Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,465Referência 23,022GitHub PoC 15,031VulnCheck XDB 8,860Nuclei 4,361Metasploit 3,491✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
CaupoShop Pro 2.x - 'action' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in CaupoShop Pro 2.x allows remote attackers to execute arbitrary P
23RISK
open ↗Referência✓ VexDay Proof
Softbiz Link Directory Script - SQL Injection
SQL injection vulnerability in searchresult.php in Softbiz Link Directory Script allows remote attackers to execute arbi
23RISK
open ↗Referência✓ VexDay Proof
ClipShare < 3.0.1 - 'tid' SQL Injection
SQL injection vulnerability in group_posts.php in ClipShare before 3.0.1 allows remote attackers to execute arbitrary SQ
23RISK
open ↗Referência✓ VexDay Proof
doITlive CMS 2.50 - SQL Injection / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in edit/showmedia.asp in doITLive CMS 2.50 and earlier allows remote attackers
23RISK
open ↗Referência✓ VexDay Proof
BoatScripts Classifieds - 'type' SQL Injection
SQL injection vulnerability in index.php in BoatScripts Classifieds allows remote attackers to execute arbitrary SQL com
23RISK
open ↗Referência✓ VexDay Proof
project alumni 1.0.9 - Cross-Site Scripting / SQL Injection
Multiple cross-site scripting (XSS) vulnerabilities in project alumni 1.0.9 and earlier allow remote attackers to inject
23RISK
open ↗Referência✓ VexDay Proof
WorkingOnWeb 2.0.1400 - 'events.php' SQL Injection
SQL injection vulnerability in events.php in WorkingOnWeb 2.0.1400 allows remote attackers to execute arbitrary SQL comm
23RISK
open ↗Referência✓ VexDay Proof
Content Injector 1.52 - 'index.php?cat' SQL Injection
SQL injection vulnerability in news.php in Content Injector 1.52 allows remote attackers to execute arbitrary SQL comman
23RISK
open ↗Referência✓ VexDay Proof
Debian OpenSSH - (Authenticated) Remote SELinux Privilege Escalation
sshd in OpenSSH 4 on Debian GNU/Linux, and the 20070303 OpenSSH snapshot, allows remote authenticated users to obtain ac
23RISK
open ↗Referência✓ VexDay Proof
IAPR COMMENCE 1.3 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in IAPR COMMENCE 1.3 allow remote attackers to execute arbitrary PHP
23RISK
open ↗Referência✓ VexDay Proof
Arctic Issue Tracker 2.0.0 - 'filter' SQL Injection (2)
SQL injection vulnerability in index.php in Arctic Issue Tracker 2.0.0 allows remote attackers to execute arbitrary SQL
23RISK
open ↗Referência✓ VexDay Proof
bilboblog 2.1 - Multiple Vulnerabilities
admin/login.php in BilboBlog 0.2.1, when register_globals is enabled, allows remote attackers to bypass authentication a
23RISK
open ↗Referência✓ VexDay Proof
Eurologon CMS - Multiple SQL Injections
Multiple SQL injection vulnerabilities in Eurologon CMS allow remote attackers to execute arbitrary SQL commands via the
23RISK
open ↗Referência✓ VexDay Proof
Apple QuickTime 7.2/7.3 - RTSP Response Remote Overwrite (SEH)
Stack-based buffer overflow in Apple QuickTime before 7.3.1, as used in QuickTime Player on Windows XP and Safari on Mac
50RISK
open ↗Referência✓ VexDay Proof
Plogger 3.0 - SQL Injection
Multiple SQL injection vulnerabilities in Plogger 3.0 and earlier allow remote attackers to execute arbitrary SQL comman
23RISK
open ↗Referência✓ VexDay Proof
IP Reg 0.4 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in IP Reg 0.4 and earlier allow remote attackers to execute arbitrary SQL command
23RISK
open ↗Referência✓ VexDay Proof
Eurologon CMS - 'files.php' Arbitrary File Download
Directory traversal vulnerability in users/files.php in Eurologon CMS allows remote attackers to read arbitrary files vi
23RISK
open ↗Referência✓ VexDay Proof
wPortfolio 0.3 - Admin Password Changing
The account_save action in admin/userinfo.php in wPortfolio 0.3 and earlier does not require authentication and does not
23RISK
open ↗Referência✓ VexDay Proof
WebStudio eCatalogue - Blind SQL Injection
SQL injection vulnerability in index.php in WebStudio eCatalogue allows remote attackers to execute arbitrary SQL comman
23RISK
open ↗Referência✓ VexDay Proof
PG Real Estate - Authentication Bypass
SQL injection vulnerability in admin/index.php in PG Real Estate Solution allows remote attackers to execute arbitrary S
23RISK
open ↗Referência✓ VexDay Proof
WordPress Plugin PictPress 0.91 - Remote File Disclosure
Multiple directory traversal vulnerabilities in resize.php in the PictPress 0.91 and earlier plugin for WordPress allow
23RISK
open ↗Referência✓ VexDay Proof
Roundcube Webmail 0.2b - Remote Code Execution
html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail)
35RISK
open ↗Referência✓ VexDay Proof
phpMyAdmin 3.1.0 - Cross-Site Request Forgery / SQL Injection
Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.11.x before 2.11.9.4 and 3.x before 3.1.1.0 allows remot
23RISK
open ↗Referência✓ VexDay Proof
PHP-Fusion Mod TI - 'id' SQL Injection
SQL injection vulnerability in blog.php in the Team Impact TI Blog System mod for PHP-Fusion allows remote attackers to
23RISK
open ↗Referência✓ VexDay Proof
CzarNews 1.14 - 'tpath' Remote File Inclusion
PHP remote file inclusion vulnerability in CzarNews 1.13b allows remote attackers to execute arbitrary PHP code via the
28RISK
open ↗Referência✓ VexDay Proof
CoolPlayer 2.19 - '.Skin' Local Buffer Overflow
Stack-based buffer overflow in skin.c in CoolPlayer 2.17 through 2.19 allows remote attackers to execute arbitrary code
23RISK
open ↗Referência✓ VexDay Proof
CoolPlayer 2.19 - '.Skin' Local Buffer Overflow
Stack-based buffer overflow in skin.c in CoolPlayer 2.17 through 2.19 allows remote attackers to execute arbitrary code
23RISK
open ↗Referência✓ VexDay Proof
WordPress Plugin Page Flip Image Gallery 0.2.2 - Remote File Disclosure
Directory traversal vulnerability in getConfig.php in the Page Flip Image Gallery plugin 0.2.2 and earlier for WordPress
23RISK
open ↗Referência✓ VexDay Proof
BulletProof FTP Client 2.63 - Local Heap Overflow (PoC)
Stack-based buffer overflow in BulletProof FTP Client 2.63 and 2010 allows user-assisted attackers to execute arbitrary
23RISK
open ↗Referência✓ VexDay Proof
Gateway Weblaunch - ActiveX Control Insecure Method
Multiple stack-based buffer overflows in the WebLaunch.WeblaunchCtl.1 (aka CWebLaunchCtl) ActiveX control in weblaunch.o
28RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.