Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,401cataloged exploits
35,511CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,332GitHub PoC 14,209VulnCheck XDB 8,646Nuclei 4,289Metasploit 3,474✓ verified onlyrecentpopularrisk
22,332 exploits
Referência
CVE-2011-5173
Buffer overflow in Bugbear Entertainment FlatOut 2005 allows user-assisted remote attackers to cause a denial of service
23RISK
open ↗Referência
CVE-2026-19899
SourceCodester Class and Exam Timetabling System edit_teacher.php sql injection
30RISK
open ↗Referência✓ VexDay Proof
CodeAvalanche Directory - Database Disclosure
CodeAvalanche Directory stores sensitive information under the web root with insufficient access control, which allows r
23RISK
open ↗Referência✓ VexDay Proof
CodeAvalanche FreeForAll - Database Disclosure
CodeAvalanche FreeForAll stores sensitive information under the web root with insufficient access control, which allows
23RISK
open ↗Referência✓ VexDay Proof
CodeAvalanche Articles - Database Disclosure
CodeAvalanche Articles stores sensitive information under the web root with insufficient access control, which allows re
23RISK
open ↗Referência
CVE-2022-43769
Hitachi Vantara Pentaho Business Analytics Server - Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)
100RISK
open ↗Referência✓ VexDay Proof
Active Test 2.1 - Authentication Bypass
Multiple SQL injection vulnerabilities in start.asp in Active Test 2.1 allow remote attackers to execute arbitrary SQL c
23RISK
open ↗Referência
CVE-2026-18216
Backup Migration < 2.1.7 - Admin+ Privilege Escalation via Post-Restore Auto-Login
23RISK
open ↗Referência
CVE-2026-16611
Product Feed PRO for WooCommerce < 13.5.7 - Unauthenticated Feed Configuration Disclosure
23RISK
open ↗Referência✓ VexDay Proof
Gravity GTD 0.4.5 - Local File Inclusion / Remote Code Execution
Directory traversal vulnerability in library/setup/rpc.php in Gravity Getting Things Done (GTD) 0.4.5 and earlier allows
23RISK
open ↗Referência
CVE-2026-16541
Simply Schedule Appointments < 1.6.12.17 - Team Member+ User Email Disclosure via Users and Customers REST Endpoints
23RISK
open ↗Referência
CVE-2026-14230
ECS < 4.3.8 - Contributor+ Stored XSS via Dynamic Repeater Bindings
23RISK
open ↗Referência
EasyNas 1.1.0 - OS Command Injection
EasyNAS backup.pl system os command injection
38RISK
open ↗Referência
CVE-2019-18818
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RISK
open ↗Referência✓ VexDay Proof
LokiCMS 0.3.4 - 'index.php' Arbitrary Check File
Directory traversal vulnerability in index.php in LokiCMS 0.3.4 and earlier, when magic_quotes_gpc is disabled, allows r
23RISK
open ↗Referência
CVE-2023-0902
SourceCodester Simple Food Ordering System process_order.php cross site scripting
28RISK
open ↗Referência
CVE-2025-61884
Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions
100RISK
open ↗Referência
CVE-2026-14229
ECS < 4.3.8 - Unauthenticated Private Content Disclosure via ecsload
23RISK
open ↗Referência✓ VexDay Proof
PHP iCalendar 2.24 - 'cookie_language' Local File Inclusion / Arbitrary File Upload
admin/index.php in PHP iCalendar 2.3.4, 2.24, and earlier does not require administrative authentication for an addupdat
23RISK
open ↗Referência✓ VexDay Proof
Ocean12 Mailing List Manager Gold - File Disclosure / SQL Injection / Cross-Site Scripting
Multiple SQL injection vulnerabilities in Ocean12 Mailing List Manager Gold allow remote attackers to execute arbitrary
23RISK
open ↗Referência✓ VexDay Proof
Jetik Emlak ESA 2.0 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in Jetik Emlak Sistem A (ESA) 2.0 allow remote attackers to execute arbitrary SQL
23RISK
open ↗Referência✓ VexDay Proof
I-Rater Basic - SQL Injection
SQL injection vulnerability in messages.php in I-Rater Basic allows remote attackers to execute arbitrary SQL commands v
23RISK
open ↗Referência
CVE-2019-0230
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lea
60RISK
open ↗Referência
CVE-2019-0230
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lea
60RISK
open ↗Referência
CVE-2026-19812
TOTOLINK A800R product.so cstecgi.cgi UploadCustomModule stack-based overflow
41RISK
open ↗Referência✓ VexDay Proof
Uploader & Downloader 3.0 - 'id_user' SQL Injection
SQL injection vulnerability in administration/administre2.php in Eric GUILLAUME uploader&downloader 3 allows remote atta
23RISK
open ↗Referência
CVE-2026-19811
TOTOLINK A800R firewall.so cstecgi.cgi setIpQosRules stack-based overflow
41RISK
open ↗Referência
CVE-2026-18039
Essential Addons for Elementor < 6.7.2 - Unauthenticated Privilege Escalation via Custom Profile Field Mass Assignment
41RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.