Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,813cataloged exploits
35,788CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,549GitHub PoC 14,290VulnCheck XDB 8,722Nuclei 4,320Metasploit 3,477✓ verified onlyrecentpopularrisk
22,523 exploits
Referência
CVE-2017-12951
The gig::DimensionRegion::CreateVelocityTable function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a den
23RISK
open ↗Referência
CVE-2015-3934
Multiple SQL injection vulnerabilities in Fiyo CMS 2.0_1.9.1 allow remote attackers to execute arbitrary SQL commands vi
23RISK
open ↗Referência
CVE-2024-53582
An issue found in the Copy and View functions in the File Manager component of OpenPanel v0.3.4 allows attackers to exec
41RISK
open ↗Referência
CVE-2011-4671
SQL injection vulnerability in adrotate/adrotate-out.php in the AdRotate plugin 3.6.6, and other versions before 3.6.8,
23RISK
open ↗Referência
CVE-2017-17110
Techno Portfolio Management Panel 1.0 allows an attacker to inject SQL commands via a single.php?id= request.
23RISK
open ↗Referência
CVE-2015-7715
Cross-site request forgery (CSRF) vulnerability in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allows
23RISK
open ↗Referência
CVE-2015-7715
Cross-site request forgery (CSRF) vulnerability in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allows
23RISK
open ↗Referência✓ VexDay Proof
OWLLib 1.0 - 'OWLMemoryProperty.php' Remote File Inclusion
PHP remote file inclusion vulnerability in memory/OWLMemoryProperty.php in OWLLib 1.0 allows remote attackers to execute
23RISK
open ↗Referência✓ VexDay Proof
BrowseDialog Class - 'ccrpbds6.dll' Multiple Denial of Service Vulnerabilities
A certain ActiveX control in the Common Controls Replacement Project (CCRP) CCRP BrowseDialog Server (ccrpbds6.dll) allo
23RISK
open ↗Referência✓ VexDay Proof
PHP-Nuke - 'iframe.php' Remote File Inclusion
PHP remote file inclusion vulnerability in iframe.php in the iFrame Module for PHP-NUKE allows remote attackers to execu
23RISK
open ↗Referência✓ VexDay Proof
Hot Links SQL-PHP 3 - 'report.php' Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in report.php in Mr. CGI Guy Hot Links SQL-PHP 3.0 and earlier allows remote at
23RISK
open ↗Referência
CVE-2026-9577
Post Status Notifier Lite < 1.13.0 - Reflected XSS via mod Parameter
33RISK
open ↗Referência
CVE-2012-0277
Heap-based buffer overflow in XnView before 1.99 allows remote attackers to cause a denial of service (application crash
23RISK
open ↗Referência
CVE-2026-16334
itsourcecode Hospital Management System prescriptionorder.php sql injection
33RISK
open ↗Referência
CVE-2026-13156
MailerSend - Official SMTP Integration < 1.0.8 - Settings Deletion and Plugin Deactivation via CSRF
33RISK
open ↗Referência
CVE-2026-12972
PayPlus Payment Gateway < 8.2.2 - Unauthenticated Order Payment Metadata Tampering
33RISK
open ↗Referência
CVE-2026-12898
All-in-One WP Migration and Backup < 7.106 - Unauthenticated Arbitrary-Location Log File Write via Path Traversal
33RISK
open ↗Referência
CVE-2026-16220
code-projects Online Examination System account.php cross site scripting
33RISK
open ↗Referência
CVE-2012-0393
The ParameterInterceptor component in Apache Struts before 2.3.1.1 does not prevent access to public constructors, which
35RISK
open ↗Referência
CVE-2017-17595
Beauty Parlour Booking Script 1.0 has SQL Injection via the /list gender or city parameter.
23RISK
open ↗Referência
CVE-2012-0394
The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers
60RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.