Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,151cataloged exploits
35,370CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,233GitHub PoC 14,119VulnCheck XDB 8,617Nuclei 4,257Metasploit 3,474✓ verified onlyrecentpopularrisk
22,175 exploits
Referência
CVE-2018-6593
An issue was discovered in MalwareFox AntiMalware 2.74.0.150. Improper access control in zam32.sys and zam64.sys allows
23RISK
open ↗Referência✓ VexDay Proof
File Upload Manager 1.0.6 - 'detail.asp' SQL Injection
SQL injection vulnerability in detail.asp in Mxmania File Upload Manager (FUM) 1.0.6 and earlier allows remote attackers
23RISK
open ↗Referência
CVE-2019-18862
maidag in GNU Mailutils before 3.8 is installed setuid and allows local privilege escalation in the url mode.
23RISK
open ↗Referência✓ VexDay Proof
XBrite Members 1.1 - 'id' SQL Injection
SQL injection vulnerability in members.php in XBrite Members 1.1 and earlier allows remote attackers to execute arbitrar
23RISK
open ↗Referência✓ VexDay Proof
Dynamic photo Gallery 1.02 - 'albumID' SQL Injection
SQL injection vulnerability in album.php in PHP WEB SCRIPT Dynamic Photo Gallery 1.02 allows remote attackers to execute
23RISK
open ↗Referência
CVE-2018-10809
In 2345 Security Guard 3.7, the driver file (2345NetFirewall.sys) allows local users to cause a denial of service (BSOD)
23RISK
open ↗Referência
CVE-2025-34074
Lucee Admin Interface Authenticated Remote Code Execution via Scheduled Job File Write
63RISK
open ↗Referência
Mersive Solstice 2.8.0 - Remote Code Execution
Insufficient validation of user-supplied input for the Solstice Pod before 2.8.4 networking configuration enables authen
28RISK
open ↗Referência
CVE-2017-7154
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RISK
open ↗Referência✓ VexDay Proof
XMB 1.9.6 Final - 'basename()' Remote Command Execution
Directory traversal vulnerability in memcp.php in XMB (Extreme Message Board) 1.9.6 and earlier allows remote attackers
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component D4JeZine 2.8 - Blind SQL Injection
SQL injection vulnerability in index.php in the DesignForJoomla.com D4J eZine (com_ezine) 2.8 and earlier component for
23RISK
open ↗Referência
CVE-2017-12971
Cross-site scripting (XSS) vulnerability in Apache2Triad 1.5.4 allows remote attackers to inject arbitrary web script or
23RISK
open ↗Referência✓ VexDay Proof
phpDirectorySource 1.1 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in phpDirectorySource 1.1.06, when magic_quotes_gpc is disabled, allow remote att
23RISK
open ↗Referência✓ VexDay Proof
SazCart 1.5.1 - 'prodid' SQL Injection
SQL injection vulnerability in index.php in SazCart 1.5.1 and earlier, when magic_quotes_gpc is disabled, allows remote
23RISK
open ↗Referência
CVE-2017-12984
PHPMyWind 5.3 has XSS in shoppingcart.php, related to message.php, admin/message.php, and admin/message_update.php.
23RISK
open ↗Referência✓ VexDay Proof
Article Friendly Pro/Standard - SQL Injection
SQL injection vulnerability in categorydetail.php in Article Friendly Standard allows remote attackers to execute arbitr
23RISK
open ↗Referência
CVE-2012-5865
SQL injection vulnerability in dispatch.php in Achievo 1.4.5 allows remote authenticated users to execute arbitrary SQL
23RISK
open ↗Referência✓ VexDay Proof
Alt-N SecurityGateway 1.0.1 - 'Username' Remote Buffer Overflow (PoC)
Stack-based buffer overflow in SecurityGateway.dll in Alt-N Technologies SecurityGateway 1.0.1 allows remote attackers t
60RISK
open ↗Referência
CVE-2014-2531
SQL injection vulnerability in xhr.php in InterWorx Web Control Panel (aka InterWorx Hosting Control Panel and InterWorx
23RISK
open ↗Referência
CVE-2022-42109
Online-shopping-system-advanced 1.0 was discovered to contain a SQL injection vulnerability via the p parameter at /shop
48RISK
open ↗Referência
CVE-2012-4258
Multiple SQL injection vulnerabilities in MYRE Real Estate Software (2012 Q2) allow remote attackers to execute arbitrar
23RISK
open ↗Referência
CVE-2010-2714
SQL injection vulnerability in photos/index.php in TCW PHP Album 1.0 allows remote attackers to execute arbitrary SQL co
23RISK
open ↗Referência✓ VexDay Proof
CzarNews 1.20 - 'cookie' SQL Injection
SQL injection vulnerability in cn_users.php in CzarNews 1.20 and earlier allows remote attackers to execute arbitrary SQ
23RISK
open ↗Referência✓ VexDay Proof
Pardal CMS 0.2.0 - Blind SQL Injection
SQL injection vulnerability in comentar.php in Pardal CMS 0.2.0 and earlier allows remote attackers to execute arbitrary
23RISK
open ↗Referência✓ VexDay Proof
PHP Director 0.21 - Remote Command Execution
SQL injection vulnerability in index.php in PHP Director 0.21 and earlier allows remote attackers to execute arbitrary S
23RISK
open ↗Referência✓ VexDay Proof
EZ-Blog Beta2 - 'category' SQL Injection
SQL injection vulnerability in public/specific.php in EZ-Blog before Beta 2 20090427, when magic_quotes_gpc is disabled,
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.