earlier authenticates administrative requests by verifying that the HTTP Referer header specifies an adm
23RISK
open ↗Referência
CVE-2009-3064
Directory traversal vulnerability in debugger/debug_php.php in Ve-EDIT 0.1.4 allows remote attackers to include and exec
23RISK
open ↗Referência
CVE-2009-3824
Directory traversal vulnerability in include/processor.php in Greenwood PHP Content Manager 0.3.2 allows remote attacker
23RISK
open ↗Referência
CVE-2010-2905
SQL injection vulnerability in info.php in ScriptsFeed and BrotherScripts (BS) Scripts Directory allows remote attackers
23RISK
open ↗Referência
CVE-2007-1580
FTPDMIN 0.96 allows remote attackers to cause a denial of service (daemon crash) via a LIST command for a Windows drive
23RISK
open ↗Referência✓ VexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to enable
23RISK
open ↗Referência✓ VexDay Proof
The Everything Development System Pre-1.0 - SQL Injection
The Everything Development Engine in The Everything Development System Pre-1.0 and earlier stores passwords in cleartext
23RISK
open ↗Referência✓ VexDay Proof
Phoenix View CMS Pre Alpha2 - SQL Injection / Local File Inclusion / Cross-Site Scripting
Directory traversal vulnerability in admin/admin_frame.php in Phoenix View CMS Pre Alpha2 and earlier allows remote atta
23RISK
open ↗Referência✓ VexDay Proof
CubeCart 3.0.6 - Remote Command Execution
PHP remote file include vulnerability in includes/orderSuccess.inc.php in CubeCart allows remote attackers to execute ar
23RISK
open ↗Referência✓ VexDay Proof
Poppler 0.8.4 - libpoppler Uninitialized pointer Code Execution
The Page destructor in Page.cc in libpoppler in Poppler 0.8.4 and earlier deletes a pageWidgets object even if it is not
28RISK
open ↗Referência✓ VexDay Proof
CMS Mini 0.2.2 - Multiple Local File Inclusions
Multiple directory traversal vulnerabilities in view/index.php in CMS Mini 0.2.2 allow remote attackers to read arbitrar
23RISK
open ↗Referência
CVE-2012-2588
Multiple cross-site scripting (XSS) vulnerabilities in MailEnable Enterprise 6.5 allow remote attackers to inject arbitr
23RISK
open ↗Referência
CVE-2010-2910
SQL injection vulnerability in the Ozio Gallery (com_oziogallery) component for Joomla! allows remote attackers to execu
23RISK
open ↗Referência
CVE-2013-5117
SQL injection vulnerability in the RSS page (DNNArticleRSS.aspx) in the ZLDNN DNNArticle module before 10.1 for DotNetNu
23RISK
open ↗Referência✓ VexDay Proof
Smeego 1.0 - 'Cookie lang' Local File Inclusion
Directory traversal vulnerability in index.php in Smeego 1.0, when magic_quotes_gpc is disabled, allows remote attackers
23RISK
open ↗Referência✓ VexDay Proof
Pixie CMS - Cross-Site Scripting / SQL Injection
SQL injection vulnerability in the referral function in admin/lib/lib_logs.php in Pixie CMS 1.01a allows remote attacker
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.