Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,466Referência 23,051GitHub PoC 15,051VulnCheck XDB 8,883Nuclei 4,361Metasploit 3,493✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
Free Download Manager 2.5/3.0 - Authorisation Stack Buffer Overflow (PoC)
Stack-based buffer overflow in Remote Control Server in Free Download Manager (FDM) 2.5 Build 758 and 3.0 Build 844 allo
50RISK
open ↗Referência✓ VexDay Proof
RSSonate - 'xml2rss.php' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Christopher Fowler (Rhode Island) RSSonate allow remote attackers
23RISK
open ↗Referência✓ VexDay Proof
EntertainmentScript 1.4.0 - 'play.php' SQL Injection
SQL injection vulnerability in play.php in EntertainmentScript 1.4.0 allows remote attackers to execute arbitrary SQL co
23RISK
open ↗Referência✓ VexDay Proof
Multi-Threaded TFTP 1.1 - GET Denial of Service
Heap-based buffer overflow in FutureSoft TFTP Server Multithreaded (MT) 1.1 allows remote attackers to cause a denial of
23RISK
open ↗Referência✓ VexDay Proof
The Walking Club - Authentication Bypass
SQL injection vulnerability in login.aspx in WarHound Walking Club allows remote attackers to execute arbitrary SQL comm
23RISK
open ↗Referência✓ VexDay Proof
TotalCalendar 2.30 - 'inc' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in TotalCalendar 2.30 and earlier allows remote attackers to execut
23RISK
open ↗Referência✓ VexDay Proof
HP Digital Imaging 'hpqvwocx.dll 2.1.0.556' - 'SaveToFile()' File Write
Absolute path traversal vulnerability in a certain ActiveX control in hpqvwocx.dll 2.1.0.556 in Hewlett-Packard (HP) Dig
23RISK
open ↗Referência✓ VexDay Proof
verlihub 0.9.8d-RC2 - Remote Command Execution
The cTrigger::DoIt function in src/ctrigger.cpp in the trigger mechanism in the daemon in Verlihub 0.9.8d-RC2 and earlie
23RISK
open ↗Referência✓ VexDay Proof
JBC Explorer 7.20 RC 1 - Remote Code Execution
Direct static code injection vulnerability in dirsys/modules/config/post.php in JBC Explorer 7.20 RC1 and earlier allows
23RISK
open ↗Referência✓ VexDay Proof
ESPG (Enhanced Simple PHP Gallery) 1.72 - File Disclosure
Directory traversal vulnerability in gallery/comment.php in Enhanced Simple PHP Gallery (ESPG) 1.72 allows remote attack
23RISK
open ↗Referência✓ VexDay Proof
blogit! - SQL Injection / File Disclosure / Cross-Site Scripting
SQL injection vulnerability in index.asp in Katy Whitton BlogIt! allows remote attackers to execute arbitrary SQL comman
23RISK
open ↗Referência✓ VexDay Proof
Quate CMS 0.3.4 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Quate CMS 0.3.4 allow remote attackers to inject arbitrary web sc
23RISK
open ↗Referência✓ VexDay Proof
CoreHTTP 0.5.3alpha - HTTPd Remote Buffer Overflow
Multiple buffer overflows in the HttpSprockMake function in http.c in Frank Yaul corehttp 0.5.3alpha allow remote attack
23RISK
open ↗Referência✓ VexDay Proof
Simple Machines Forum (SMF) 1.1.6 - Local File Inclusion / Code Execution
Directory traversal vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 all
23RISK
open ↗Referência✓ VexDay Proof
ZeusCMS 0.3 - Blind SQL Injection
Absolute path traversal vulnerability in ZeusCMS 0.3 and earlier might allow remote attackers to list arbitrary director
23RISK
open ↗Referência✓ VexDay Proof
blogit! - SQL Injection / File Disclosure / Cross-Site Scripting
Katy Whitton BlogIt! stores sensitive information under the web root with insufficient access control, which allows remo
23RISK
open ↗Referência✓ VexDay Proof
blogit! - SQL Injection / File Disclosure / Cross-Site Scripting
SQL injection vulnerability in index.asp in Katy Whitton BlogIt! allows remote attackers to execute arbitrary SQL comman
23RISK
open ↗Referência✓ VexDay Proof
S-Gastebuch 1.5.3 - 'gb_pfad' Remote File Inclusion
PHP remote file inclusion vulnerability in functions_inc.php in VS-Gastebuch 1.5.3 and earlier allows remote attackers t
23RISK
open ↗Referência✓ VexDay Proof
Miniweb 0.8.19 - Multiple Vulnerabilities
Heap-based buffer overflow in the _mwProcessReadSocket function in http.c in MiniWeb HTTP Server 0.8.19 allows remote at
23RISK
open ↗Referência✓ VexDay Proof
Community CMS 0.4 - 'id' Blind SQL Injection
SQL injection vulnerability in index.php in Community CMS 0.4 and earlier allows remote attackers to execute arbitrary S
23RISK
open ↗Referência✓ VexDay Proof
CodeBB 1.0 Beta 2 - 'phpbb_root_path' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in CodeBB 1.1b3 and earlier allow remote attackers to execute arbitra
23RISK
open ↗Referência✓ VexDay Proof
Max.Blog 1.0.6 - 'offline_auth.php' Offline Authentication Bypass
SQL injection vulnerability in offline_auth.php in Max.Blog 1.0.6 and earlier, when magic_quotes_gpc is disabled, allows
23RISK
open ↗Referência✓ VexDay Proof
YourFreeScreamer 1.0 - 'serverPath' Remote File Inclusion
PHP remote file inclusion vulnerability in templates/2blue/bodyTemplate.php in YourFreeScreamer 1.0 allows remote attack
23RISK
open ↗Referência✓ VexDay Proof
BoastMachine 3.1 - 'mail.php' id SQL Injection
SQL injection vulnerability in mail.php in boastMachine (aka bMachine) 3.1 and earlier allows remote attackers to execut
23RISK
open ↗Referência✓ VexDay Proof
Linksys WRT54G Firmware 1.00.9 - Security Bypass (1)
The web interface on the Linksys WRT54g router with firmware 1.00.9 does not require credentials when invoking scripts,
23RISK
open ↗Referência✓ VexDay Proof
runawaysoft haber portal 1.0 - 'tr' Multiple Vulnerabilities
RunawaySoft Haber portal 1.0 stores sensitive information under the web root with insufficient access control, which all
23RISK
open ↗Referência✓ VexDay Proof
ASP PORTAL - Remote Database Disclosure
ASPPortal stores sensitive information under the web root with insufficient access control, which allows remote attacker
23RISK
open ↗Referência✓ VexDay Proof
Total Video Player 1.31 - 'DefaultSkin.ini' Local Stack Overflow
Stack-based buffer overflow in EffectMatrix Total Video Player 1.31 allows user-assisted attackers to execute arbitrary
43RISK
open ↗Referência✓ VexDay Proof
PHPbbBook 1.3 - 'bbcode.php?l' Local File Inclusion
Directory traversal vulnerability in bbcode.php in PHPbbBook 1.3 and 1.3h allows remote attackers to include and execute
23RISK
open ↗Referência✓ VexDay Proof
DreamPics Photo/Video Gallery - Blind SQL Injection
SQL injection vulnerability in index.php in Dreampics Gallery Builder allows remote attackers to execute arbitrary SQL c
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.