Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,056cataloged exploits
35,925CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,640GitHub PoC 14,392VulnCheck XDB 8,755Nuclei 4,333Metasploit 3,478✓ verified onlyrecentpopularrisk
22,640 exploits
Referência
TP-Link Router AX50 firmware 210730 - Remote Code Execution (RCE) (Authenticated)
In TP-Link Router AX50 firmware 210730 and older, import of a malicious backup file via web interface can lead to remote
35RISK
open ↗Referência
CVE-2012-1604
Cross-site scripting (XSS) vulnerability in NextBBS 0.6 allows remote attackers to inject arbitrary web script or HTML v
23RISK
open ↗Referência
CVE-2010-1855
SQL injection vulnerability in auktion.php in Pay Per Watch & Bid Auktions System allows remote attackers to execute arb
23RISK
open ↗Referência
CVE-2010-1855
SQL injection vulnerability in auktion.php in Pay Per Watch & Bid Auktions System allows remote attackers to execute arb
23RISK
open ↗Referência
CVE-2012-4901
Cross-site scripting (XSS) vulnerability in Template CMS 2.1.1 and earlier allows remote attackers to inject arbitrary w
23RISK
open ↗Referência✓ VexDay Proof
PowerClan 1.14a - Authentication Bypass
SQL injection vulnerability in admin/index.php in PowerClan 1.14a allows remote attackers to execute arbitrary SQL comma
23RISK
open ↗Referência
CVE-2009-5102
SQL injection vulnerability in default.asp in ATCOM Netvolution 1.0 ASP allows remote attackers to execute arbitrary SQL
23RISK
open ↗Referência
CVE-2015-5754
Race condition in runner in Install.framework in the Install Framework Legacy component in Apple OS X before 10.10.5 all
23RISK
open ↗Referência
CVE-2010-2133
SQL injection vulnerability in contact.php in My Little Forum allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗Referência
CVE-2010-2133
SQL injection vulnerability in contact.php in My Little Forum allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗Referência✓ VexDay Proof
Realty Web-Base 1.0 - Authentication Bypass
Multiple SQL injection vulnerabilities in admin/admin.php in Realty Webware Technologies Realty Web-Base 1.0 allow remot
23RISK
open ↗Referência
CVE-2009-3181
Directory traversal vulnerability in Anantasoft Gazelle CMS 1.0 allows remote attackers to overwrite arbitrary files via
23RISK
open ↗Referência✓ VexDay Proof
PHP Blue Dragon CMS 2.9 - Remote File Inclusion
PHP remote file inclusion vulnerability in public_includes/pub_popup/popup_finduser.php in PHP Blue Dragon Platinum 2.8.
23RISK
open ↗Referência
CVE-2016-5809
An issue was discovered on Schneider Electric IONXXXX series power meters ION73XX series, ION75XX series, ION76XX series
23RISK
open ↗Referência
CVE-2016-9950
An issue was discovered in Apport before 2.20.4. There is a path traversal issue in the Apport crash file "Package" and
23RISK
open ↗Referência
CVE-2017-15971
Same Sex Dating Software Pro 1.0 allows SQL Injection via the viewprofile.php profid parameter, the viewmessage.php send
23RISK
open ↗Referência✓ VexDay Proof
PHP121 Instant Messenger 1.4 - Remote Code Execution
SQL injection vulnerability in php121language.php in PHP121 1.4 allows remote attackers to execute arbitrary SQL command
23RISK
open ↗Referência
CVE-2017-2528
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The
23RISK
open ↗Referência✓ VexDay Proof
OLIB 7 WebView 2.5.1.1 - 'infile' Local File Inclusion
Fretwell-Downing Informatics (FDI) OLIB7 WebView 2.5.1.1 allows remote authenticated users to obtain sensitive informati
23RISK
open ↗Referência
CVE-2019-19493
Kentico before 12.0.50 allows file uploads in which the Content-Type header is inconsistent with the file extension, lea
23RISK
open ↗Referência✓ VexDay Proof
Ktools Photostore 3.5.2 - Multiple SQL Injections
SQL injection vulnerability in manager/image_details_editor.php in Ktools PhotoStore 2.5, 2.9.8, 3.1.0, and other versio
23RISK
open ↗Referência✓ VexDay Proof
Star Articles 6.0 - Blind SQL Injection (1)
Multiple SQL injection vulnerabilities in Kalptaru Infotech Ltd. Star Articles 6.0 allow remote attackers to inject arbi
23RISK
open ↗Referência
CVE-2010-1077
Directory traversal vulnerability in vbseo.php in Crawlability vBSEO plugin 3.1.0 for vBulletin allows remote attackers
23RISK
open ↗Referência
CVE-2010-1077
Directory traversal vulnerability in vbseo.php in Crawlability vBSEO plugin 3.1.0 for vBulletin allows remote attackers
23RISK
open ↗Referência
CVE-2015-3443
Cross-site scripting (XSS) vulnerability in the basic dashboard in Thycotic Secret Server 8.6.x, 8.7.x, and 8.8.x before
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.