Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,866cataloged exploits
35,812CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,573GitHub PoC 14,316VulnCheck XDB 8,722Nuclei 4,320Metasploit 3,477✓ verified onlyrecentpopularrisk
22,572 exploits
Referência✓ VexDay Proof
TCPDB 3.8 - Arbitrary Add Admin Account
user/index.php in TCPDB 3.8 does not require administrative authentication, which allows remote attackers to add admin a
23RISK
open ↗Referência✓ VexDay Proof
32bit FTP - 'PASV' Reply Client Remote Overflow (Metasploit)
Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a
43RISK
open ↗Referência✓ VexDay Proof
Flyspeck CMS 6.8 - Local/Remote File Inclusion / Change Add Admin
Directory traversal vulnerability in includes/database/examples/addressbook.php in Flyspeck CMS 6.8 allows remote attack
23RISK
open ↗Referência✓ VexDay Proof
ST-Gallery 0.1a - Multiple SQL Injections
Multiple SQL injection vulnerabilities in the getGalleryImage function in st_admin/gallery_output.php in ST-Gallery 0.1
23RISK
open ↗Referência
CVE-2013-5447
Stack-based buffer overflow in IBM Forms Viewer 4.x before 4.0.0.3 and 8.x before 8.0.1.1 allows remote attackers to exe
50RISK
open ↗Referência
CVE-2015-1130
The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and o
86RISK
open ↗Referência
CVE-2009-4761
Stack-based buffer overflow in Mini-stream RM Downloader allows remote attackers to execute arbitrary code via a long st
23RISK
open ↗Referência
CVE-2013-5758
cgi-bin/cgiServer.exx in Yealink VoIP Phone SIP-T38G allows remote authenticated users to execute arbitrary commands by
28RISK
open ↗Referência✓ VexDay Proof
Soulseek 157 NS x/156.x - Remote Distributed Search Code Execution
Stack-based buffer overflow in Soulseek 156 and 157 NS allows remote attackers to execute arbitrary code via a long sear
23RISK
open ↗Referência✓ VexDay Proof
Winamp 5.55 - MAKI Script Universal Overwrite (SEH)
The Nullsoft Modern Skins Support module (gen_ff.dll) in Nullsoft Winamp before 5.552 allows remote attackers to execute
50RISK
open ↗Referência✓ VexDay Proof
phpBugTracker 1.0.3 - Authentication Bypass
SQL injection vulnerability in index.php in phpBugTracker 1.0.3 allows remote attackers to execute arbitrary SQL command
23RISK
open ↗Referência✓ VexDay Proof
MyForum 1.3 - Authentication Bypass
Multiple SQL injection vulnerabilities in Graphiks MyForum 1.3 allow remote attackers to execute arbitrary SQL commands
23RISK
open ↗Referência✓ VexDay Proof
Million Dollar Text Links 1.x - Insecure Cookie Handling
Million Dollar Text Links 1.0 allows remote attackers to bypass authentication and gain administrative access by setting
23RISK
open ↗Referência
CVE-2013-5977
Cross-site request forgery (CSRF) vulnerability in Cart66Product.php in the Cart66 Lite plugin before 1.5.1.15 for WordP
23RISK
open ↗Referência
CVE-2023-38035
A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an
100RISK
open ↗Referência
CVE-2025-24813
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open ↗Referência
CVE-2013-6117
Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive informatio
50RISK
open ↗Referência
CVE-2013-6232
Cross-site scripting (XSS) vulnerability in SpagoBI before 4.1 allows remote authenticated users to inject arbitrary web
23RISK
open ↗Referência✓ VexDay Proof
DB Top Sites 1.0 - 'index.php?u' Local File Inclusion
Multiple directory traversal vulnerabilities in DB Top Sites 1.0, when magic_quotes_gpc is disabled, allow remote attack
23RISK
open ↗Referência
CVE-2015-1479
SQL injection vulnerability in reports/CreateReportTable.jsp in ZOHO ManageEngine ServiceDesk Plus (SDP) before 9.0 buil
23RISK
open ↗Referência
CVE-2009-2123
Multiple SQL injection vulnerabilities in Elvin 1.2.0 allow remote attackers to execute arbitrary SQL commands via the (
23RISK
open ↗Referência
CVE-2026-9434
Totolink A8000RU Web Management cstecgi.cgi setWiFiWpsCfg os command injection
48RISK
open ↗Referência
CVE-2013-6987
Multiple directory traversal vulnerabilities in the FileBrowser components in Synology DiskStation Manager (DSM) before
28RISK
open ↗Referência
CVE-2013-7025
Multiple cross-site scripting (XSS) vulnerabilities in ematStaticAlertTypes.jsp in the Alert Settings section in Dell So
23RISK
open ↗Referência
CVE-2013-7186
Buffer overflow in Steinberg MyMp3PRO 5.0 (Build 5.1.0.21) allows remote attackers to execute arbitrary code via a long
28RISK
open ↗Referência
CVE-2013-7186
Buffer overflow in Steinberg MyMp3PRO 5.0 (Build 5.1.0.21) allows remote attackers to execute arbitrary code via a long
28RISK
open ↗Referência
CVE-2013-7186
Buffer overflow in Steinberg MyMp3PRO 5.0 (Build 5.1.0.21) allows remote attackers to execute arbitrary code via a long
28RISK
open ↗Referência✓ VexDay Proof
LushiNews 1.01 - 'comments.php' SQL Injection
SQL injection vulnerability in comments.php in LushiNews 1.01 and earlier allows remote authenticated users to inject ar
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.