Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,465Referência 23,022GitHub PoC 15,031VulnCheck XDB 8,860Nuclei 4,361Metasploit 3,491✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
ClassWeb 2.0.3 - 'BASE' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in ClassWeb 2.03 and earlier allow remote attackers to execute arbitr
23RISK
open ↗Referência✓ VexDay Proof
PortailPhp 2.0 - 'idnews' SQL Injection
SQL injection vulnerability in index.php in PortailPHP 2.0 allows remote attackers to execute arbitrary SQL commands via
23RISK
open ↗Referência✓ VexDay Proof
Active NewsLetter 4.3 - 'ViewNewspapers.asp' SQL Injection
SQL injection vulnerability in ViewNewspapers.asp in Active Newsletter 4.3 and earlier allows remote attackers to execut
23RISK
open ↗Referência✓ VexDay Proof
Philex 0.2.3 - Remote File Inclusion / File Disclosure
download.php in Philex 0.2.3 and earlier allows remote attackers to read arbitrary files and source code, and obtain sen
23RISK
open ↗Referência✓ VexDay Proof
Mambo Module Flatmenu 1.07 - Remote File Inclusion
PHP remote file inclusion vulnerability in mod_flatmenu.php in the Flatmenu 1.07 and earlier Mambo module allows remote
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component RWCards 2.4.3 - SQL Injection
SQL injection vulnerability in index.php in the RWCards (com_rwcards) 2.4.3 and earlier component for Joomla! allows rem
23RISK
open ↗Referência✓ VexDay Proof
Active Trade 2 - 'catid' SQL Injection
SQL injection vulnerability in default.asp in Active Trade 2 allows remote attackers to execute arbitrary SQL commands v
23RISK
open ↗Referência✓ VexDay Proof
eWebquiz 8 - 'eWebQuiz.asp' SQL Injection
SQL injection vulnerability in eWebQuiz.asp in eWebQuiz 8 allows remote attackers to execute arbitrary SQL commands via
23RISK
open ↗Referência✓ VexDay Proof
ttCMS 4 - 'ez_sql.php?lib_path' Remote File Inclusion
PHP remote file inclusion vulnerability in lib/db/ez_sql.php in ttCMS 4 and earlier allows remote attackers to execute a
23RISK
open ↗Referência✓ VexDay Proof
Corel WordPerfect X3 13.0.0.565 - '.prs' Local Buffer Overflow
Stack-based buffer overflow in Corel WordPerfect Office X3 (13.0.0.565) allows user-assisted remote attackers to execute
23RISK
open ↗Referência✓ VexDay Proof
PHP-Nuke Module Eve-Nuke 0.1 - 'mysql.php' Remote File Inclusion
PHP remote file inclusion vulnerability in db/mysql.php in the Eve-Nuke 0.1 (EN-Forums) module for PHP-Nuke allows remot
23RISK
open ↗Referência✓ VexDay Proof
Kaqoo Auction - 'install_root' Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Kaqoo Auction Software Free Edition allow remote attackers to exec
23RISK
open ↗Referência✓ VexDay Proof
Picture-Engine 1.2.0 - 'wall.php?cat' SQL Injection
SQL injection vulnerability in wall.php in Picture-Engine 1.2.0 and earlier allows remote attackers to execute arbitrary
23RISK
open ↗Referência✓ VexDay Proof
XOOPS Module RM+Soft Gallery 1.0 - Blind SQL Injection
SQL injection vulnerability in categos.php in the RM+Soft Gallery (rmgallery) 1.0 module for Xoops allows remote attacke
23RISK
open ↗Referência✓ VexDay Proof
XOOPS Module Kshop 1.17 - 'id' SQL Injection
SQL injection vulnerability in product_details.php in the Kshop 1.17 and earlier module for Xoops allows remote attacker
23RISK
open ↗Referência✓ VexDay Proof
XOOPS Module Tiny Event 1.01 - 'id' SQL Injection
SQL injection vulnerability in index.php in the Tiny Event (tinyevent) 1.01 and earlier module for Xoops allows remote a
23RISK
open ↗Referência✓ VexDay Proof
BT-sondage 1.12 - 'gestion_sondage.php' Remote File Inclusion
PHP remote file inclusion vulnerability in utilitaires/gestion_sondage.php in BT-Sondage 112 allows remote attackers to
23RISK
open ↗Referência✓ VexDay Proof
XOOPS Module MyAds Bug Fix 2.04jp - 'index.php' SQL Injection
SQL injection vulnerability in index.php in the MyAds 2.04jp and earlier module for Xoops allows remote attackers to exe
23RISK
open ↗Referência✓ VexDay Proof
Really Simple PHP and Ajax (RSPA) 2007-03-23 - Remote File Inclusion
Multiple directory traversal vulnerabilities in Really Simple PHP and Ajax (RSPA) 2007-03-23 allow remote attackers to i
23RISK
open ↗Referência✓ VexDay Proof
Pathos CMS 0.92-2 - 'warn.php' Remote File Inclusion
PHP remote file inclusion vulnerability in warn.php in Pathos Content Management System (CMS) 0.92-2 allows remote attac
23RISK
open ↗Referência✓ VexDay Proof
PHP121 Instant Messenger 2.2 - Local File Inclusion
PHP file inclusion vulnerability in php121db.php in PHP121 Instant Messenger 2.2 allows remote attackers to execute arbi
23RISK
open ↗Referência✓ VexDay Proof
Microsoft Word 2007 - Multiple Vulnerabilities
Buffer overflow in wwlib.dll in Microsoft Word 2007 allows remote attackers to cause a denial of service (application cr
28RISK
open ↗Referência✓ VexDay Proof
Microsoft Windows - '.hlp' Local HEAP Overflow (PoC)
Heap-based buffer overflow in Microsoft Windows allows user-assisted remote attackers to have an unknown impact via a cr
28RISK
open ↗Referência✓ VexDay Proof
Beryo 2.0 - 'downloadpic.php?chemin' Remote File Disclosure
Directory traversal vulnerability in downloadpic.php in Beryo 2.0, and possibly other versions including 2.4, allows rem
23RISK
open ↗Referência✓ VexDay Proof
SmodCMS 2.10 - Slownik ssid SQL Injection
SQL injection vulnerability in index.php in the slownik module in SmodCMS 2.10 and earlier allows remote attackers to ex
23RISK
open ↗Referência✓ VexDay Proof
PcP-Guestbook 3.0 - 'lang' Local File Inclusion
Multiple directory traversal vulnerabilities in PcP-Guestbook (PcP-Book) 3.0 allow remote attackers to include and execu
23RISK
open ↗Referência✓ VexDay Proof
PHP-Nuke Module eBoard 1.0.7 - GLOBALS[name] Local File Inclusion
Directory traversal vulnerability in member.php in the eBoard 1.0.7 module for PHP-Nuke allows remote attackers to inclu
23RISK
open ↗Referência✓ VexDay Proof
HIOX GUEST BOOK (HGB) 4.0 - Remote Code Execution
Direct static code injection vulnerability in HIOX Guest Book (HGB) 4.0 allows remote attackers to inject arbitrary PHP
23RISK
open ↗Referência✓ VexDay Proof
gtcatalog 0.9.1 - 'index.php' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in Chris Mac gtcatalog (aka GimeScripts Shopping Catalog) 0.9.1 and
23RISK
open ↗Referência✓ VexDay Proof
Scorp Book 1.0 - 'smilies.php?config' Remote File Inclusion
PHP remote file inclusion vulnerability in smilies.php in Scorp Book 1.0 allows remote attackers to execute arbitrary PH
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.