Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,207cataloged exploits
36,419CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,464Referência 23,022GitHub PoC 15,023VulnCheck XDB 8,846Nuclei 4,361Metasploit 3,491✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
Cartweaver 3 - 'prodId' Blind SQL Injection
SQL injection vulnerability in details.php in Application Dynamics Cartweaver 3.0 allows remote attackers to execute arb
23RISK
open ↗Referência✓ VexDay Proof
iWare Pro 5.0.4 - 'chat_panel.php' Remote Code Execution
Static code injection vulnerability in chat_panel.php in the SimpleChat 1.0.0 module for iWare Professional CMS allows r
23RISK
open ↗Referência✓ VexDay Proof
TorrentFlux 2.2 - 'downloaddetails.php' Local File Disclosure
Directory traversal vulnerability in viewnfo.php in (1) TorrentFlux before 2.2 and (2) torrentflux-b4rt before 2.1-b4rt-
23RISK
open ↗Referência✓ VexDay Proof
NewsCMSLite - 'newsCMS.mdb' Remote Password Disclosure
newsCMSlite stores sensitive information under the web root with insufficient access control, which allows remote attack
23RISK
open ↗Referência✓ VexDay Proof
Pakupaku CMS 0.4 - Arbitrary File Upload / Local File Inclusion
Unrestricted file upload vulnerability in index.php in Pakupaku CMS 0.4 and earlier allows remote attackers to upload an
23RISK
open ↗Referência✓ VexDay Proof
Webace-Linkscript 1.3 SE - 'start.php' SQL Injection
SQL injection vulnerability in start.php in Webace-Linkscript (wls) 1.3 Special Edition (SE) allows remote attackers to
23RISK
open ↗Referência✓ VexDay Proof
rgboard 3.0.12 - Remote File Inclusioni / Cross-Site Scripting
PHP remote file inclusion vulnerability in include/bbs.lib.inc.php in Rgboard 3.0.12 allows remote attackers to execute
23RISK
open ↗Referência✓ VexDay Proof
ourvideo CMS 9.5 - Local File Inclusion / Remote File Inclusion / Cross-Site Scripting
Multiple PHP remote file inclusion vulnerabilities in Ourvideo CMS 9.5 allow remote attackers to execute arbitrary PHP c
23RISK
open ↗Referência✓ VexDay Proof
tplSoccerSite 1.0 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in tplSoccerSite 1.0 allow remote attackers to execute arbitrary SQL commands via
23RISK
open ↗Referência✓ VexDay Proof
YourFreeWorld Shopping Cart - Blind SQL Injection
SQL injection vulnerability in index.php in YourFreeWorld Shopping Cart Script allows remote attackers to execute arbitr
23RISK
open ↗Referência✓ VexDay Proof
sCssBoard (Multiple Versions) - 'pwnpack' Remote s
PHP remote file inclusion vulnerability in index.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allows remote attackers to ex
23RISK
open ↗Referência✓ VexDay Proof
TorrentTrader Classic 1.09 - Multiple Vulnerabilities
Directory traversal vulnerability in backend/admin-functions.php in TorrentTrader Classic 1.09, when used on a case-inse
23RISK
open ↗Referência✓ VexDay Proof
Exero CMS 1.0.1 - 'theme' Multiple Local File Inclusions
Multiple directory traversal vulnerabilities in the Default theme in Exero CMS 1.0.1 allow remote attackers to include a
23RISK
open ↗Referência✓ VexDay Proof
Boite de News 4.0.1 - 'index.php' Remote File Inclusion
PHP remote file inclusion vulnerability in boitenews4/index.php in Boite de News 4.0.1 allows remote attackers to execut
23RISK
open ↗Referência✓ VexDay Proof
phpAtm 1.21 - 'include_location' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in PHP Advanced Transfer Manager (phpAtm) 1.21 and earlier allow remo
23RISK
open ↗Referência✓ VexDay Proof
OtomiGen.x 2.2 - 'lang' Local File Inclusion
Multiple directory traversal vulnerabilities in OtomiGenX 2.2 allow remote attackers to include and execute arbitrary lo
23RISK
open ↗Referência✓ VexDay Proof
e107 < 0.75 - 'e107language_e107cookie' Local File Inclusion
Directory traversal vulnerability in class2.php in e107 0.7.5 and earlier allows remote attackers to read and execute PH
23RISK
open ↗Referência✓ VexDay Proof
ezcms 1.2 - Blind SQL Injection / Authentication Bypass
admin/filemanager/ (aka the File Manager) in EZTechhelp EZCMS 1.2 and earlier does not require authentication, which all
23RISK
open ↗Referência✓ VexDay Proof
syzygyCMS 0.3 - 'index.php' Local File Inclusion
Directory traversal vulnerability in index.php in SyzygyCMS 0.3 allows remote attackers to include and execute arbitrary
23RISK
open ↗Referência✓ VexDay Proof
AuraCMS 2.2 - Remote Add Administrator
Directory traversal vulnerability in index.php in AuraCMS 2.2 allows remote authenticated users to include and execute a
23RISK
open ↗Referência✓ VexDay Proof
Mini-CMS 1.0.1 - 'index.php' Local File Inclusion
Multiple directory traversal vulnerabilities in index.php in Mini CMS 1.0.1 allow remote attackers to include and execut
23RISK
open ↗Referência✓ VexDay Proof
KTP Computer Customer Database CMS 1.0 - Local File Inclusion
Directory traversal vulnerability in KTP Computer Customer Database (KTPCCD) CMS, when magic_quotes_gpc is disabled, all
23RISK
open ↗Referência✓ VexDay Proof
Absolute Form Processor XE-V 1.5 - Insecure Cookie Handling
Absolute Form Processor XE 1.5 allows remote attackers to bypass authentication and gain administrative access by settin
23RISK
open ↗Referência✓ VexDay Proof
Bitweaver 2.6 - 'saveFeed()' Remote Code Execution
Directory traversal vulnerability in the saveFeed function in rss/feedcreator.class.php in Bitweaver 2.6 and earlier all
23RISK
open ↗Referência✓ VexDay Proof
Postfix 2.6-20080814 - 'symlink' Local Privilege Escalation
Postfix before 2.3.15, 2.4 before 2.4.8, 2.5 before 2.5.4, and 2.6 before 2.6-20080814, when the operating system suppor
23RISK
open ↗Referência✓ VexDay Proof
GGCMS 1.1.0 RC1 - Remote Code Execution
Directory traversal vulnerability in admin/subpages.php in GGCMS 1.1.0 RC1 and earlier allows remote attackers to inject
23RISK
open ↗Referência✓ VexDay Proof
Garennes 0.6.1 - 'repertoire_config' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Garennes 0.6.1 and earlier allow remote attackers to execute arbit
23RISK
open ↗Referência✓ VexDay Proof
iyzi Forum 1.0b3 - Database Disclosure
iyzi Forum 1.0 beta 3 stores sensitive information under the web root with insufficient access control, which allows rem
23RISK
open ↗Referência✓ VexDay Proof
GoSamba 1.0.1 - 'INCLUDE_PATH' Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in GoSamba 1.0.1 allow remote attackers to execute arbitrary PHP code
23RISK
open ↗Referência✓ VexDay Proof
Apache Tomcat < 6.0.18 - 'utf8' Directory Traversal (PoC)
Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16,
60RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.