Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,794cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,459Referência 22,721GitHub PoC 14,946VulnCheck XDB 8,829Nuclei 4,350Metasploit 3,489✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
Sports Clubs Web Panel 0.0.1 - 'p' Local File Inclusion
Directory traversal vulnerability in index.php in Sports Clubs Web Panel 0.0.1 allows remote attackers to include and ex
23RISK
open ↗Referência✓ VexDay Proof
EasyMail - ActiveX 'emmailstore.dll 6.5.0.3' Remote Buffer Overflow
Buffer overflow in emmailstore.dll 6.5.0.3 in the QuikSoft EasyMail MailStore ActiveX control allows remote attackers to
23RISK
open ↗Referência✓ VexDay Proof
IBM Domino Web Access 7.0 Upload Module - 'inotes6.dll' Remote Buffer Overflow
Multiple stack-based buffer overflows in the IBM Lotus Domino Web Access ActiveX control, as provided by inotes6.dll, in
50RISK
open ↗Referência✓ VexDay Proof
IBM Domino Web Access Upload Module - Overwrite (SEH)
Multiple stack-based buffer overflows in the IBM Lotus Domino Web Access ActiveX control, as provided by inotes6.dll, in
50RISK
open ↗Referência✓ VexDay Proof
iGaming CMS 2.0 Alpha 1 - 'search.php' SQL Injection
SQL injection vulnerability in search.php in iGaming CMS 2.0 Alpha 1 allows remote attackers to execute arbitrary SQL co
23RISK
open ↗Referência✓ VexDay Proof
CafeEngine - Multiple SQL Injections
SQL injection vulnerability in CafeEngine allows remote attackers to execute arbitrary SQL commands via the id parameter
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component EventList 0.8 - 'did' SQL Injection
SQL injection vulnerability in index.php in the EventList component (com_eventlist) 0.8 and earlier for Joomla! allows r
23RISK
open ↗Referência✓ VexDay Proof
HP Virtual Rooms WebHPVCInstall Control - Remote Buffer Overflow
Multiple buffer overflows in the WebHPVCInstall.HPVirtualRooms14 ActiveX control in HPVirtualRooms14.dll 1.0.0.100, as u
35RISK
open ↗Referência✓ VexDay Proof
Diesel Job Site - 'job_id' Blind SQL Injection
SQL injection vulnerability in jobs/jobseekers/job-info.php in Diesel Job Site allows remote attackers to execute arbitr
23RISK
open ↗Referência✓ VexDay Proof
fungamez rc1 - Authentication Bypass / Local File Inclusion
SQL injection vulnerability in pages/login.php in FunGamez RC1 allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component com_iJoomla_rss - Blind SQL Injection
SQL injection vulnerability in the iJoomla RSS Feeder (com_ijoomla_rss) component for Joomla! allows remote attackers to
23RISK
open ↗Referência✓ VexDay Proof
PortalApp 4.0 - SQL Injection / Cross-Site Scripting / Authentication Bypass
PortalApp 4.0 does not require authentication for (1) forums.asp and (2) content.asp, which allows remote attackers to c
23RISK
open ↗Referência✓ VexDay Proof
phpFastNews 1.0.0 - Insecure Cookie Handling
The isLoggedIn function in fastnews-code.php in phpFastNews 1.0.0 allows remote attackers to bypass authentication and g
23RISK
open ↗Referência✓ VexDay Proof
Fast Click SQL 1.1.7 Lite - 'init.php' Remote File Inclusion
PHP remote file inclusion vulnerability in init.php in Fast Click SQL Lite 1.1.7, when register_globals is enabled, allo
23RISK
open ↗Referência✓ VexDay Proof
Blogator-script 0.95 - Change User Password
_blogadata/include/init_pass2.php in Blogator-script 0.95 allows remote attackers to change the password for arbitrary u
23RISK
open ↗Referência✓ VexDay Proof
WordPress Plugin st_newsletter - 'stnl_iframe.php' SQL Injection
SQL injection vulnerability in stnl_iframe.php in the ShiftThis Newsletter (st_newsletter) plugin for WordPress allows r
23RISK
open ↗Referência✓ VexDay Proof
Yappa-ng 2.3.3-beta0 - 'album' Local File Inclusion
Directory traversal vulnerability in index.php in Fritz Berger yet another php photo album - next generation (yappa-ng)
23RISK
open ↗Referência✓ VexDay Proof
WBB Plugin rGallery 1.09 - 'itemID' Blind SQL Injection
SQL injection vulnerability in the rGallery plugin 1.09 for WoltLab Burning Board (WBB) allows remote attackers to execu
23RISK
open ↗Referência✓ VexDay Proof
mystats - 'hits.php' Multiple Vulnerabilities
SQL injection vulnerability in hits.php in myWebland myStats allows remote attackers to execute arbitrary SQL commands v
23RISK
open ↗Referência✓ VexDay Proof
NVR SP2 2.0 'nvUtility.dll 1.0.14.0' - 'SaveXMLFile()' Insecure Method
Multiple absolute path traversal vulnerabilities in the nvUtility.Utility.1 ActiveX control in nvUtility.dll 1.0.14.0 in
23RISK
open ↗Referência✓ VexDay Proof
PHPWebGallery 1.7.2 - Session Hijacking / Code Execution
plugins/event_tracer/event_list.php in PhpWebGallery 1.7.2 and earlier allows remote authenticated administrators to exe
23RISK
open ↗Referência✓ VexDay Proof
WebFileExplorer 3.1 - 'db.mdb' Database Disclosure
Web File Explorer 3.1 stores sensitive information under the web root with insufficient access control, which allows rem
23RISK
open ↗Referência✓ VexDay Proof
TorrentTrader Classic 1.09 - Multiple Vulnerabilities
TorrentTrader Classic 1.09 allows remote attackers to (1) obtain configuration information via a direct request to phpin
23RISK
open ↗Referência✓ VexDay Proof
XOOPS Module makale 0.26 - SQL Injection
SQL injection vulnerability in makale.php in Makale 0.26 and possibly other versions, a module for XOOPS, allows remote
23RISK
open ↗Referência✓ VexDay Proof
XAMPP 1.6.8 - Cross-Site Request Forgery (Change Administrative Password)
security/xamppsecurity.php in XAMPP 1.6.8 performs an extract operation on the SERVER superglobal array, which allows re
23RISK
open ↗Referência✓ VexDay Proof
Microsoft Windows - GDI Image Parsing Stack Overflow (MS08-021)
Stack-based buffer overflow in GDI in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, and Server 200
35RISK
open ↗Referência✓ VexDay Proof
iDB 0.2.5pa SVN 243 - 'skin' Local File Inclusion
Directory traversal vulnerability in inc/profilemain.php in Game Maker 2k Internet Discussion Boards (iDB) 0.2.5 Pre-Alp
23RISK
open ↗Referência✓ VexDay Proof
Ultimate WebBoard 3.00 - 'Category' SQL Injection
SQL injection vulnerability in webboard.php in Ultimate Webboard 3.00 allows remote attackers to execute arbitrary SQL c
23RISK
open ↗Referência✓ VexDay Proof
Real Estate Manager 1.01 - 'cat_id' SQL Injection
SQL injection vulnerability in realestate-index.php in Conkurent Real Estate Manager 1.01 allows remote attackers to exe
23RISK
open ↗Referência✓ VexDay Proof
PHPcounter 1.3.2 - 'index.php' SQL Injection
SQL injection vulnerability in index.php in PHPcounter 1.3.2 and earlier allows remote attackers to execute arbitrary SQ
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.