Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,464Referência 22,936GitHub PoC 15,010VulnCheck XDB 8,846Nuclei 4,361Metasploit 3,490✓ verified onlyrecentpopularrisk
24,695 exploits
Exploit-DB✓ VexDay Proof
ZeroCMS 1.0 - 'zero_view_article.php' SQL Injection
SQL injection vulnerability in zero_view_article.php in ZeroCMS 1.0 allows remote attackers to execute arbitrary SQL com
23RISK
open ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Featured Comments - Cross-Site Request Forgery
Multiple cross-site request forgery (CSRF) vulnerabilities in the Featured Comments plugin 1.2.1 for WordPress allow rem
23RISK
open ↗Exploit-DB✓ VexDay Proof
Foreman Smart-Proxy - Remote Command Injection
The Smart-Proxy in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to execute arbitrary commands via
23RISK
open ↗Exploit-DB✓ VexDay Proof
Linux Kernel 3.2.0-23/3.5.0-23 (Ubuntu 12.04/12.04.1/12.04.2 x64) - 'perf_swevent_init' Local Privilege Escalation (3)
The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data t
83RISK
open ↗Exploit-DB✓ VexDay Proof
Huawei E303 Router - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in api/sms/send-sms in the Web UI 11.010.06.01.858 on Huawei E303 modems
23RISK
open ↗Exploit-DB✓ VexDay Proof
ElasticSearch Dynamic Script - Arbitrary Java Execution (Metasploit)
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execut
100RISK
open ↗Exploit-DB✓ VexDay Proof
AuraCMS 3.0 - Multiple Vulnerabilities
Absolute path traversal vulnerability in filemanager.php in AuraCMS 3.0 allows remote attackers to list a directory via
23RISK
open ↗Exploit-DB✓ VexDay Proof
AuraCMS 3.0 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in filemanager.php in AuraCMS 3.0 and earlier allows remote attackers to inject
23RISK
open ↗Exploit-DB✓ VexDay Proof
webEdition CMS - 'we_fs.php' SQL Injection
Multiple SQL injection vulnerabilities in the file browser component (we_fs.php) in webEdition CMS before 6.2.7-s1.2 and
23RISK
open ↗Exploit-DB✓ VexDay Proof
WordPress Plugin HDW Player - '/wp-admin/admin.php' SQL Injection
SQL injection vulnerability in the videos page in the HDW Player Plugin (hdw-player-video-player-video-gallery) 2.4.2 fo
23RISK
open ↗Exploit-DB✓ VexDay Proof
Wireshark CAPWAP Dissector - Denial of Service (Metasploit)
The dissect_capwap_data function in epan/dissectors/packet-capwap.c in the CAPWAP dissector in Wireshark 1.6.x before 1.
50RISK
open ↗Exploit-DB✓ VexDay Proof
WordPress Plugin ENL NewsLetter - '/wp-admin/admin.php' SQL Injection
SQL injection vulnerability in the ENL Newsletter (enl-newsletter) plugin 1.0.1 for WordPress allows remote authenticate
23RISK
open ↗Exploit-DB✓ VexDay Proof
WordPress Plugin BookX 1.7 - 'bookx_export.php' Local File Inclusion
Directory traversal vulnerability in includes/bookx_export.php BookX plugin 1.7 for WordPress allows remote attackers to
23RISK
open ↗Exploit-DB✓ VexDay Proof
WordPress Plugin WP Rss Poster - '/wp-admin/admin.php' SQL Injection
SQL injection vulnerability in the WP Rss Poster (wp-rss-poster) plugin 1.0.0 for WordPress allows remote attackers to e
23RISK
open ↗Exploit-DB✓ VexDay Proof
Linux Kernel 3.3.5 - '/drivers/media/media-device.c' Local Information Disclosure
The media_device_enum_entities function in drivers/media/media-device.c in the Linux kernel before 3.14.6 does not initi
23RISK
open ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Tera Charts (tera-charts) - '/charts/zoomabletreemap.php?fn' Directory Traversal
Multiple directory traversal vulnerabilities in Tera Charts (tera-charts) plugin 0.1 for WordPress allow remote attacker
43RISK
open ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Tera Charts (tera-charts) - '/charts/treemap.php?fn' Directory Traversal
Multiple directory traversal vulnerabilities in Tera Charts (tera-charts) plugin 0.1 for WordPress allow remote attacker
43RISK
open ↗Exploit-DB✓ VexDay Proof
Castor Library - XML External Entity Information Disclosure
The default configuration for the Xerces SAX Parser in Castor before 1.3.3 allows context-dependent attackers to conduct
23RISK
open ↗Exploit-DB✓ VexDay Proof
Easy File Sharing FTP Server 3.5 - Remote Stack Buffer Overflow
Stack-based buffer overflow in EFS Software Easy File Sharing FTP Server 2.0 allows remote attackers to execute arbitrar
50RISK
open ↗Exploit-DB✓ VexDay Proof
Videos Tube 1.0 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in Videos Tube 1.0 allow remote attackers to execute arbitrary SQL commands via t
23RISK
open ↗Exploit-DB✓ VexDay Proof
Symantec Workspace Streaming - Arbitrary File Upload (Metasploit)
The server in Symantec Workspace Streaming (SWS) before 7.5.0.749 allows remote attackers to access files and functional
50RISK
open ↗Exploit-DB✓ VexDay Proof
User Cake - Cross-Site Request Forgery
Multiple cross-site request forgery (CSRF) vulnerabilities in user_settings.php in Usercake 2.0.2 and earlier allow remo
23RISK
open ↗Exploit-DB✓ VexDay Proof
dpkg Source Package - Index: pseudo-header Processing Multiple Local Directory Traversals
Multiple directory traversal vulnerabilities in dpkg-source in dpkg-dev 1.3.0 allow remote attackers to modify files out
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHP-Nuke 'Submit_News' Component - SQL Injection
SQL injection vulnerability in the Submit_News module for PHP-Nuke 8.3 allows remote attackers to execute arbitrary SQL
23RISK
open ↗Exploit-DB✓ VexDay Proof
Mayan-EDms Web-Based Document Management OS System - Multiple Persistent Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in apps/common/templates/calculate_form_title.html in Mayan EDMS 0.1
23RISK
open ↗Exploit-DB✓ VexDay Proof
Pyplate - 'addScript.py' Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in admin/addScript.py in Pyplate 0.08 allows remote attackers to hijack
23RISK
open ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Booking System (Booking Calendar) - 'booking_form_id' SQL Injection
SQL injection vulnerability in dopbs-backend-forms.php in the Booking System (Booking Calendar) plugin before 1.3 for Wo
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apache mod_wsgi - Information Disclosure
mod_wsgi module before 3.4 for Apache, when used in embedded mode, might allow remote attackers to obtain sensitive info
23RISK
open ↗Exploit-DB✓ VexDay Proof
SafeNet Sentinel Protection Server 7.0 < 7.4 / Sentinel Keys Server 1.0.3 < 1.0.4 - Directory Traversal
Directory traversal vulnerability in SafeNet Sentinel Protection Server 7.0.0 through 7.4.0 and possibly earlier version
28RISK
open ↗Exploit-DB✓ VexDay Proof
XOOPS Glossaire Module - '/modules/glossaire/glossaire-aff.php' SQL Injection
SQL injection vulnerability in glossaire-aff.php in the Glossaire module 1.0 for XOOPS allows remote attackers to execut
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.