Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,466Referência 23,051GitHub PoC 15,051VulnCheck XDB 8,883Nuclei 4,361Metasploit 3,493✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
OwnRS Blog 1.2 - 'autor.php' SQL Injection
SQL injection vulnerability in autor.php in OwnRS CMS 1.2 allows remote attackers to execute arbitrary SQL commands via
23RISK
open ↗Referência✓ VexDay Proof
AMX Corp. VNC ActiveX Control - 'AmxVnc.dll 1.0.13.0' Remote Buffer Overflow
Multiple buffer overflows in the AMX NetLinx VNC (AmxVnc) ActiveX control in AmxVnc.dll 1.0.13.0 allow remote attackers
28RISK
open ↗Referência✓ VexDay Proof
PHPress 0.2.0 - 'adisplay.php?lang' Local File Inclusion
PHP remote file inclusion vulnerability in adisplay.php in PhPress 0.2.0 allows remote attackers to execute arbitrary PH
23RISK
open ↗Referência✓ VexDay Proof
Community CMS 0.4 - 'id' Blind SQL Injection
SQL injection vulnerability in index.php in Community CMS 0.4 and earlier allows remote attackers to execute arbitrary S
23RISK
open ↗Referência✓ VexDay Proof
CodeBB 1.0 Beta 2 - 'phpbb_root_path' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in CodeBB 1.1b3 and earlier allow remote attackers to execute arbitra
23RISK
open ↗Referência✓ VexDay Proof
Max.Blog 1.0.6 - 'offline_auth.php' Offline Authentication Bypass
SQL injection vulnerability in offline_auth.php in Max.Blog 1.0.6 and earlier, when magic_quotes_gpc is disabled, allows
23RISK
open ↗Referência✓ VexDay Proof
YourFreeScreamer 1.0 - 'serverPath' Remote File Inclusion
PHP remote file inclusion vulnerability in templates/2blue/bodyTemplate.php in YourFreeScreamer 1.0 allows remote attack
23RISK
open ↗Referência✓ VexDay Proof
BoastMachine 3.1 - 'mail.php' id SQL Injection
SQL injection vulnerability in mail.php in boastMachine (aka bMachine) 3.1 and earlier allows remote attackers to execut
23RISK
open ↗Referência✓ VexDay Proof
DMXReady Classified Listings Manager 1.1 - SQL Injection
SQL injection vulnerability in CategoryManager/upload_image_category.asp in DMXReady Classified Listings Manager 1.1 and
23RISK
open ↗Referência✓ VexDay Proof
VRNews 1.1.1 - 'admin.php' Remote Security Bypass
admin.php in VRNews 1.1.1, and possibly other 1.x versions, does not require authentication, which allows remote attacke
23RISK
open ↗Referência✓ VexDay Proof
DMXReady Member Directory Manager 1.1 - SQL Injection
SQL injection vulnerability in CategoryManager/upload_image_category.asp in DMXReady Member Directory Manager 1.1 and ea
23RISK
open ↗Referência✓ VexDay Proof
CMS-BRD - 'menuclick' SQL Injection
SQL injection vulnerability in index.php in CMS-BRD allows remote attackers to execute arbitrary SQL commands via the me
23RISK
open ↗Referência✓ VexDay Proof
MyDesing Sayac 2.0 - Authentication Bypass
Multiple SQL injection vulnerabilities in default.asp in MyDesign Sayac 2.0 allow remote attackers to execute arbitrary
23RISK
open ↗Referência✓ VexDay Proof
WebMatic 2.6 - 'index_album.php' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in index/index_album.php in Valarsoft WebMatic 2.6 allow remote attac
23RISK
open ↗Referência✓ VexDay Proof
shibby shop 2.2 - Multiple Vulnerabilities
upgrade.asp in sHibby sHop 2.2 and earlier does not require administrative authentication, which allows remote attackers
23RISK
open ↗Referência✓ VexDay Proof
PUMA 1.0 RC 2 - 'config.php' Remote File Inclusion
PHP remote file inclusion vulnerability in config.php in PSYWERKS PUMA 1.0 RC2 allows remote attackers to execute arbitr
23RISK
open ↗Referência✓ VexDay Proof
emuCMS 0.3 - 'cat_id' SQL Injection
SQL injection vulnerability in index.php in eMuSOFT emuCMS 0.3 allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗Referência✓ VexDay Proof
Microsoft Windows Vista - Access Violation from Limited Account (Blue Screen of Death)
Microsoft Windows Vista Home and Ultimate Edition SP1 and earlier allows local users to cause a denial of service (page
23RISK
open ↗Referência✓ VexDay Proof
Segue CMS 1.5.8 - 'themesdir' Remote File Inclusion
PHP remote file inclusion vulnerability in themes/program/themesettings.inc.php in Segue CMS 1.5.8 and earlier, when reg
23RISK
open ↗Referência✓ VexDay Proof
Zeeways PHOTOVIDEOTUBE 1.1 - Authentication Bypass
Zeeways PhotoVideoTube 1.1 and earlier allows remote attackers to bypass authentication and perform administrative tasks
23RISK
open ↗Referência✓ VexDay Proof
BlazeVideo HDTV Player 3.5 - '.PLF' Playlist File Local Overflow
Stack-based buffer overflow in BlazeVideo HDTV Player 3.5 and earlier allows remote attackers to execute arbitrary code
28RISK
open ↗Referência✓ VexDay Proof
SkaLinks 1.5 - Authentication Bypass
SQL injection vulnerability in Skalfa SkaLinks 1.5 allows remote attackers to execute arbitrary SQL commands via the Adm
23RISK
open ↗Referência✓ VexDay Proof
Online Grades 3.2.4 - Authentication Bypass
Multiple SQL injection vulnerabilities in parents/login.php in Online Grades 3.2.4, when magic_quotes_gpc is disabled, a
23RISK
open ↗Referência✓ VexDay Proof
a-ConMan 3.2b - 'common.inc.php' Remote File Inclusion
PHP remote file inclusion vulnerability in common.inc.php in a-ConMan 3.2 beta allows remote attackers to execute arbitr
23RISK
open ↗Referência✓ VexDay Proof
Macromedia Flash 8 (Flash8b.ocx) Internet Explorer 7 - Denial of Service
Flash8b.ocx in Macromedia Flash 8 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a
23RISK
open ↗Referência✓ VexDay Proof
PayProCart 1146078425 - Multiple Remote File Inclusions
PHP remote file inclusion vulnerability in profitCode ppalCart 2.5 EE, possibly a component of PayProCart, allows remote
23RISK
open ↗Referência✓ VexDay Proof
E-Smart Cart - 'productsofcat.asp' SQL Injection
SQL injection vulnerability in productsofcat.asp in E-SMART CART allows remote attackers to execute arbitrary SQL comman
23RISK
open ↗Referência✓ VexDay Proof
QK SMTP 3.01 - 'RCPT TO' Remote Denial of Service
Stack-based buffer overflow in QK SMTP 3.01 and earlier might allow remote attackers to execute arbitrary code via a lon
23RISK
open ↗Referência✓ VexDay Proof
phpBLASTER CMS 1.0 RC1 - Multiple Local File Inclusions
Multiple directory traversal vulnerabilities in admin/minibb/index.php in phpBLASTER CMS 1.0 RC1, when register_globals
23RISK
open ↗Referência✓ VexDay Proof
Ultimate PHP Board 2.0 - 'header_simple.php' File Inclusion
PHP remote file inclusion vulnerability in includes/header_simple.php in Ultimate PHP Board (UPB) 2.0 and earlier allows
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.