Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,464Referência 22,936GitHub PoC 15,010VulnCheck XDB 8,846Nuclei 4,361Metasploit 3,490✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
ExoPHPDesk 1.2 Final - Authentication Bypass
SQL injection vulnerability in admin.php in Exocrew ExoPHPDesk 1.2 Final allows remote attackers to execute arbitrary SQ
23RISK
open ↗Referência✓ VexDay Proof
ThePortal 2.2 - Arbitrary File Upload
Unrestricted file upload vulnerability in admin/galeria.php in ThePortal2 2.2 allows remote attackers to execute arbitra
23RISK
open ↗Referência✓ VexDay Proof
TaskDriver 1.3 - Remote Change Admin Password
profileedit.php TaskDriver 1.3 and earlier allows remote attackers to bypass authentication and gain administrative acce
23RISK
open ↗Referência✓ VexDay Proof
dotProject 2.0.4 - 'baseDir' Remote File Inclusion
PHP remote file inclusion vulnerability in classes/query.class.php in dotProject 2.0.4 and earlier allows remote attacke
23RISK
open ↗Referência✓ VexDay Proof
PHPAdBoard - PHP uploads Arbitrary File Upload
Unrestricted file upload vulnerability in index.php in phpAdBoard 1.8 allows remote attackers to execute arbitrary code
23RISK
open ↗Referência✓ VexDay Proof
Google Chrome 0.2.149.27 - Denial of Service
Integer underflow in net/base/escape.cc in chrome.dll in Google Chrome 0.2.149.27 allows remote attackers to cause a den
23RISK
open ↗Referência✓ VexDay Proof
phpBB Garage 1.2.0 Beta3 - SQL Injection
SQL injection vulnerability in garage.php in phpBB Garage 1.2.0 Beta3 allows remote attackers to execute arbitrary SQL c
23RISK
open ↗Referência✓ VexDay Proof
Rayzz Script 2.0 - Local/Remote File Inclusion
PHP remote file inclusion vulnerability in common/classes/class_HeaderHandler.lib.php in Rayzz Script 2.0 allows remote
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component com_jim 1.0.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in install.jim.php in the JIM 1.0.1 component for Joomla or Mambo allows remote
23RISK
open ↗Referência✓ VexDay Proof
RealPlayer 11 - '.au' Denial of Service
A certain ActiveX control in RealNetworks RealPlayer 11 allows remote attackers to cause a denial of service (applicatio
23RISK
open ↗Referência✓ VexDay Proof
tellmatic 1.0.7 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in tellmatic 1.0.7 allow remote attackers to execute arbitrary PHP co
23RISK
open ↗Referência✓ VexDay Proof
Snitz Forums 2000 - 'Active.asp' SQL Injection
SQL injection vulnerability in active.asp in Snitz Forums 2000 3.4.06 allows remote attackers to execute arbitrary SQL c
23RISK
open ↗Referência✓ VexDay Proof
Mambo Component bigAPE-Backup 1.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in classes/Tar.php in bigAPE-Backup component (com_babackup) for Mambo 1.1 allow
23RISK
open ↗Referência✓ VexDay Proof
SimpleBlog 2.0 - 'comments.asp' SQL Injection (2)
SQL injection vulnerability in comments.asp in SimpleBlog 2.0 and earlier allows remote attackers to execute arbitrary S
23RISK
open ↗Referência✓ VexDay Proof
Microsoft Internet Explorer 6 - DirectX Media Remote Overflow Denial of Service
Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (crash) via a long Color attrib
35RISK
open ↗Referência✓ VexDay Proof
Texas Imperial Software WFTPD 3.23 - 'SIZE' Remote Buffer Overflow
Buffer overflow in WFTPD Server 3.23 allows remote attackers to execute arbitrary code via long SIZE commands.
50RISK
open ↗Referência✓ VexDay Proof
OpenSSL < 0.9.7l/0.9.8d - SSLv2 Client Crash
The get_server_hello function in the SSLv2 client code in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier
28RISK
open ↗Referência✓ VexDay Proof
Apache Tomcat Connector jk2-2.0.2 mod_jk2 - Remote Overflow
Multiple stack-based buffer overflows in the legacy mod_jk2 2.0.3-DEV and earlier Apache module allow remote attackers t
35RISK
open ↗Referência✓ VexDay Proof
Apple Mac OSX 10.5.0 (Leopard) - vpnd Remote Denial of Service (PoC)
The accept_connections function in the virtual private network daemon (vpnd) in Apple Mac OS X 10.5 before 10.5.4 allows
23RISK
open ↗Referência✓ VexDay Proof
MDaemon POP3 Server < 9.06 - 'USER' Remote Buffer Overflow (PoC)
Multiple heap-based buffer overflows in the POP3 server in Alt-N Technologies MDaemon before 9.0.6 allow remote attacker
35RISK
open ↗Referência✓ VexDay Proof
Falt4 CMS rc4 10.9.2007 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Falt4Extreme RC4 10.9.2007 allow remote attackers to inject arbit
23RISK
open ↗Referência✓ VexDay Proof
Interact 2.2 - 'CONFIG[base_path]' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in interact 2.2, when register_globals is enabled, allow remote attac
23RISK
open ↗Referência✓ VexDay Proof
xml2owl 0.1.1 - 'filedownload.php' Remote File Disclosure
Directory traversal vulnerability in filedownload.php in xml2owl 0.1.1 allows remote attackers to read arbitrary files v
23RISK
open ↗Referência✓ VexDay Proof
HP Compaq Notebooks - ActiveX Remote Code Execution
Absolute path traversal vulnerability in the HPInfoDLL.HPInfo.1 ActiveX control in HPInfoDLL.dll 1.0, as shipped with HP
35RISK
open ↗Referência✓ VexDay Proof
phpGroupWare 0.9.16.010 - 'GLOBALS[]' Remote Code Execution
Directory traversal vulnerability in calendar/inc/class.holidaycalc.inc.php in phpGroupWare 0.9.16.010 and earlier allow
23RISK
open ↗Referência✓ VexDay Proof
SH-News 3.0 - 'comments.php' SQL Injection
SQL injection vulnerability in patch/comments.php in SH-News 3.0 allows remote attackers to execute arbitrary SQL comman
23RISK
open ↗Referência✓ VexDay Proof
TR Forum 2.0 - SQL Injection / Bypass Security Restriction
The admin panel in Tr Forum 2.0 accepts a username and password hash for authentication, which allows remote authenticat
23RISK
open ↗Referência✓ VexDay Proof
TikiWiki 1.9 Sirius - 'jhot.php' Remote Command Execution
Unrestricted file upload vulnerability in jhot.php in TikiWiki 1.9.4 Sirius and earlier allows remote attackers to execu
50RISK
open ↗Referência✓ VexDay Proof
Ace Image Hosting Script - 'id' SQL Injection
SQL injection vulnerability in albums.php in Ace Image Hosting Script allows remote authenticated users to execute arbit
23RISK
open ↗Referência✓ VexDay Proof
Flat PHP Board 1.2 - Multiple Vulnerabilities
Flat PHP Board 1.2 and earlier stores sensitive information under the web root with insufficient access control, which a
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.