Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,465Referência 23,022GitHub PoC 15,031VulnCheck XDB 8,860Nuclei 4,361Metasploit 3,491✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
eNdonesia 8.4 - '/mod.php/friend.php/admin.php' Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in eNdonesia 8.4 allow remote attackers to inject arbitrary web scri
23RISK
open ↗Referência✓ VexDay Proof
PHP-Update 2.7 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in code/guestadd.php in PHP-Update 2.7 and earlier allow remote attackers to exec
23RISK
open ↗Referência✓ VexDay Proof
Macromedia Shockwave 10 'SwDir.dll' Internet Explorer 7 - Denial of Service
An ActiveX control in SwDir.dll in Macromedia Shockwave 10 allows remote attackers to cause a denial of service (Interne
23RISK
open ↗Referência✓ VexDay Proof
Voodoo chat 1.0RC1b - 'users.dat' Password Disclosure
Voodoo chat 1.0RC1b stores sensitive information under the web root with insufficient access control, which allows remot
23RISK
open ↗Referência✓ VexDay Proof
Vz (Adp) Forum 2.0.3 - Remote Password Disclosure
Vz (Adp) Forum 2.0.3 stores sensitive information under the web root with insufficient access control, which allows remo
23RISK
open ↗Referência✓ VexDay Proof
Formbankserver 1.9 - 'Name' Remote Denial of Service
formbankcgi.exe in Fersch Formbankserver 1.9, when the PATH_INFO begins with Abfrage, allows remote attackers to cause a
23RISK
open ↗Referência✓ VexDay Proof
Quote&Ordering System 1.0 - 'ordernum' Multiple Vulnerabilities
SQL injection vulnerability in search.asp in Digitizing Quote And Ordering System 1.0 allows remote authenticated users
23RISK
open ↗Referência✓ VexDay Proof
CA BrightStor ARCserve - 'tapeeng.exe' Remote Buffer Overflow
Multiple buffer overflows in Computer Associates (CA) BrightStor ARCserve Backup R11.5 Server before SP2 allows remote a
28RISK
open ↗Referência✓ VexDay Proof
PHPGiggle 12.08 - 'CFG_PHPGIGGLE_ROOT' File Inclusion
PHP remote file inclusion vulnerability in kernel/system/startup.php in J. He PHPGiggle 12.08 and earlier, as distribute
23RISK
open ↗Referência✓ VexDay Proof
JAF CMS 4.0 RC2 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in JAF CMS 4.0 and 4.0 RC2 allow remote attackers to execute arbitrar
23RISK
open ↗Referência✓ VexDay Proof
JAF CMS 4.0 RC1 - 'forum.php' Remote File Inclusion
PHP remote file inclusion vulnerability in forum/forum.php JAF CMS 4.0 RC1 allows remote attackers to execute arbitrary
23RISK
open ↗Referência✓ VexDay Proof
Jinzora 2.6 - '/extras/mt.php' Remote File Inclusion
PHP remote file inclusion vulnerability in extras/mt.php in Jinzora 2.6 allows remote attackers to execute arbitrary PHP
23RISK
open ↗Referência✓ VexDay Proof
phpPC 1.04 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in PHP Poll Creator (phpPC) 1.04 and earlier allow remote attackers t
23RISK
open ↗Referência✓ VexDay Proof
PHP-Stats 0.1.9.1b - 'PC-REMOTE-ADDR' SQL Injection
Multiple SQL injection vulnerabilities in php-stats.recphp.php in PHP-Stats 0.1.9.1b and earlier allow remote attackers
23RISK
open ↗Referência✓ VexDay Proof
Mambo Component com_forum 1.2.4RC3 - Remote File Inclusion
PHP remote file inclusion vulnerability in download.php in the Adam van Dongen Forum (com_forum) component (aka phpBB co
23RISK
open ↗Referência✓ VexDay Proof
Microsoft Windows - '.png' IHDR Block Denial of Service (PoC) (1)
Microsoft Windows 2000, XP, and Server 2003 allows remote attackers to cause a denial of service (cpu consumption) via a
28RISK
open ↗Referência✓ VexDay Proof
Microsoft Windows - '.png' IHDR Block Denial of Service (PoC) (2)
Microsoft Windows 2000, XP, and Server 2003 allows remote attackers to cause a denial of service (cpu consumption) via a
28RISK
open ↗Referência✓ VexDay Proof
Microsoft Windows - '.png' IHDR Block Denial of Service (PoC) (3)
Microsoft Windows 2000, XP, and Server 2003 allows remote attackers to cause a denial of service (cpu consumption) via a
28RISK
open ↗Referência✓ VexDay Proof
Apple QuickTime - 'rtsp URL Handler' Remote Stack Buffer Overflow
Buffer overflow in Apple QuickTime 7.1.3 allows remote attackers to execute arbitrary code via a long rtsp:// URI.
50RISK
open ↗Referência✓ VexDay Proof
Mint Haber Sistemi 2.7 - 'duyuru.asp?id' SQL Injection
SQL injection vulnerability in duyuru.asp in MiNT Haber Sistemi 2.7 allows remote attackers to execute arbitrary SQL com
23RISK
open ↗Referência✓ VexDay Proof
Article System 0.1 - 'INCLUDE_DIR' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Article System 1.0 allow remote attackers to execute arbitrary PHP
23RISK
open ↗Referência✓ VexDay Proof
JV2 Folder Gallery 3.0 - 'download.php' Remote File Disclosure
download.php in Joonas Viljanen JV2 Folder Gallery allows remote attackers to read sensitive files via a relative pathna
23RISK
open ↗Referência✓ VexDay Proof
BolinTech DreamFTP Server - 'USER' Remote Buffer Overflow (PoC)
Heap-based buffer overflow in Dream FTP Server allows remote attackers to execute arbitrary code via a USER command with
23RISK
open ↗Referência✓ VexDay Proof
Microsoft Help Workshop 4.03.0002 - '.cnt' Local Buffer Overflow
Stack-based buffer overflow in Microsoft Help Workshop 4.03.0002 allows user-assisted remote attackers to execute arbitr
35RISK
open ↗Referência✓ VexDay Proof
Apple Mac OSX 10.4.8 - SLP Daemon Service Registration Buffer Overflow (PoC)
Buffer overflow in the Apple Minimal SLP v2 Service Agent (slpd) in Mac OS X 10.4.11 and earlier, including 10.4.8, allo
23RISK
open ↗Referência✓ VexDay Proof
phpBP RC3 (2.204) - SQL Injection / Remote Code Execution
SQL injection vulnerability in phpBP RC3 (2.204) and earlier allows remote attackers to execute arbitrary SQL commands v
23RISK
open ↗Referência✓ VexDay Proof
CascadianFAQ 4.1 - 'index.php' SQL Injection
SQL injection vulnerability in index.php in Eclectic Designs CascadianFAQ 4.1 and earlier allows remote attackers to exe
23RISK
open ↗Referência✓ VexDay Proof
Galeria Zdjec 3.0 - 'zd_numer.php' Local File Inclusion
Directory traversal vulnerability in zd_numer.php in Galeria Zdjec 3.0 and earlier allows remote attackers to include an
23RISK
open ↗Referência✓ VexDay Proof
GuppY 4.5.16 - Remote Command Execution
Multiple static code injection vulnerabilities in error.php in GuppY 4.5.16 and earlier allow remote attackers to inject
23RISK
open ↗Referência✓ VexDay Proof
Dev-C++ 4.9.9.2 - '.CPP' File Parsing Local Stack Overflow (PoC)
Stack-based buffer overflow in Bloodshed Dev-C++ 4.9.9.2 allows user-assisted remote attackers to cause a denial of serv
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.