Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,980cataloged exploits
36,899CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,476Referência 23,400GitHub PoC 15,250VulnCheck XDB 8,959Nuclei 4,393Metasploit 3,502✓ verified onlyrecentpopularrisk
24,476 exploits
Exploit-DB✓ VexDay Proof
FS Freelancer Clone 1.0 - 'profile.php?u' SQL Injection
FS Freelancer Clone 1.0 has SQL Injection via the profile.php u parameter.
23RISK
open ↗Exploit-DB✓ VexDay Proof
FS Linkedin Clone 1.0 - 'grid' / 'fid' / 'id' SQL Injection
FS Linkedin Clone 1.0 has SQL Injection via the group.php grid parameter, profile.php fid parameter, or company_details.
23RISK
open ↗Exploit-DB✓ VexDay Proof
FS Indiamart Clone 1.0 - 'token' / 'id' / 'c' SQL Injection
FS Indiamart Clone 1.0 has SQL Injection via the catcompany.php token parameter, buyleads-details.php id parameter, or c
23RISK
open ↗Exploit-DB✓ VexDay Proof
FS Crowdfunding Script 1.0 - 'latest_news_details.php?id' SQL Injection
FS Crowdfunding Script 1.0 has SQL Injection via the latest_news_details.php id parameter.
23RISK
open ↗Exploit-DB✓ VexDay Proof
FS Groupon Clone 1.0 - 'id' SQL Injection
FS Groupon Clone 1.0 has SQL Injection via the item_details.php id parameter or the vendor_details.php id parameter.
23RISK
open ↗Exploit-DB✓ VexDay Proof
FS Gigs Script 1.0 - 'cat' / 'sc' SQL Injection
FS Gigs Script 1.0 has SQL Injection via the browse-category.php cat parameter, browse-scategory.php sc parameter, or se
23RISK
open ↗Exploit-DB✓ VexDay Proof
Advance B2B Script 2.1.3 - 'show_id' / 'pid' SQL Injection
Advance B2B Script 2.1.3 has SQL Injection via the tradeshow-list-detail.php show_id or view-product.php pid parameter.
23RISK
open ↗Exploit-DB✓ VexDay Proof
FS Trademe Clone 1.0 - 'search' / 'id' SQL Injection
FS Trademe Clone 1.0 has SQL Injection via the search_item.php search parameter or the general_item_details.php id param
23RISK
open ↗Exploit-DB✓ VexDay Proof
Basic B2B Script 2.0.8 - 'product_details.php?id' SQL Injection
Basic B2B Script 2.0.8 has SQL Injection via the product_details.php id parameter.
23RISK
open ↗Exploit-DB✓ VexDay Proof
FS Care Clone 1.0 - 'jobFrequency' / 'jobType' SQL Injection
FS Care Clone 1.0 has SQL Injection via the searchJob.php jobType or jobFrequency parameter.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Advance Online Learning Management Script 3.1 - 'subcatid' / 'popcourseid' SQL Injection
Advance Online Learning Management Script 3.1 has SQL Injection via the courselist.php subcatid or popcourseid parameter
23RISK
open ↗Exploit-DB✓ VexDay Proof
FS Foodpanda Clone 1.0 - SQL Injection
FS Foodpanda Clone 1.0 has SQL Injection via the /food keywords parameter.
23RISK
open ↗Exploit-DB✓ VexDay Proof
FS IMDB Clone 1.0 - 'f' / 's' / 'id' SQL Injection
FS IMDB Clone 1.0 has SQL Injection via the movie.php f parameter, tvshow.php s parameter, or show_misc_video.php id par
23RISK
open ↗Exploit-DB✓ VexDay Proof
FS Grubhub Clone 1.0 - 'keywords' SQL Injection
FS Grubhub Clone 1.0 has SQL Injection via the /food keywords parameter.
23RISK
open ↗Exploit-DB✓ VexDay Proof
FS Ebay Clone 1.0 - 'id' / 'sub_category_id' / 'category_id' SQL Injection
FS Ebay Clone 1.0 has SQL Injection via the product.php id parameter, or the search.php category_id or sub_category_id p
23RISK
open ↗Exploit-DB✓ VexDay Proof
Beauty Parlour Booking Script 1.0 - 'gender' / 'city' SQL Injection
Beauty Parlour Booking Script 1.0 has SQL Injection via the /list gender or city parameter.
23RISK
open ↗Exploit-DB
Affiliate MLM Script 1.0 - 'product-category.php?key' SQL Injection
Affiliate MLM Script 1.0 has SQL Injection via the product-category.php key parameter.
23RISK
open ↗Exploit-DB✓ VexDay Proof
FS Expedia Clone 1.0 - 'fl_orig' / 'fl_dest' / 'id' SQL Injection
FS Expedia Clone 1.0 has SQL Injection via the pages.php or content.php id parameter, or the show-flight-result.php fl_o
23RISK
open ↗Exploit-DB
Event Calendar Category Script 1.0 - 'city' SQL Injection
Event Search Script 1.0 has SQL Injection via the /event-list city parameter.
23RISK
open ↗Exploit-DB✓ VexDay Proof
DomainSale PHP Script 1.0 - 'id' SQL Injection
DomainSale PHP Script 1.0 has SQL Injection via the domain.php id parameter.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Website Auction Marketplace 2.0.5 - 'cat_id' SQL Injection
Website Auction Marketplace 2.0.5 has SQL Injection via the search.php cat_id parameter.
23RISK
open ↗Exploit-DB
Doctor Search Script 1.0 - 'city' SQL Injection
Doctor Search Script 1.0 has SQL Injection via the /list city parameter.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Simple Chatting System 1.0.0 - Arbitrary File Upload
Simple Chatting System 1.0 allows Arbitrary File Upload via view/my_profile.php, which places files under uploads/.
23RISK
open ↗Exploit-DB✓ VexDay Proof
FS Quibids Clone 1.0 - SQL Injection
FS Quibids Clone 1.0 has SQL Injection via the itechd.php productid parameter.
23RISK
open ↗Exploit-DB✓ VexDay Proof
FS Shutterstock Clone 1.0 - 'keywords' SQL Injection
FS Shutterstock Clone 1.0 has SQL Injection via the /Category keywords parameter.
23RISK
open ↗Exploit-DB
Nearbuy Clone Script 3.2 - 'search' SQL Injection
Nearbuy Clone Script 3.2 has SQL Injection via the category_list.php search parameter.
23RISK
open ↗Exploit-DB✓ VexDay Proof
FS Olx Clone 1.0 - 'scat' / 'pid' SQL Injection
FS Olx Clone 1.0 has SQL Injection via the subpage.php scat parameter or the message.php pid parameter.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Realestate Crowdfunding Script 2.7.2 - 'pid' SQL Injection
Realestate Crowdfunding Script 2.7.2 has SQL Injection via the single-cause.php pid parameter.
23RISK
open ↗Exploit-DB✓ VexDay Proof
FS Stackoverflow Clone 1.0 - 'keywords' SQL Injection
FS Stackoverflow Clone 1.0 has SQL Injection via the /question keywords parameter.
23RISK
open ↗Exploit-DB
Child Care Script 1.0 - 'city' SQL Injection
Child Care Script 1.0 has SQL Injection via the /list city parameter.
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.