Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,231cataloged exploits
35,420CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,266GitHub PoC 14,131VulnCheck XDB 8,635Nuclei 4,274Metasploit 3,474✓ verified onlyrecentpopularrisk
22,233 exploits
Referência
CVE-2022-50992
Weaver E-cology 9.5 Unauthenticated Arbitrary File Read via XmlRpcServlet
41RISK
open ↗Referência
CVE-2022-50992
Weaver E-cology 9.5 Unauthenticated Arbitrary File Read via XmlRpcServlet
41RISK
open ↗Referência
CVE-2022-50993
Weaver E-office < 10.0_20221201 Unauthenticated Arbitrary File Read via XmlRpcServlet
48RISK
open ↗Referência
CVE-2022-50993
Weaver E-office < 10.0_20221201 Unauthenticated Arbitrary File Read via XmlRpcServlet
48RISK
open ↗Referência
CVE-2025-71284
Synway SMG Gateway Management Software OS Command Injection via radius_address
48RISK
open ↗Referência
CVE-2010-4365
SQL injection vulnerability in JE Ajax Event Calendar (com_jeajaxeventcalendar) component for Joomla! allows remote atta
23RISK
open ↗Referência
CVE-2010-4365
SQL injection vulnerability in JE Ajax Event Calendar (com_jeajaxeventcalendar) component for Joomla! allows remote atta
23RISK
open ↗Referência
CVE-2010-4366
Multiple cross-site scripting (XSS) vulnerabilities in forum_new_topic.php in Chameleon Social Networking allow remote a
23RISK
open ↗Referência
CVE-2010-5016
SQL injection vulnerability in matchdb.php in Elite Gaming Ladders 3.5 and earlier allows remote attackers to execute ar
23RISK
open ↗Referência✓ VexDay Proof
Pre Real Estate Listings - Authentication Bypass
SQL injection vulnerability in manager/login.php in Pre Projects Pre Real Estate Listings allows remote attackers to exe
23RISK
open ↗Referência✓ VexDay Proof
Pre Real Estate Listings - Arbitrary File Upload
Multiple SQL injection vulnerabilities in login.php in Pre Projects Pre Real Estate Listings allow remote attackers to e
23RISK
open ↗Referência✓ VexDay Proof
Tribiq CMS 5.0.9a (Beta) - Insecure Cookie Handling
Tribiq CMS 5.0.9a beta allows remote attackers to bypass authentication and gain administrative access by setting the CO
23RISK
open ↗Referência✓ VexDay Proof
7Shop 1.1 - Arbitrary File Upload
Unrestricted file upload vulnerability in includes/imageupload.php in 7Shop 1.1 and earlier allows remote attackers to e
23RISK
open ↗Referência
CVE-2017-8656
Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code
35RISK
open ↗Referência✓ VexDay Proof
SFS EZ Link Directory - 'cat_id' SQL Injection
SQL injection vulnerability in links.php in Scripts for Sites (SFS) EZ Link Directory allows remote attackers to execute
23RISK
open ↗Referência✓ VexDay Proof
Booking Centre 2.01 - 'HotelID' SQL Injection
SQL injection vulnerability in hotel_habitaciones.php in Venalsur Booking Centre Booking System for Hotels Group 2.01 al
23RISK
open ↗Referência
CVE-2017-8671
Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary
35RISK
open ↗Referência✓ VexDay Proof
Booking Centre 2.01 - Authentication Bypass
Multiple SQL injection vulnerabilities in admin/checklogin.php in Venalsur Booking Centre Booking System for Hotels Grou
23RISK
open ↗Referência✓ VexDay Proof
PHPwebnews 0.2 MySQL Edition - 'det' SQL Injection
SQL injection vulnerability in bukutamu.php in phpWebNews 0.2 MySQL Edition allows remote attackers to execute arbitrary
23RISK
open ↗Referência✓ VexDay Proof
Absolute Banner Manager - Insecure Cookie Handling
Absolute Banner Manager .NET 4.0 allows remote attackers to bypass authentication and gain administrative access by sett
23RISK
open ↗Referência✓ VexDay Proof
Absolute Control Panel XE 1.5 - Insecure Cookie Handling
Xigla Software Absolute Control Panel XE 1.5 allows remote attackers to bypass authentication and gain administrative ac
23RISK
open ↗Referência
CVE-2026-30368
A client-side authorization flaw in Lightspeed Classroom v5.1.2.1763770643 allows unauthenticated attackers to impersona
33RISK
open ↗Referência
CVE-2026-6942
radare2-mcp <=1.6.0 OS Command Injection via Shell Metacharacter Bypass
28RISK
open ↗Referência
CVE-2026-6940
radare2 < 6.1.4 Project Deletion Path Traversal Directory Deletion
13RISK
open ↗Referência
CVE-2026-23751
Kofax Capture 6.0.0.0 Unauthenticated File Read/Write & SMB Coercion via .NET Remoting
48RISK
open ↗Referência
CVE-2026-41460
SocialEngine <= 7.8.0 SQL Injection via activity/index/get-memberall
48RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.