Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,900cataloged exploits
35,840CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,600GitHub PoC 14,323VulnCheck XDB 8,722Nuclei 4,320Metasploit 3,477✓ verified onlyrecentpopularrisk
22,573 exploits
Referência
CVE-2010-1470
Directory traversal vulnerability in the Web TV (com_webtv) component 1.0 for Joomla! allows remote attackers to read ar
43RISK
open ↗Referência✓ VexDay Proof
PowerBook 1.21 - 'index.php' Local File Inclusion
Directory traversal vulnerability in pb_inc/admincenter/index.php in PowerScripts PowerBook 1.21 allows remote attackers
23RISK
open ↗Referência
CVE-2017-5264
Versions of Nexpose prior to 6.4.66 fail to adequately validate the source of HTTP requests intended for the Automated A
23RISK
open ↗Referência
CVE-2012-2442
Buffer overflow in the Video Manager in Nokia PC Suite 7.1.180.64 and earlier allows remote attackers to cause a denial
23RISK
open ↗Referência
CVE-2012-2442
Buffer overflow in the Video Manager in Nokia PC Suite 7.1.180.64 and earlier allows remote attackers to cause a denial
23RISK
open ↗Referência✓ VexDay Proof
Multi-Page Comment System 1.1.0 - Insecure Cookie Handling
admin.php in Multi-Page Comment System (MPCS) 1.0 and 1.1 allows remote attackers to bypass authentication and gain priv
23RISK
open ↗Referência
CVE-2019-14346
Internal/Views/config.php in Schben Adive 2.0.7 allows admin/config CSRF to change a user password.
23RISK
open ↗Referência
CVE-2009-3912
Directory traversal vulnerability in index.php in TFTgallery 0.13 allows remote attackers to read arbitrary files via a
23RISK
open ↗Referência
CVE-2009-3123
Directory traversal vulnerability in gallery/gallery.php in Wap-Motor before 18.1 allows remote attackers to read arbitr
23RISK
open ↗Referência✓ VexDay Proof
Galatolo Web Manager 1.0 - SQL Injection
SQL injection vulnerability in view.php in Galatolo WebManager 1.0 and earlier allows remote attackers to execute arbitr
23RISK
open ↗Referência✓ VexDay Proof
WebCreator 0.2.6-rc3 - 'moddir' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in WebCreator 0.2.6-rc3 and earlier allow remote attackers to execute
23RISK
open ↗Referência✓ VexDay Proof
AyeView 2.20 - Invalid Bitmap Header Parsing Crash
AyeView 2.20 allows user-assisted attackers to cause a denial of service (memory consumption or application crash) via a
23RISK
open ↗Referência✓ VexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to obtain sensitive information via (1)
23RISK
open ↗Referência✓ VexDay Proof
Gravy Media Photo Host 1.0.8 - Local File Disclosure
Absolute path traversal vulnerability in forcedownload.php in Gravy Media Photo Host 1.0.8 allows remote attackers to re
23RISK
open ↗Referência✓ VexDay Proof
LinPHA 1.3.3 Plugin Maps - Remote Command Execution
plugins/maps/db_handler.php in LinPHA 1.3.3 and earlier does not require authentication for a settings action that modif
23RISK
open ↗Referência✓ VexDay Proof
Pet Grooming Management System 2.0 - Arbitrary Add Admin
Pet Grooming Management System 2.0 allows remote attackers to gain privileges via a direct request to useradded.php with
23RISK
open ↗Referência
CVE-2019-1364
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle o
23RISK
open ↗Referência✓ VexDay Proof
Pooya Site Builder (PSB) 6.0 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in Pooya Site Builder (PSB) 6.0 allow remote attackers to execute arbitrary SQL c
23RISK
open ↗Referência
CVE-2016-3694
Multiple SQL injection vulnerabilities in modified eCommerce Shopsoftware 2.0.0.0 revision 9678, when the easybill-modul
23RISK
open ↗Referência
CVE-2009-3366
Directory traversal vulnerability in navigation.php in An image gallery 1.0 allows remote attackers to list arbitrary di
23RISK
open ↗Referência
CVE-2011-2944
SQL injection vulnerability in login.php in MegaLab The Uploader before 2.0.5 allows remote attackers to execute arbitra
23RISK
open ↗Referência
CVE-2011-2944
SQL injection vulnerability in login.php in MegaLab The Uploader before 2.0.5 allows remote attackers to execute arbitra
23RISK
open ↗Referência
CVE-2010-1478
Directory traversal vulnerability in the Ternaria Informatica Jfeedback! (com_jfeedback) component 1.2 for Joomla! allow
38RISK
open ↗Referência✓ VexDay Proof
eFiction 3.0 - 'toplists.php' SQL Injection
SQL injection vulnerability in toplists.php in eFiction 3.0 and 3.4.3, when magic_quotes_gpc is disabled, allows remote
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.