Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,620cataloged exploits
35,647CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,429GitHub PoC 14,270VulnCheck XDB 8,693Nuclei 4,299Metasploit 3,474✓ verified onlyrecentpopularrisk
22,429 exploits
Referência
CVE-2010-4701
Heap-based buffer overflow in the CDrawPoly::Serialize function in fxscover.exe in Microsoft Windows Fax Services Cover
35RISK
open ↗Referência
CVE-2011-3981
PHP remote file inclusion vulnerability in actions.php in the Allwebmenus plugin 1.1.3 for WordPress allows remote attac
28RISK
open ↗Referência
CVE-2019-16692
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter-result.php table parameter when action=add is us
28RISK
open ↗Referência
CVE-2020-35737
In Correspondence Management System (corms) in Newgen eGov 12.0, an attacker can modify other users' profile information
28RISK
open ↗Referência
CVE-2011-1546
Multiple SQL injection vulnerabilities in Andy's PHP Knowledgebase (Aphpkb) before 0.95.3 allow remote attackers to exec
23RISK
open ↗Referência
CVE-2010-1029
Stack consumption vulnerability in the WebCore::CSSSelector function in WebKit, as used in Apple Safari 4.0.4, Apple Saf
28RISK
open ↗Referência
CVE-2010-1029
Stack consumption vulnerability in the WebCore::CSSSelector function in WebKit, as used in Apple Safari 4.0.4, Apple Saf
28RISK
open ↗Referência
CVE-2020-6857
CarbonFTP v1.4 uses insecure proprietary password encryption with a hard-coded weak encryption key. The key for local FT
23RISK
open ↗Referência
CVE-2017-8770
There is LFD (local file disclosure) on BE126 WIFI repeater 1.0 devices that allows attackers to read the entire filesys
28RISK
open ↗Referência
CVE-2019-15993
Cisco Small Business Switches Information Disclosure Vulnerability
46RISK
open ↗Referência✓ VexDay Proof
DNS Tools (PHP Digger) - Remote Command Execution
dig.php in GScripts.net DNS Tools allows remote attackers to execute arbitrary commands via shell metacharacters in the
28RISK
open ↗Referência✓ VexDay Proof
SolidState 0.4 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in SolidState 0.4 and earlier allow remote attackers to execute arbit
28RISK
open ↗Referência
CVE-2009-4892
SQL injection vulnerability in Content Management System WEBjump! allows remote attackers to execute arbitrary SQL comma
23RISK
open ↗Referência
CVE-2013-6935
Buffer overflow in VideoCharge Software Watermark Master 2.2.23 allows remote attackers to execute arbitrary code via a
50RISK
open ↗Referência✓ VexDay Proof
Joomla! Component com_galeria - SQL Injection
SQL injection vulnerability in index.php in the com_galeria component for Joomla! allows remote attackers to execute arb
23RISK
open ↗Referência✓ VexDay Proof
XOOPS Module myTopics - 'articleId' SQL Injection
SQL injection vulnerability in print.php in the myTopics module for XOOPS allows remote attackers to execute arbitrary S
23RISK
open ↗Referência✓ VexDay Proof
RunCMS Module MyAnnonces - 'cid' SQL Injection
SQL injection vulnerability in index.php in the MyAnnonces 1.7 and earlier module for RunCMS allows remote attackers to
23RISK
open ↗Referência
CVE-2020-5260
malicious URLs may cause Git to present stored credentials to the wrong server
53RISK
open ↗Referência
CVE-2018-8619
A remote code execution vulnerability exists when the Internet Explorer VBScript execution policy does not properly rest
35RISK
open ↗Referência
CVE-2018-12706
DIGISOL DG-BR4000NG devices have a Buffer Overflow via a long Authorization HTTP header.
28RISK
open ↗Referência
CVE-2017-0263
The kernel-mode drivers in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012
76RISK
open ↗Referência
CVE-2010-2919
SQL injection vulnerability in the StaticXT (com_staticxt) component for Joomla! allows remote attackers to execute arbi
23RISK
open ↗Referência
CVE-2006-0992
Stack-based buffer overflow in Novell GroupWise Messenger before 2.0 Public Beta 2 allows remote attackers to execute ar
60RISK
open ↗Referência
CVE-2017-17999
SQL injection vulnerability in RISE Ultimate Project Manager 1.9 allows remote attackers to execute arbitrary SQL comman
23RISK
open ↗Referência
CVE-2017-5972
The TCP stack in the Linux kernel 3.x does not properly implement a SYN cookie protection mechanism for the case of a fa
28RISK
open ↗Referência
CVE-2014-2223
Unrestricted file upload vulnerability in plog-admin/plog-upload.php in Plogger 1.0 RC1 and earlier allows remote authen
28RISK
open ↗Referência
CVE-2014-2223
Unrestricted file upload vulnerability in plog-admin/plog-upload.php in Plogger 1.0 RC1 and earlier allows remote authen
28RISK
open ↗Referência
CVE-2009-3020
win32k.sys in Microsoft Windows Server 2003 SP2 allows remote attackers to cause a denial of service (system crash) by r
28RISK
open ↗Referência
CVE-2015-7245
Directory traversal vulnerability in D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 allows remot
50RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.