Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,794cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,459Referência 22,721GitHub PoC 14,946VulnCheck XDB 8,829Nuclei 4,350Metasploit 3,489✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
AjPortal2Php - 'PagePrefix' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in AjPortal2Php allow remote attackers to execute arbitrary PHP code
23RISK
open ↗Referência✓ VexDay Proof
AJ Auction Web 2.0 - 'cate_id' SQL Injection
SQL injection vulnerability in category.php in AJSquare AJ Auction Pro web 2.0 allows remote attackers to execute arbitr
23RISK
open ↗Referência✓ VexDay Proof
PHP Site Lock 2.0 - 'index.php' SQL Injection
SQL injection vulnerability in index.php in Kalptaru Infotech PHP Site Lock 2.0 allows remote attackers to execute arbit
23RISK
open ↗Referência✓ VexDay Proof
CaupoShop Classic 1.3 - 'saArticle[ID]' SQL Injection
SQL injection vulnerability in csc_article_details.php in Caupo.net CaupoShop Classic 1.3 allows remote attackers to exe
23RISK
open ↗Referência✓ VexDay Proof
E-topbiz ViralDX 2.07 - 'bannerid' SQL Injection
SQL injection vulnerability in adclick.php in E-topbiz Viral DX 1 2.07 allows remote attackers to execute arbitrary SQL
23RISK
open ↗Referência✓ VexDay Proof
DUcalendar 1.0 - 'iEve' SQL Injection
SQL injection vulnerability in detail.asp in DUware DUcalendar 1.0 and possibly earlier allows remote attackers to execu
23RISK
open ↗Referência✓ VexDay Proof
Link ADS 1 - 'linkid' SQL Injection
SQL injection vulnerability in out.php in E-topbiz Link ADS 1 allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗Referência✓ VexDay Proof
ShareCMS 0.1 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in ShareCMS 0.1 Beta allow remote attackers to execute arbitrary SQL commands via
23RISK
open ↗Referência✓ VexDay Proof
shibby shop 2.2 - Multiple Vulnerabilities
sHibby sHop 2.2 and earlier stores sensitive information under the web root with insufficient access control, which allo
23RISK
open ↗Referência✓ VexDay Proof
AvailScript Classmate Script - 'viewprofile.php' SQL Injection
SQL injection vulnerability in viewprofile.php in Availscript Classmate Script allows remote attackers to execute arbitr
23RISK
open ↗Referência✓ VexDay Proof
Live TV Script - 'index.php?mid' SQL Injection
SQL injection vulnerability in index.php in Live TV Script allows remote attackers to execute arbitrary SQL commands via
23RISK
open ↗Referência✓ VexDay Proof
Natterchat 1.1 - Authentication Bypass
Multiple SQL injection vulnerabilities in login.asp in NatterChat 1.1 and 1.12 allow remote attackers to execute arbitra
23RISK
open ↗Referência✓ VexDay Proof
Jokes & Funny Pics Script - 'sb_jokeid' SQL Injection
SQL injection vulnerability in index.php in Softbiz Jokes & Funny Pics Script allows remote attackers to execute arbitra
23RISK
open ↗Referência✓ VexDay Proof
phpAuction 3.2.1 - 'item.php' SQL Injection
SQL injection vulnerability in item.php in PHPAuction 3.2 allows remote attackers to execute arbitrary SQL commands via
23RISK
open ↗Referência✓ VexDay Proof
Advanced Webhost Billing System (AWBS) 2.7.1 - 'news.php' SQL Injection
SQL injection vulnerability in news.php in Advanced Webhost Billing System (AWBS) 2.3.3 through 2.7.1, when magic_quotes
23RISK
open ↗Referência✓ VexDay Proof
Mambo 4.6.4 - 'Output.php' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/Cache/Lite/Output.php in the Cache_Lite package in Mambo 4.6.4 and e
43RISK
open ↗Referência✓ VexDay Proof
Natterchat 1.12 - Authentication Bypass
Multiple SQL injection vulnerabilities in login.asp in NatterChat 1.1 and 1.12 allow remote attackers to execute arbitra
23RISK
open ↗Referência✓ VexDay Proof
WebChamado 1.1 - 'tsk_id' SQL Injection
SQL injection vulnerability in lista_anexos.php in WebChamado 1.1 allows remote attackers to execute arbitrary SQL comma
23RISK
open ↗Referência✓ VexDay Proof
Pre Job Board - 'JobSearch.php' SQL Injection
Multiple SQL injection vulnerabilities in jobseekers/JobSearch.php (aka the search module) in Pre Job Board allow remote
23RISK
open ↗Referência✓ VexDay Proof
Pre ADS Portal 2.0 - SQL Injection
Multiple SQL injection vulnerabilities in Pre ADS Portal 2.0 and earlier, when magic_quotes_gpc is disabled, allow remot
23RISK
open ↗Referência✓ VexDay Proof
CJG EXPLORER PRO 3.2 - 'g_pcltar_lib_dir' Remote File Inclusion
PHP remote file inclusion vulnerability in lib/pcltar.lib.php (aka pcltar.php) in the PclTar module 1.3 and 1.3.1 for Vi
35RISK
open ↗Referência✓ VexDay Proof
Dana IRC 1.3 - Remote Buffer Overflow (PoC)
Stack-based buffer overflow in artegic Dana IRC client 1.3 and earlier allows remote attackers to cause a denial of serv
23RISK
open ↗Referência✓ VexDay Proof
mIRC 6.34 - Remote Buffer Overflow
Stack-based buffer overflow in mIRC 6.34 allows remote attackers to execute arbitrary code via a long hostname in a PRIV
50RISK
open ↗Referência✓ VexDay Proof
LogMeIn Remote Access Utility - ActiveX Memory Corruption (Denial of Service)
LogMeIn Remote Access Utility ActiveX control (RACtrl.dll) allows remote attackers to cause a denial of service (crash)
23RISK
open ↗Referência✓ VexDay Proof
PHP-CMS 1 - 'Username' Blind SQL Injection
SQL injection vulnerability in admin/login.php in PHP-CMS Project 1 allows remote attackers to execute arbitrary SQL com
23RISK
open ↗Referência✓ VexDay Proof
BandSite CMS 1.1.4 - Download Backup / Cross-Site Scripting / Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in BandSite CMS 1.1.4 allows remote attackers to hijack the authenticati
23RISK
open ↗Referência✓ VexDay Proof
Poppler 0.8.4 - libpoppler Uninitialized pointer Code Execution
The Page destructor in Page.cc in libpoppler in Poppler 0.8.4 and earlier deletes a pageWidgets object even if it is not
28RISK
open ↗Referência✓ VexDay Proof
Visual Basic Enterprise Edition SP6 - 'vb6skit.dll' Buffer Overflow (PoC)
Buffer overflow in a certain ActiveX control (vb6skit.dll) in Microsoft Visual Basic Enterprise Edition 6.0 SP6 might al
28RISK
open ↗Referência✓ VexDay Proof
ICQ Toolbar 2.3 - ActiveX Remote Denial of Service
toolbaru.dll in ICQ Toolbar (ICQToolbar) 2.3 allows remote attackers to cause a denial of service (toolbar crash) via a
23RISK
open ↗Referência✓ VexDay Proof
CMS Mini 0.2.2 - Multiple Local File Inclusions
Multiple directory traversal vulnerabilities in view/index.php in CMS Mini 0.2.2 allow remote attackers to read arbitrar
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.