Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,449cataloged exploits
35,552CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,367GitHub PoC 14,225VulnCheck XDB 8,649Nuclei 4,283Metasploit 3,474✓ verified onlyrecentpopularrisk
22,367 exploits
Referência✓ VexDay Proof
SolarCMS 0.53.8 - 'Forum' Remote Cookies Disclosure
SQL injection vulnerability in Forum.php in SolarCMS 0.53.8 and 1.0 allows remote attackers to execute arbitrary SQL com
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component ongumatimesheet20 4b - Remote File Inclusion
PHP remote file inclusion vulnerability in lib/onguma.class.php in the Onguma Time Sheet (com_ongumatimesheet20) 2.0 4b
28RISK
open ↗Referência✓ VexDay Proof
DevelopItEasy Photo Gallery 1.2 - SQL Injection
Multiple SQL injection vulnerabilities in DevelopItEasy Photo Gallery 1.2 allow remote attackers to execute arbitrary SQ
23RISK
open ↗Referência✓ VexDay Proof
TurnkeyForms Business Survey Pro 1.0 - 'id' SQL Injection
SQL injection vulnerability in survey_results_text.php in TurnkeyForms Business Survey Pro 1.0 allows remote attackers t
23RISK
open ↗Referência
CVE-2018-17456
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x be
60RISK
open ↗Referência
CVE-2023-27524
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISK
open ↗Referência
CVE-2020-17506
Artica Web Proxy 4.30.00000000 allows remote attacker to bypass privilege detection and gain web backend administrator p
60RISK
open ↗Referência
CVE-2023-27524
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISK
open ↗Referência✓ VexDay Proof
Rae Media Contact MS - Authentication Bypass
SQL injection vulnerability in asadmin/default.asp in Rae Media Contact Management Software SOHO, Standard, and Enterpri
23RISK
open ↗Referência
CVE-2015-7857
SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.p
60RISK
open ↗Referência
CVE-2015-7857
SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.p
60RISK
open ↗Referência
CVE-2019-16172
LimeSurvey before v3.17.14 allows stored XSS for escalating privileges from a low-privileged account to, for example, Su
23RISK
open ↗Referência
CVE-2017-5753
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of
55RISK
open ↗Referência
CVE-2008-6392
SQL injection vulnerability in showads.php in Z1Exchange allows remote attackers to execute arbitrary SQL commands via t
23RISK
open ↗Referência
CVE-2018-14933
upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir par
100RISK
open ↗Referência
CyberArk Viewfinity 5.5.10.95 - Local Privilege Escalation
In CyberArk Viewfinity 5.5.10.95 and 6.x before 6.1.1.220, a low privilege user can escalate to an administrative user v
41RISK
open ↗Referência
CVE-2015-5122
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player
100RISK
open ↗Referência
CVE-2017-1129
IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it coul
50RISK
open ↗Referência
CVE-2019-15976
Cisco Data Center Network Manager Authentication Bypass Vulnerabilities
70RISK
open ↗Referência✓ VexDay Proof
HotScripts Clone - 'cid' SQL Injection
SQL injection vulnerability in showcategory.php in Hotscripts Clone allows remote attackers to execute arbitrary SQL com
23RISK
open ↗Referência✓ VexDay Proof
Ol BookMarks Manager 0.7.5 - Local File Inclusion / Remote File Inclusion / SQL Injection
PHP remote file inclusion vulnerability in frame.php in ol'bookmarks manager 0.7.5 allows remote attackers to execute ar
23RISK
open ↗Referência
CVE-2012-1297
Multiple cross-site request forgery (CSRF) vulnerabilities in main.php in Contao (formerly TYPOlight) 2.11.0 and earlier
23RISK
open ↗Referência✓ VexDay Proof
Ol BookMarks Manager 0.7.5 - Local File Inclusion / Remote File Inclusion / SQL Injection
SQL injection vulnerability in index.php in ol'bookmarks manager 0.7.5 allows remote attackers to execute arbitrary SQL
23RISK
open ↗Referência
CVE-2012-1297
Multiple cross-site request forgery (CSRF) vulnerabilities in main.php in Contao (formerly TYPOlight) 2.11.0 and earlier
23RISK
open ↗Referência✓ VexDay Proof
AJ Auction Pro Platinum Skin - 'item_id' SQL Injection
SQL injection vulnerability in detail.php in AJ Auction Pro Platinum Skin 2 allows remote attackers to execute arbitrary
23RISK
open ↗Referência✓ VexDay Proof
Social Site Generator 2.0 - 'sgc_id' SQL Injection
Multiple SQL injection vulnerabilities in Social Site Generator (SSG) 2.0 allow remote attackers to execute arbitrary SQ
23RISK
open ↗Referência✓ VexDay Proof
Social Site Generator 2.0 - Multiple Remote File Disclosure Vulnerabilities
Social Site Generator (SSG) 2.0 allows remote attackers to read arbitrary files via the file parameter to (1) filedload.
23RISK
open ↗Referência
Inosoft VisiWin 7 2022-2.1 - Insecure Folders Permissions
An issue was discovered in Inosoft VisiWin 7 through 2022-2.1 (Runtime RT7.3 RC3 20221209.5). The "%PROGRAMFILES(X86)%\I
41RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.