Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,794cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,459Referência 22,721GitHub PoC 14,946VulnCheck XDB 8,829Nuclei 4,350Metasploit 3,489✓ verified onlyrecentpopularrisk
22,573 exploits
Referência✓ VexDay Proof
EgyPlus 7ml 1.0.1 - Authentication Bypass
Multiple SQL injection vulnerabilities in cpanel/login.php in EgyPlus 7ammel (aka 7ml) 1.0.1 and earlier, when magic_quo
23RISK
open ↗Referência
CVE-2019-9194
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
60RISK
open ↗Referência
CVE-2019-9194
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
60RISK
open ↗Referência✓ VexDay Proof
Internet PhotoShow (Special Edition) - Insecure Cookie Handling
admin.php in Internet Photoshow and Internet Photoshow Special Edition (SE) allows remote attackers to bypass authentica
23RISK
open ↗Referência
CVE-2023-33246
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RISK
open ↗Referência
CVE-2023-33246
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RISK
open ↗Referência★ 104
CVE-2023-33246 RocketMQ RCE Detect By Version and Exploit
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RISK
open ↗Referência✓ VexDay Proof
idautomation bar code - ActiveX Multiple Vulnerabilities
IDAutomation allows remote attackers to overwrite arbitrary files via the argument to the (1) SaveBarCode and (2) SaveEn
23RISK
open ↗Referência
CVE-2026-10815
LakshayD02 Hostel-Management-System-PHP Admin Dashboard index.php authorization
33RISK
open ↗Referência
CVE-2026-10812
zilliztech GPTCache Cache Key pre.py BufferedReader.peek weak hash
28RISK
open ↗Referência
CVE-2023-46747
BIG-IP Configuration utility unauthenticated remote code execution vulnerability
100RISK
open ↗Referência
CVE-2020-8260
A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform
100RISK
open ↗Referência
CVE-2020-11651
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISK
open ↗Referência
CVE-2020-11651
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISK
open ↗Referência
CVE-2008-7269
Open redirect vulnerability in api.php in SiteEngine 5.x allows user-assisted remote attackers to redirect users to arbi
38RISK
open ↗Referência✓ VexDay Proof
Kostenloses Linkmanagementscript - SQL Injection
SQL injection vulnerability in Kostenloses Linkmanagementscript allows remote attackers to execute arbitrary SQL command
23RISK
open ↗Referência
CVE-2026-8037
OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF
100RISK
open ↗Referência
CVE-2026-10803
MLflow Dataset Digest Computation digest_utils.py mlflow.data.digest_utils weak hash
28RISK
open ↗Referência
CVE-2026-10802
keystonejs keystone GraphQL API Endpoint output-field.ts resource consumption
33RISK
open ↗Referência
CVE-2026-10801
modelscope ms-swift PIL Image Cache Key base.py Template._save_pil_image weak hash
28RISK
open ↗Referência
CVE-2026-10288
code-projects Hotel and Tourism Reservation System Admin Login login.php password_verify improper authentication
33RISK
open ↗Referência✓ VexDay Proof
Core Image Fun House 2.0 (OSX) - Arbitrary Code Execution (PoC)
Buffer overflow in Apple Core Image Fun House 2.0 and earlier in CoreImage Examples in Xcode tools before 3.1 allows use
23RISK
open ↗Referência
CVE-2026-7229
code-projects Coaching Management System POST reply.php sql injection
33RISK
open ↗Referência
CVE-2021-25298
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi
100RISK
open ↗Referência
CVE-2021-25298
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.