Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,813cataloged exploits
35,788CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,549GitHub PoC 14,290VulnCheck XDB 8,722Nuclei 4,320Metasploit 3,477✓ verified onlyrecentpopularrisk
22,523 exploits
Referência✓ VexDay Proof
FOSS Gallery Public 1.0 - Arbitrary File Upload
Unrestricted file upload vulnerability in processFiles.php in FOSS Gallery Admin and FOSS Gallery Public 1.0 beta allows
23RISK
open ↗Referência✓ VexDay Proof
Konqueror 3.5.9 - 'font color' Remote Crash
The HTML parser in KDE Konqueror 3.5.9 allows remote attackers to cause a denial of service (application crash) via a fo
23RISK
open ↗Referência
CVE-2017-14848
WPHRM Human Resource Management System for WordPress 1.0 allows SQL Injection via the employee_id parameter.
23RISK
open ↗Referência
CVE-2009-2395
SQL injection vulnerability in the K2 (com_k2) component 1.0.1 Beta and earlier for Joomla! allows remote attackers to e
23RISK
open ↗Referência
CVE-2009-3601
Cross-site scripting (XSS) vulnerability in demo_page.php in Scriptsez Ultimate Poll allows remote attackers to inject a
23RISK
open ↗Referência✓ VexDay Proof
Ez Ringtone Manager - Multiple Remote File Disclosure Vulnerabilities
Multiple directory traversal vulnerabilities in Ez Ringtone Manager allow remote attackers to read arbitrary files via a
23RISK
open ↗Referência
CVE-2018-11415
SAP Internet Transaction Server (ITS) 6200.X.X has Reflected Cross Site Scripting (XSS) via certain wgate URIs. NOTE: th
23RISK
open ↗Referência
CVE-2004-1521
Eudora 6.2.0.14 does not issue a warning when a user forwards an e-mail message that contains base64 or quoted-printable
23RISK
open ↗Referência✓ VexDay Proof
PHPFootball 1.6 - Remote Database Disclosure
show.php in Vlad Alexa Mancini PHPFootball 1.6 allows remote attackers to obtain sensitive information (database content
23RISK
open ↗Referência
CVE-2010-4781
index.php in Enano CMS 1.1.7pl1, and possibly other versions before 1.1.8, 1.0.6pl3, and 1.1.7pl2, allows remote attacke
23RISK
open ↗Referência
CVE-2010-1219
Directory traversal vulnerability in the JA News (com_janews) component 1.0 for Joomla! allows remote attackers to read
38RISK
open ↗Referência
CVE-2010-4781
index.php in Enano CMS 1.1.7pl1, and possibly other versions before 1.1.8, 1.0.6pl3, and 1.1.7pl2, allows remote attacke
23RISK
open ↗Referência
CVE-2007-0122
Multiple SQL injection vulnerabilities in Coppermine Photo Gallery 1.4.10 and earlier allow remote authenticated adminis
23RISK
open ↗Referência
inoERP 4.15 - 'download' SQL Injection
download.php in inoERP 4.15 allows SQL injection through insecure deserialization.
23RISK
open ↗Referência✓ VexDay Proof
Valdersoft Shopping Cart 3.0 - Remote Command Execution
PHP remote file include vulnerability in (1) include/templates/categories/default.php and (2) certain other include/temp
23RISK
open ↗Referência✓ VexDay Proof
open NewsLetter 2.5 - Multiple Vulnerabilities (2)
Open Newsletter 2.5 and earlier allows remote authenticated administrators to execute arbitrary PHP code by inserting th
23RISK
open ↗Referência✓ VexDay Proof
Xpression News 1.0.1 - 'archives.php' Remote File Disclosure
Directory traversal vulnerability in archives.php in Xpression News (X-News) 1.0.1 allows remote attackers to include ar
23RISK
open ↗Referência✓ VexDay Proof
Real Estate Scripts 2008 - 'cat' SQL Injection
SQL injection vulnerability in index.php in Real Estate Classifieds allows remote attackers to execute arbitrary SQL com
23RISK
open ↗Referência
CVE-2018-6363
SQL Injection exists in Task Rabbit Clone 1.0 via the single_blog.php id parameter.
23RISK
open ↗Referência
CVE-2018-6363
SQL Injection exists in Task Rabbit Clone 1.0 via the single_blog.php id parameter.
23RISK
open ↗Referência
CVE-2017-9614
The fill_input_buffer function in jdatasrc.c in libjpeg-turbo 1.5.1 allows remote attackers to cause a denial of service
23RISK
open ↗Referência
CVE-2017-9614
The fill_input_buffer function in jdatasrc.c in libjpeg-turbo 1.5.1 allows remote attackers to cause a denial of service
23RISK
open ↗Referência
CVE-2010-1711
Cross-site scripting (XSS) vulnerability in carga_foto_al.php in Siestta 2.0, when register_globals is enabled, allows r
23RISK
open ↗Referência
CVE-2010-1711
Cross-site scripting (XSS) vulnerability in carga_foto_al.php in Siestta 2.0, when register_globals is enabled, allows r
23RISK
open ↗Referência
CVE-2019-0570
An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka "Windo
23RISK
open ↗Referência
CVE-2009-2923
Multiple directory traversal vulnerabilities in BitmixSoft PHP-Lance 1.52 allow remote attackers to read arbitrary files
23RISK
open ↗Referência
CVE-2012-5387
Cross-site request forgery (CSRF) vulnerability in wlcms-plugin.php in the White Label CMS plugin before 1.5.1 for WordP
23RISK
open ↗Referência✓ VexDay Proof
Jupiter CMS 1.1.5 - '/index.php' Local/Remote File Inclusion
Directory traversal vulnerability in index.php in Jupiter CMS 1.1.5 allows remote attackers to include and execute arbit
23RISK
open ↗Referência
CVE-2009-4386
SQL injection vulnerability in hotel_tiempolibre_ext.php in Venalsur Booking Centre Booking System for Hotels Group, whe
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.