Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,449cataloged exploits
35,552CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,367GitHub PoC 14,225VulnCheck XDB 8,649Nuclei 4,283Metasploit 3,474✓ verified onlyrecentpopularrisk
22,367 exploits
Referência
TermTalk Server 3.24.0.2 - Arbitrary File Read (Unauthenticated)
A Directory Traversal vulnerability exists in Solari di Udine TermTalk Server (TTServer) 3.24.0.2, which lets an unauthe
50RISK
open ↗Referência✓ VexDay Proof
Booby 1.0.1 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Brim (formerly Booby) 1.0.1 allow remote attackers to execute arbi
35RISK
open ↗Referência
CVE-2016-20016
MVPower CCTV DVR models, including TV-7104HE 1.8.4 115215B9 and TV7108HE, contain a web shell that is accessible via a /
85RISK
open ↗Referência
CVE-2019-1003001
A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.61 and earlier in src/main/java/org/jenkinsci/plugins
60RISK
open ↗Referência
CVE-2018-15379
Cisco Prime Infrastructure Arbitrary File Upload and Command Execution Vulnerability
60RISK
open ↗Referência✓ VexDay Proof
Mambo Component com_lurm_constructor 0.6b - Remote File Inclusion
PHP remote file inclusion vulnerability in admin.lurm_constructor.php in the Lurm Constructor component (com_lurm_constr
23RISK
open ↗Referência
CVE-2013-7091
Directory traversal vulnerability in /res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,ZmKeys,ZdMsg,Ajx%20TemplateMsg.js.zgz in Zim
60RISK
open ↗Referência✓ VexDay Proof
pSlash 0.7 - 'lvc_include_dir' Remote File Inclusion
PHP remote file inclusion vulnerability in modules/visitors2/include/config.inc.php in pSlash 0.70 allows remote attacke
23RISK
open ↗Referência✓ VexDay Proof
PeopleAggregator 1.2pre6-release-53 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in PeopleAggregator 1.2pre6, when register_globals is enabled, allow
35RISK
open ↗Referência
CVE-2022-0482
Exposure of Private Personal Information to an Unauthorized Actor in alextselegidis/easyappointments
75RISK
open ↗Referência
CVE-2022-47878
Incorrect input validation for the default-storage-path in the settings page in Jedox 2020.2.5 allows remote, authentica
60RISK
open ↗Referência
CVE-2019-10945
An issue was discovered in Joomla! before 3.9.5. The Media Manager component does not properly sanitize the folder param
35RISK
open ↗Referência
CVE-2019-10945
An issue was discovered in Joomla! before 3.9.5. The Media Manager component does not properly sanitize the folder param
35RISK
open ↗Referência✓ VexDay Proof
PHP Project Management 0.8.10 - Multiple Local/Remote File Inclusions
Multiple directory traversal vulnerabilities in PHP Project Management 0.8.10 and earlier allow remote attackers to incl
23RISK
open ↗Referência
CVE-2013-2751
Eval injection vulnerability in frontview/lib/np_handler.pl in the FrontView web interface in NETGEAR ReadyNAS RAIDiator
60RISK
open ↗Referência
CVE-2019-16893
The Web Management of TP-Link TP-SG105E V4 1.0.0 Build 20181120 devices allows an unauthenticated attacker to reboot the
35RISK
open ↗Referência
CVE-2020-5735
Amcrest cameras and NVR are vulnerable to a stack-based buffer overflow over port 37777. An authenticated remote attacke
83RISK
open ↗Referência
CVE-2021-43405
An issue was discovered in FusionPBX before 4.5.30. The fax_extension may have risky characters (it is not constrained t
35RISK
open ↗Referência
CVE-2018-11094
An issue was discovered on Intelbras NCLOUD 300 1.0 devices. /cgi-bin/ExportSettings.sh, /goform/updateWPS, /goform/Rebo
35RISK
open ↗Referência
CVE-2015-2456
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
35RISK
open ↗Referência
CVE-2014-3996
SQL injection vulnerability in the LinkViewFetchServlet servlet in ManageEngine Desktop Central (DC) and Desktop Central
50RISK
open ↗Referência
CVE-2017-5792
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.
35RISK
open ↗Referência
CVE-2009-4221
SQL injection vulnerability in classified.php in phpBazar 2.1.1fix and earlier allows remote attackers to execute arbitr
23RISK
open ↗Referência✓ VexDay Proof
propertymax pro free - SQL Injection / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in PropertyMax Pro FREE 0.3 allows remote attackers to inject arbi
23RISK
open ↗Referência
CVE-2015-6168
Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a
35RISK
open ↗Referência
CVE-2021-43164
A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.191
35RISK
open ↗Referência
CVE-2010-2103
Cross-site scripting (XSS) vulnerability in axis2-admin/axis2-admin/engagingglobally in the administration console in Ap
35RISK
open ↗Referência
CVE-2013-0019
Use-after-free vulnerability in Microsoft Internet Explorer 7 through 10 allows remote attackers to execute arbitrary co
35RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.