Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,533cataloged exploits
35,607CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,407GitHub PoC 14,247VulnCheck XDB 8,663Nuclei 4,287Metasploit 3,474✓ verified onlyrecentpopularrisk
22,407 exploits
Referência
CVE-2017-0060
The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; W
28RISK
open ↗Referência
Ingress-NGINX Admission Controller v1.11.1 - FD Injection to RCE
ingress-nginx controller - configuration injection via unsanitized mirror annotations
78RISK
open ↗Referência
CVE-2020-0986
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka '
76RISK
open ↗Referência
CVE-2018-11311
A hardcoded FTP username of myscada and password of Vikuk63 in 'myscadagate.exe' in mySCADA myPRO 7 allows remote attack
28RISK
open ↗Referência✓ VexDay Proof
DigitalHive 2.0 RC2 - 'user_id' SQL Injection
Multiple SQL injection vulnerabilities in Digital Hive 2.0 RC2 and earlier allow (1) remote attackers to execute arbitra
23RISK
open ↗Referência✓ VexDay Proof
RichStrong CMS - 'cat' SQL Injection
SQL injection vulnerability in showproduct.asp in RichStrong CMS allows remote attackers to execute arbitrary SQL comman
23RISK
open ↗Referência
CVE-2020-23935
Kabir Alhasan Student Management System 1.0 is vulnerable to Authentication Bypass via "Username: admin'# && Password: (
28RISK
open ↗Referência
CVE-2009-4660
Stack-based buffer overflow in the AntServer Module (AntServer.exe) in BigAnt IM Server 2.50 allows remote attackers to
50RISK
open ↗Referência
CVE-2020-8639
An unrestricted file upload vulnerability in keywordsImport.php in TestLink 1.9.20 allows remote attackers to execute ar
28RISK
open ↗Referência
CVE-2025-2775
SysAid On-Prem <= 23.3.40 Checkin Proceessing XML External Entity Injection
100RISK
open ↗Referência
CVE-2019-0571
An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations,
28RISK
open ↗Referência
CVE-2011-0518
Directory traversal vulnerability in core/lib/router.php in LotusCMS Fraise 3.0, when magic_quotes_gpc is disabled, allo
43RISK
open ↗Referência
CVE-2012-3575
Unrestricted file upload vulnerability in uploader.php in the RBX Gallery plugin 2.1 for WordPress allows remote attacke
28RISK
open ↗Referência
CVE-2010-2128
Directory traversal vulnerability in the JE Quotation Form (com_jequoteform) component 1.0b1 for Joomla! allows remote a
43RISK
open ↗Referência
CVE-2021-43062
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiMail version 7.0
53RISK
open ↗Referência
CVE-2017-5799
A Remote Code Execution vulnerability in HPE OpenCall Media Platform (OCMP) was found. The vulnerability impacts OCMP ve
28RISK
open ↗Referência
CVE-2018-1821
IBM Operational Decision Management 8.5, 8.6, 8.7, 8.8, and 8.9 is vulnerable to a XML External Entity Injection (XXE) a
46RISK
open ↗Referência
CVE-2010-4719
Directory traversal vulnerability in JRadio (com_jradio) component before 1.5.1 for Joomla! allows remote attackers to r
43RISK
open ↗Referência
CVE-2010-4719
Directory traversal vulnerability in JRadio (com_jradio) component before 1.5.1 for Joomla! allows remote attackers to r
43RISK
open ↗Referência✓ VexDay Proof
PHPBB2 MODificat 0.2.0 - 'functions.php' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/functions.php in phpBB2-MODificat 0.2.0 and earlier allows remote at
28RISK
open ↗Referência
CVE-2018-8139
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft
35RISK
open ↗Referência
CVE-2017-12965
Session fixation vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack web sessions via the PHPSESSID pa
28RISK
open ↗Referência
CVE-2015-8352
Directory traversal vulnerability in Zen Cart 1.5.4 allows remote attackers to include and execute arbitrary local files
28RISK
open ↗Referência
CVE-2013-7051
D-Link DIR-100 4.03B07: cli.cgi security bypass due to failure to check authentication parameters
28RISK
open ↗Referência
CVE-2018-0491
A use-after-free issue was discovered in Tor 0.3.2.x before 0.3.2.10. It allows remote attackers to cause a denial of se
28RISK
open ↗Referência
CVE-2020-25790
Typesetter CMS 5.x through 5.1 allows admins to upload and execute arbitrary PHP code via a .php file inside a ZIP archi
28RISK
open ↗Referência
CVE-2020-25790
Typesetter CMS 5.x through 5.1 allows admins to upload and execute arbitrary PHP code via a .php file inside a ZIP archi
28RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.