Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,794cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,459Referência 22,721GitHub PoC 14,946VulnCheck XDB 8,829Nuclei 4,350Metasploit 3,489✓ verified onlyrecentpopularrisk
22,573 exploits
Referência
CVE-2012-1125
Unrestricted file upload vulnerability in uploadify/scripts/uploadify.php in the Kish Guest Posting plugin before 1.2 fo
28RISK
open ↗Referência
CVE-2020-17530
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISK
open ↗Referência✓ VexDay Proof
Joomla! Component Rapid Recipe 1.6.6/1.6.7 - SQL Injection
SQL injection vulnerability in the Rapid Recipe (com_rapidrecipe) component 1.6.6 and 1.6.7 for Joomla! allows remote at
23RISK
open ↗Referência
CVE-2012-1153
Unrestricted file upload vulnerability in addons/uploadify/uploadify.php in appRain CMF 0.1.5 and earlier allows remote
50RISK
open ↗Referência
CVE-2023-23956
A user can supply malicious HTML and JavaScript code that will be executed in the client browser
33RISK
open ↗Referência✓ VexDay Proof
Galatolo Web Manager 1.0 - Cross-Site Scripting / Local File Inclusion
Multiple directory traversal vulnerabilities in Galatolo WebManager (GWM) 1.0 allow remote attackers to include and exec
23RISK
open ↗Referência✓ VexDay Proof
Black Ice Software Annotation Plugin - 'BiAnno.ocx' Remote Buffer Overflow (2)
Stack-based buffer overflow in BiAnno ActiveX Control (BiAnno.ocx) in Black Ice Software Annotation Plugin 10.95 allows
28RISK
open ↗Referência
CVE-2020-11530
A blind SQL injection vulnerability is present in Chop Slider 3, a WordPress plugin. The vulnerability is introduced in
60RISK
open ↗Referência
CVE-2020-11530
A blind SQL injection vulnerability is present in Chop Slider 3, a WordPress plugin. The vulnerability is introduced in
60RISK
open ↗Referência✓ VexDay Proof
JAMM CMS - 'id' Blind SQL Injection
SQL injection vulnerability in index.php in JAMM CMS allows remote attackers to execute arbitrary SQL commands via the i
23RISK
open ↗Referência✓ VexDay Proof
PreProject Multi-Vendor Shopping Malls - Multiple Vulnerabilities
SQL injection vulnerability in buyer_detail.php in Pre Multi-Vendor Shopping Malls allows remote attackers to execute ar
23RISK
open ↗Referência
CVE-2009-2219
Multiple cross-site scripting (XSS) vulnerabilities in phpCollegeExchange 0.1.5c allow remote attackers to inject arbitr
23RISK
open ↗Referência
CVE-2009-2220
Multiple directory traversal vulnerabilities in Tribiq CMS 5.0.12c, when register_globals is enabled and magic_quotes_gp
23RISK
open ↗Referência
CVE-2026-7222
code-projects Coaching Management System Complaint Form complaint.php cross site scripting
33RISK
open ↗Referência✓ VexDay Proof
CKGold Shopping Cart 2.5 - 'category_id' SQL Injection
SQL injection vulnerability in item.php in CartKeeper CKGold Shopping Cart 2.5 and 2.7 allows remote attackers to execut
23RISK
open ↗Referência
CVE-2022-41352
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through ama
100RISK
open ↗Referência✓ VexDay Proof
RevokeBB 1.0 RC11 - 'Search' SQL Injection
SQL injection vulnerability in inc/class_search.php in the Search System in RevokeBB 1.0 RC11 allows remote attackers to
23RISK
open ↗Referência
CVE-2019-11580
Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attac
100RISK
open ↗Referência✓ VexDay Proof
MyMarket 1.72 - Blind SQL Injection
SQL injection vulnerability in shopping/index.php in MyMarket 1.72 allows remote attackers to execute arbitrary SQL comm
23RISK
open ↗Referência✓ VexDay Proof
Nitro Web Gallery 1.4.3 - 'section' SQL Injection
SQL injection vulnerability in albums.php in NiTrO Web Gallery 1.4.3 and earlier allows remote attackers to execute arbi
23RISK
open ↗Referência✓ VexDay Proof
LE.CMS 1.4 - Arbitrary File Upload
admin/upload.php in le.cms 1.4 and earlier allows remote attackers to bypass administrative authentication, and upload a
23RISK
open ↗Referência
CVE-2019-7609
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISK
open ↗Referência✓ VexDay Proof
IGSuite 3.2.4 - Reverse Shell / Blind SQL Injection
SQL injection vulnerability in cgi-bin/igsuite in IGSuite 3.2.4 allows remote attackers to execute arbitrary SQL command
23RISK
open ↗Referência✓ VexDay Proof
traindepot 0.1 - Local File Inclusion / Cross-Site Scripting
Directory traversal vulnerability in index.php in Traindepot 0.1 allows remote attackers to read arbitrary files via a .
23RISK
open ↗Referência✓ VexDay Proof
traindepot 0.1 - Local File Inclusion / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the search module in Traindepot 0.1 allows remote attackers to inject arbitr
23RISK
open ↗Referência✓ VexDay Proof
SFS EZ Webstore - 'where' SQL Injection
SQL injection vulnerability in SearchResults.php in Scripts For Sites (SFS) EZ e-store allows remote attackers to execut
23RISK
open ↗Referência
CVE-2026-17434
nanocoai NanoClaw add_mcp_server request.ts handleAddMcpServer improper authorization
33RISK
open ↗Referência
CVE-2026-65711
sysPass 3.2.11 Authenticated OS Command Injection via Backup Path
41RISK
open ↗Referência
CVE-2009-2235
SQL injection vulnerability in page.php in Your Articles Directory allows remote attackers to execute arbitrary SQL comm
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.