Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,813cataloged exploits
35,788CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,549GitHub PoC 14,290VulnCheck XDB 8,722Nuclei 4,320Metasploit 3,477✓ verified onlyrecentpopularrisk
22,523 exploits
Referência
CVE-2021-42013
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open ↗Referência
CVE-2026-9575
itsourcecode Student Transcript Processing System index.php sql injection
33RISK
open ↗Referência
CVE-2026-9574
itsourcecode Student Transcript Processing System trans.php sql injection
33RISK
open ↗Referência
CVE-2026-9573
itsourcecode Student Transcript Processing System index.php sql injection
33RISK
open ↗Referência
CVE-2013-4694
Stack-based buffer overflow in gen_jumpex.dll in Winamp before 5.64 Build 3418 allows remote attackers to cause a denial
28RISK
open ↗Referência
CVE-2013-4863
The HomeAutomationGateway service in MiCasaVerde VeraLite with firmware 1.5.408 allows (1) remote attackers to execute a
28RISK
open ↗Referência
CVE-2026-7293
SourceCodester Pizzafy Ecommerce System ajax.php delete_category sql injection
33RISK
open ↗Referência✓ VexDay Proof
Teraway LiveHelp 2.0 - Insecure Cookie Handling
Teraway LiveHelp 2.0 allows remote attackers to bypass authentication and gain administrative access via a pwd=&lvl=1&us
23RISK
open ↗Referência
CVE-2015-1059
Unrestricted file upload vulnerability in admin/files/add in AdaptCMS 3.0.3 allows remote authenticated users to execute
23RISK
open ↗Referência
CVE-2015-1060
Open redirect vulnerability in lib/Cake/Controller/Controller.php in AdaptCMS 3.0.3 allows remote attackers to redirect
23RISK
open ↗Referência✓ VexDay Proof
Teraway FileStream 1.0 - Insecure Cookie Handling
Teraway FileStream 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the tw
23RISK
open ↗Referência✓ VexDay Proof
SDP Downloader 2.3.0 - '.asx' Local Heap Overflow (PoC)
Stack-based buffer overflow in Streaming Download Project (SDP) Downloader 2.3.0 allows remote attackers to execute arbi
23RISK
open ↗Referência✓ VexDay Proof
SDP Downloader 2.3.0 - '.asx' Local Buffer Overflow (SEH) (1)
Stack-based buffer overflow in Streaming Download Project (SDP) Downloader 2.3.0 allows remote attackers to execute arbi
23RISK
open ↗Referência✓ VexDay Proof
Mini-stream Ripper 3.0.1.1 - '.RAM' Local Buffer Overflow
Multiple stack-based buffer overflows in Mini-stream Ripper 3.0.1.1 allow remote attackers to execute arbitrary code via
50RISK
open ↗Referência✓ VexDay Proof
Mini-stream ASX to MP3 Converter 3.0.0.7 - '.asx HREF' Local Buffer Overflow
Multiple stack-based buffer overflows in Mini-stream ASX to MP3 Converter 3.0.0.7 allow remote attackers to execute arbi
23RISK
open ↗Referência
CVE-2013-5121
SQL injection vulnerability in PHPFox before 3.6.0 (build6) allows remote attackers to execute arbitrary SQL commands vi
23RISK
open ↗Referência✓ VexDay Proof
DB Top Sites 1.0 - 'index.php?u' Local File Inclusion
Multiple directory traversal vulnerabilities in DB Top Sites 1.0, when magic_quotes_gpc is disabled, allow remote attack
23RISK
open ↗Referência
CVE-2015-1479
SQL injection vulnerability in reports/CreateReportTable.jsp in ZOHO ManageEngine ServiceDesk Plus (SDP) before 9.0 buil
23RISK
open ↗Referência
CVE-2009-2123
Multiple SQL injection vulnerabilities in Elvin 1.2.0 allow remote attackers to execute arbitrary SQL commands via the (
23RISK
open ↗Referência
CVE-2026-9434
Totolink A8000RU Web Management cstecgi.cgi setWiFiWpsCfg os command injection
48RISK
open ↗Referência
CVE-2013-6987
Multiple directory traversal vulnerabilities in the FileBrowser components in Synology DiskStation Manager (DSM) before
28RISK
open ↗Referência
CVE-2013-7025
Multiple cross-site scripting (XSS) vulnerabilities in ematStaticAlertTypes.jsp in the Alert Settings section in Dell So
23RISK
open ↗Referência
CVE-2013-7186
Buffer overflow in Steinberg MyMp3PRO 5.0 (Build 5.1.0.21) allows remote attackers to execute arbitrary code via a long
28RISK
open ↗Referência
CVE-2013-7186
Buffer overflow in Steinberg MyMp3PRO 5.0 (Build 5.1.0.21) allows remote attackers to execute arbitrary code via a long
28RISK
open ↗Referência
CVE-2013-7186
Buffer overflow in Steinberg MyMp3PRO 5.0 (Build 5.1.0.21) allows remote attackers to execute arbitrary code via a long
28RISK
open ↗Referência
CVE-2026-2441
Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside
76RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.