Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,302cataloged exploits
35,469CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,301GitHub PoC 14,141VulnCheck XDB 8,646Nuclei 4,289Metasploit 3,474✓ verified onlyrecentpopularrisk
22,301 exploits
Referência
CVE-2026-16069
Brizy - Page Builder < 2.8.19 - Contributor+ Stored XSS via Featured Image Focal Point
33RISK
open ↗Referência
CVE-2026-16068
Brizy - Page Builder < 2.8.19 - Author+ Stored XSS via brizy_set_project Global Project Code Asset
28RISK
open ↗Referência
CVE-2020-25762
An issue was discovered in SourceCodester Seat Reservation System 1.0. The file admin_class.php does not perform input v
28RISK
open ↗Referência✓ VexDay Proof
Shop Script Pro 2.12 - SQL Injection
SQL injection vulnerability in index.php in Shop-Script Pro 2.12, when magic_quotes_gpc is disabled, allows remote attac
23RISK
open ↗Referência
CVE-2020-25762
An issue was discovered in SourceCodester Seat Reservation System 1.0. The file admin_class.php does not perform input v
28RISK
open ↗Referência✓ VexDay Proof
yogurt 0.3 - Cross-Site Scripting / SQL Injection
SQL injection vulnerability in writemessage.php in Yogurt 0.3, when register_globals is enabled, allows remote authentic
23RISK
open ↗Referência✓ VexDay Proof
PHPCollegeExchange 0.1.5c - 'listing_view.php?itemnr' SQL Injection
SQL injection vulnerability in house/listing_view.php in phpCollegeExchange 0.1.5c allows remote attackers to execute ar
23RISK
open ↗Referência✓ VexDay Proof
PHPortal 1 - 'topicler.php?id' SQL Injection
SQL injection vulnerability in topicler.php in phPortal 1.0 allows remote attackers to execute arbitrary SQL commands vi
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component com_iJoomla_rss - Blind SQL Injection
SQL injection vulnerability in the iJoomla RSS Feeder (com_ijoomla_rss) component for Joomla! allows remote attackers to
23RISK
open ↗Referência
Genexis Platinum 4410 Router 2.1 - UPnP Credential Exposure
UPNP Service listening on port 5555 in Genexis Platinum 4410 Router V2.1 (P4410-V2–1.34H) has an action 'X_GetAccess' wh
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component Jumi - 'fileid' Blind SQL Injection
SQL injection vulnerability in the Jumi (com_jumi) component 2.0.3 and possibly other versions for Joomla allows remote
23RISK
open ↗Referência
CVE-2020-26567
An issue was discovered on D-Link DSR-250N before 3.17B devices. The CGI script upgradeStatusReboot.cgi can be accessed
28RISK
open ↗Referência✓ VexDay Proof
elvin bts 1.2.0 - Multiple Vulnerabilities
Cross-site request forgery (CSRF) vulnerability in login.php in Elvin 1.2.0 allows remote attackers to hijack the authen
23RISK
open ↗Referência✓ VexDay Proof
elvin bts 1.2.0 - Multiple Vulnerabilities
Elvin 1.2.0 allows remote attackers to read the PHP source code of (1) login.ei, (2) jump_bug.ei, or (3) create_account.
23RISK
open ↗Referência✓ VexDay Proof
phpWebThings 1.5.2 - MD5 Hash Retrieve/File Disclosure
SQL injection vulnerability in fdown.php in phpWebThings 1.5.2 and earlier allows remote attackers to execute arbitrary
23RISK
open ↗Referência
CVE-2020-28328
SuiteCRM before 7.11.17 is vulnerable to remote code execution via the system settings Log File Name setting. In certain
50RISK
open ↗Referência
CVE-2020-28688
The add artwork functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to uplo
28RISK
open ↗Referência
OpenCart 3.0.3.6 - 'Profile Image' Stored Cross-Site Scripting (Authenticated)
OpenCart 3.0.3.6 is affected by cross-site scripting (XSS) in the Profile Image. An admin can upload a profile image as
23RISK
open ↗Referência
CVE-2020-3452
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISK
open ↗Referência
CVE-2021-22205
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open ↗Referência
CVE-2021-22205
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open ↗Referência
CVE-2026-16630
syncfusion ej2-javascript-ui-controls package.json child_process.exec os command injection
33RISK
open ↗Referência
CVE-2026-63108
Roo Code 3.54.0 Command Injection via Parameter Expansion Parsing
41RISK
open ↗Referência
CVE-2026-10724
Reviews Feed < 2.6.5 - Unauthenticated Stored Arbitrary Shortcode Execution via Google Reviews
33RISK
open ↗Referência
CVE-2026-16227
SourceCodester Class and Exam Timetabling System edit_subject.php sql injection
33RISK
open ↗Referência
CVE-2021-22911
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RISK
open ↗Referência
CVE-2021-24145
Modern Events Calendar Lite < 5.16.5 - Authenticated Arbitrary File Upload leading to RCE
60RISK
open ↗Referência
CVE-2021-24276
Contact Form by Supsystic < 1.7.15 - Reflected Cross-Site scripting (XSS)
43RISK
open ↗Referência
CVE-2021-24499
Workreap theme < 2.2.2 - Unauthenticated Upload Leading to Remote Code Execution
50RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.