Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,331cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,721GitHub PoC 14,484VulnCheck XDB 8,829Nuclei 4,350Metasploit 3,489✓ verified onlyrecentpopularrisk
22,721 exploits
Referência
CVE-2023-0904
SourceCodester Employee Task Management System task-details.php sql injection
33RISK
open ↗Referência
CVE-2008-5970
SQL injection vulnerability in profile_social.php in i-Net Solution Orkut Clone allows remote authenticated users to exe
23RISK
open ↗Referência★ 47
Unauthenticated RCE on CraftCMS when PHP `register_argc_argv` config setting is enabled
RCE when PHP `register_argc_argv` config setting is enabled in craftcms/cms
100RISK
open ↗Referência
CVE-2016-7288
The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (m
35RISK
open ↗Referência✓ VexDay Proof
PHP iCalendar 2.24 - 'cookie_language' Local File Inclusion / Arbitrary File Upload
Directory traversal vulnerability in print.php in PHP iCalendar 2.24 and earlier allows remote attackers to include and
23RISK
open ↗Referência
CVE-2026-19823
Tenda W20E QoS Rule Deletion delQos formQOSRuleDel stack-based overflow
41RISK
open ↗Referência✓ VexDay Proof
AllMyGuests 0.4.1 - 'AMG_id' SQL Injection
SQL injection vulnerability in index.php in Voice Of Web AllMyGuests 0.4.1 allows remote attackers to execute arbitrary
23RISK
open ↗Referência✓ VexDay Proof
Aterr 0.9.1 - PHP5 Local File Inclusion
Multiple directory traversal vulnerabilities in Aterr 0.9.1 allow remote attackers to include and execute arbitrary loca
23RISK
open ↗Referência
CVE-2019-9082
ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public/
100RISK
open ↗Referência✓ VexDay Proof
Acidcat CMS 3.4.1 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in Acidcat CMS 3.4.1 allow remote attackers to execute arbitrary SQL commands via
23RISK
open ↗Referência✓ VexDay Proof
Watchfire Appscan 7.0 - ActiveX Multiple Insecure Methods
Multiple absolute path traversal vulnerabilities in certain ActiveX controls in WatchFire AppScan 7.0 allow remote attac
23RISK
open ↗Referência
CVE-2021-40964
A Path Traversal vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to
23RISK
open ↗Referência
CVE-2019-0230
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lea
60RISK
open ↗Referência
CVE-2019-0230
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lea
60RISK
open ↗Referência
CVE-2026-19812
TOTOLINK A800R product.so cstecgi.cgi UploadCustomModule stack-based overflow
41RISK
open ↗Referência
CVE-2021-41318
In Progress WhatsUp Gold prior to version 21.1.0, an application endpoint failed to adequately sanitize malicious input.
23RISK
open ↗Referência
CVE-2026-19811
TOTOLINK A800R firewall.so cstecgi.cgi setIpQosRules stack-based overflow
41RISK
open ↗Referência
CVE-2026-18039
Essential Addons for Elementor < 6.7.2 - Unauthenticated Privilege Escalation via Custom Profile Field Mass Assignment
41RISK
open ↗Referência
CVE-2026-16739
Epeken All Kurir <= 2.1.2 - Unauthenticated Order Payment Confirmation Forgery
33RISK
open ↗Referência
CVE-2017-3248
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Core Components). Suppo
60RISK
open ↗Referência✓ VexDay Proof
Uploader & Downloader 3.0 - 'id_user' SQL Injection
SQL injection vulnerability in administration/administre2.php in Eric GUILLAUME uploader&downloader 3 allows remote atta
23RISK
open ↗Referência✓ VexDay Proof
Bandwebsite 1.5 - 'LOGIN' Remote Add Admin
Bandwebsite (aka Bandsite portal system) 1.5 allows remote attackers to create administrative accounts via a direct requ
23RISK
open ↗Referência✓ VexDay Proof
Megabbs Forum 2.2 - SQL Injection / Cross-Site Scripting
Multiple SQL injection vulnerabilities in PD9 Software MegaBBS 2.2 allow remote attackers to execute arbitrary SQL comma
23RISK
open ↗Referência✓ VexDay Proof
MiniBB 2.2 - Cross-Site Scripting / SQL Injection / Full Path Disclosure
Cross-site scripting (XSS) vulnerability in index.php in miniBB 2.2, and possibly earlier, when register_globals is enab
23RISK
open ↗Referência
CVE-2025-34028
Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal
100RISK
open ↗Referência★ 21
watchtowrlabs/watchTowr-vs-Commvault-PreAuth-RCE-CVE-2025-34028
Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal
100RISK
open ↗Referência
Payara Micro Community 5.2021.6 - Directory Traversal
Payara Micro Community 5.2021.6 and below allows Directory Traversal.
50RISK
open ↗Referência
CVE-2023-1671
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.