Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,466Referência 23,051GitHub PoC 15,051VulnCheck XDB 8,883Nuclei 4,361Metasploit 3,493✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
Joomla! Component Highwood Design hwdVideoShare - SQL Injection
SQL injection vulnerability in the Highwood Design hwdVideoShare (com_hwdvideoshare) 1.1.3 Alpha component for Joomla!
23RISK
open ↗Referência✓ VexDay Proof
OSSIM 0.9.9rc5 - Cross-Site Scripting / SQL Injection
SQL injection vulnerability in port/modifyportform.php in Open Source Security Information Management (OSSIM) 0.9.9 rc5
23RISK
open ↗Referência✓ VexDay Proof
BeContent 031 - 'id' SQL Injection
SQL injection vulnerability in news.php in beContent 0.3.1 allows remote attackers to execute arbitrary SQL commands via
23RISK
open ↗Referência✓ VexDay Proof
Microsoft Windows Server 2000 - UPNP 'getdevicelist' Memory Leak Denial of Service
PNP_GetDeviceList (upnp_getdevicelist) in UPnP for Microsoft Windows 2000 SP4 and earlier, and possibly Windows XP SP1 a
35RISK
open ↗Referência✓ VexDay Proof
phpQLAdmin 2.2.7 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in phpQLAdmin 2.2.7 allow remote attackers to execute arbitrary PHP c
28RISK
open ↗Referência✓ VexDay Proof
GROUP-E 1.6.41 - 'head_auth.php' Remote File Inclusion
PHP remote file inclusion vulnerability in lib/head_auth.php in GROUP-E 1.6.41 allows remote attackers to execute arbitr
35RISK
open ↗Referência✓ VexDay Proof
Microsoft Windows - GDI (CreateDIBPatternBrushPt) Heap Overflow (PoC)
Heap-based buffer overflow in the CreateDIBPatternBrushPt function in GDI in Microsoft Windows 2000 SP4, XP SP2, Server
53RISK
open ↗Referência✓ VexDay Proof
Centreon 1.4.2.3 - 'get_image.php' Remote File Disclosure
Directory traversal vulnerability in include/doc/get_image.php in Centreon 1.4.2.3 and earlier allows remote attackers t
23RISK
open ↗Referência✓ VexDay Proof
eazyPortal 1.0 - 'cookie' SQL Injection
SQL injection vulnerability in index.php in eazyPortal 1.0 and earlier allows remote attackers to execute arbitrary SQL
23RISK
open ↗Referência✓ VexDay Proof
Dream4 Koobi Pro 5.7 - 'categ' SQL Injection
SQL injection vulnerability in the downloads module in Koobi Pro 5.7 allows remote attackers to execute arbitrary SQL co
23RISK
open ↗Referência✓ VexDay Proof
Podcast Generator 1.0 Beta 2 - Remote File Inclusion / File Disclosure
Multiple PHP remote file inclusion vulnerabilities in Podcast Generator 1.0 BETA 2 and earlier allow remote attackers to
28RISK
open ↗Referência✓ VexDay Proof
Podcast Generator 1.0 Beta 2 - Remote File Inclusion / File Disclosure
Multiple directory traversal vulnerabilities in Podcast Generator 1.0 BETA 2 and earlier allow remote attackers to read
23RISK
open ↗Referência✓ VexDay Proof
Cisco IP Phone 7940 - Reboot (Denial of Service)
The Cisco IP Phone 7940 allows remote attackers to cause a denial of service (reboot) via a large amount of TCP SYN pack
28RISK
open ↗Referência✓ VexDay Proof
Winamp 5.12 - '.pls' Remote Buffer Overflow (Perl) (2)
Buffer overflow in Nullsoft Winamp 5.12 allows remote attackers to execute arbitrary code via a playlist (pls) file with
60RISK
open ↗Referência✓ VexDay Proof
jspwiki 2.4.104/2.5.139 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in Edit.jsp in JSPWiki 2.4.104 and 2.5.139 allows remote attackers to inject ar
23RISK
open ↗Referência✓ VexDay Proof
BM Classifieds 20080409 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in BM Classifieds 20080309 and earlier allow remote attackers to execute arbitrar
23RISK
open ↗Referência✓ VexDay Proof
phpMyNewsletter 0.8b5 - 'msg_id' SQL Injection
SQL injection vulnerability in archives.php in Gregory Kokanosky (aka Greg's Place) phpMyNewsletter 0.8 beta 5 and earli
23RISK
open ↗Referência✓ VexDay Proof
eXchange POP3 5.0.050203 - RPCT TO Remote Buffer Overflow
Buffer overflow in the POP3 server in Kinesphere Corporation eXchange before 5.0.060125 allows remote attackers to execu
35RISK
open ↗Referência✓ VexDay Proof
phpBB Mod FileBase 2.0 - 'id' SQL Injection
SQL injection vulnerability in filebase.php in the Filebase mod for phpBB allows remote attackers to execute arbitrary S
23RISK
open ↗Referência✓ VexDay Proof
EasyCalendar 4.0tr - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in plugins/calendar/calendar_backend.php in MyioSoft EasyCalendar 4.0tr and ear
23RISK
open ↗Referência✓ VexDay Proof
Admbook 1.2.2 - 'x-forwarded-for' Remote Command Execution
Direct static code injection vulnerability in write.php in Admbook 1.2.2 and earlier allows remote attackers to execute
23RISK
open ↗Referência✓ VexDay Proof
vuBB 0.2 Final - 'cookie' SQL Injection
SQL injection vulnerability in vuBB 0.2 allows remote attackers to execute arbitrary SQL commands via the pass parameter
23RISK
open ↗Referência✓ VexDay Proof
Lansuite 2.1.0 Beta - 'fid' SQL Injection
SQL injection vulnerability in the board module in LanSuite LanParty Intranet System 2.0.6 and 2.1.0 beta allows remote
23RISK
open ↗Referência✓ VexDay Proof
Aztek Forum 4.00 - Cross-Site Scripting / SQL Injection
Cross-site scripting (XSS) vulnerability in Aztek Forum 4.0 allows remote attackers to inject arbitrary web script or HT
23RISK
open ↗Referência✓ VexDay Proof
Aztek Forum 4.00 - Cross-Site Scripting / SQL Injection
Aztek Forum 4.0 allows remote attackers to obtain sensitive information via a "*/*" in the msg parameter to index.php, w
23RISK
open ↗Referência✓ VexDay Proof
Aztek Forum 4.00 - Cross-Site Scripting / SQL Injection
Aztek Forum 4.0 allows remote attackers to obtain sensitive information via a long login value in a register form, which
23RISK
open ↗Referência✓ VexDay Proof
crossfire-server 1.9.0 - 'SetUp()' Remote Buffer Overflow
Buffer overflow in the SetUp function in socket/request.c in CrossFire 1.9.0 allows remote attackers to execute arbitrar
28RISK
open ↗Referência✓ VexDay Proof
gCards 1.45 - Multiple Vulnerabilities
Directory traversal vulnerability in inc/setLang.php in Greg Neustaetter gCards 1.45 and earlier allows remote attackers
23RISK
open ↗Referência✓ VexDay Proof
gCards 1.45 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in index.php in Greg Neustaetter gCards 1.45 and earlier allows remote attacker
23RISK
open ↗Referência✓ VexDay Proof
XHP CMS 0.5 - 'upload' Remote Command Execution
Laurentiu Matei eXpandable Home Page (XHP) CMS 0.5 and earlier allows remote authenticated users to use the HTMLArea Fil
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.