Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,151cataloged exploits
35,370CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,233GitHub PoC 14,119VulnCheck XDB 8,617Nuclei 4,257Metasploit 3,474✓ verified onlyrecentpopularrisk
22,175 exploits
Referência
CVE-2016-2386
SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbi
100RISK
open ↗Referência
CVE-2007-6587
SQL injection vulnerability in plog-rss.php in Plogger 1.0 Beta 3.0 allows remote attackers to execute arbitrary SQL com
23RISK
open ↗Referência
CVE-2015-1727
Buffer overflow in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows S
23RISK
open ↗Referência
CVE-2016-2494
Off-by-one error in sdcard/sdcard.c in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before
23RISK
open ↗Referência
CVE-2016-2494
Off-by-one error in sdcard/sdcard.c in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before
23RISK
open ↗Referência
CVE-2016-2776
buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly
60RISK
open ↗Referência
CVE-2018-6372
SQL Injection exists in the JB Bus 2.3 component for Joomla! via the order_number parameter.
23RISK
open ↗Referência✓ VexDay Proof
Gizzar 03162002 - 'index.php' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in Gizzar 03162002 and earlier allows remote attackers to execute a
23RISK
open ↗Referência
CVE-2016-3081
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, a
60RISK
open ↗Referência
CVE-2010-3266
Multiple cross-site scripting (XSS) vulnerabilities in BugTracker.NET before 3.4.5 allow remote authenticated users to i
23RISK
open ↗Referência✓ VexDay Proof
IntelliTamper 2.07 - '.map' Local Arbitrary Code Execution (1)
Stack-based buffer overflow in IntelliTamper 2.07 allows remote attackers to execute arbitrary code via a crafted .map f
23RISK
open ↗Referência✓ VexDay Proof
ACGVclick 0.2.0 - 'path' Remote File Inclusion
PHP remote file inclusion vulnerability in function.inc.php in ACGVclick 0.2.0 and earlier allows remote attackers to ex
23RISK
open ↗Referência
CVE-2016-3081
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, a
60RISK
open ↗Referência
CVE-2014-5090
admin/options/logs.php in Status2k allows remote authenticated administrators to execute arbitrary commands via shell me
23RISK
open ↗Referência✓ VexDay Proof
phpBB MOD Forum picture and META tags 1.7 - Remote File Inclusion
PHP remote file inclusion vulnerability in MOD_forum_fields_parse.php in the Forum picture and META tags 1.7 module for
23RISK
open ↗Referência✓ VexDay Proof
YAAP 1.5 - '__autoload()' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/common.php in Yaap 1.5 and earlier allows remote attackers to execut
23RISK
open ↗Referência
CVE-2017-6547
Cross-site scripting (XSS) vulnerability in httpd on ASUS RT-N56U, RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC
23RISK
open ↗Referência
CVE-2010-4858
Directory traversal vulnerability in team.rc5-72.php in DNET Live-Stats 0.8 allows remote attackers to read arbitrary fi
23RISK
open ↗Referência
CVE-2010-4858
Directory traversal vulnerability in team.rc5-72.php in DNET Live-Stats 0.8 allows remote attackers to read arbitrary fi
23RISK
open ↗Referência
CVE-2016-6772
An elevation of privilege vulnerability in Wi-Fi could enable a local malicious application to execute arbitrary code wi
23RISK
open ↗Referência
CVE-2009-4424
SQL injection vulnerability in results.php in the Pyrmont plugin 2 for WordPress allows remote attackers to execute arbi
23RISK
open ↗Referência
CVE-2009-4424
SQL injection vulnerability in results.php in the Pyrmont plugin 2 for WordPress allows remote attackers to execute arbi
23RISK
open ↗Referência✓ VexDay Proof
Scallywag - 'template.php?path' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Scallywag 2005-04-25 allow remote attackers to execute arbitrary P
23RISK
open ↗Referência✓ VexDay Proof
phpBB Mod OpenID 0.2.0 - 'BBStore.php' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/openid/Auth/OpenID/BBStore.php in phpBB Openid 0.2.0 allows remote a
23RISK
open ↗Referência✓ VexDay Proof
Flat PHP Board 1.2 - Multiple Vulnerabilities
Multiple directory traversal vulnerabilities in index.php in Flat PHP Board 1.2 and earlier allow remote attackers to (1
23RISK
open ↗Referência✓ VexDay Proof
NmnNewsletter 1.0.7 - 'output' Remote File Inclusion
PHP remote file inclusion vulnerability in confirmUnsubscription.php in NmnNewsletter 1.0.7 allows remote attackers to e
23RISK
open ↗Referência✓ VexDay Proof
Cyberfolio 7.12 - 'rep' Remote File Inclusion
PHP remote file inclusion vulnerability in portfolio/commentaires/derniers_commentaires.php in Cyberfolio 7.12, when reg
23RISK
open ↗Referência✓ VexDay Proof
Million Dollar Text Links 1.0 - Arbitrary Authentication Bypass
Million Dollar Text Links 1.0 does not properly restrict administrator access to admin.home.php, which allows remote att
23RISK
open ↗Referência
CVE-2015-1428
Multiple SQL injection vulnerabilities in Sefrengo before 1.6.2 allow (1) remote attackers to execute arbitrary SQL comm
23RISK
open ↗Referência
CVE-2014-3442
Winamp 5.666 and earlier allows remote attackers to cause a denial of service (memory corruption and crash) via a malfor
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.