Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,466Referência 23,051GitHub PoC 15,051VulnCheck XDB 8,883Nuclei 4,361Metasploit 3,493✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
asp-project 1.0 - Insecure Cookie Method
Asp Project Management 1.0 allows remote attackers to bypass authentication and gain administrative access by setting th
23RISK
open ↗Referência✓ VexDay Proof
PAD Site Scripts 3.6 - Insecure Cookie Handling
PAD Site Scripts 3.6 allows remote attackers to bypass authentication and gain privileges as other users, including admi
23RISK
open ↗Referência✓ VexDay Proof
WinFTP Server 2.0.2 - 'PASV' Remote Denial of Service
WinFtp Server 2.0.2 allows remote attackers to cause a denial of service (crash) via long (1) PASV, (2) LIST, (3) USER,
23RISK
open ↗Referência✓ VexDay Proof
Admidio 1.4.8 - 'getfile.php' Remote File Disclosure
Directory traversal vulnerability in modules/download/get_file.php in Admidio 1.4.8 allows remote attackers to read arbi
23RISK
open ↗Referência✓ VexDay Proof
TLM CMS 1.1 - 'i-accueil.php?chemin' Remote File Inclusion
PHP remote file inclusion vulnerability in i-accueil.php in TLM CMS 1.1 and earlier allows remote attackers to execute a
23RISK
open ↗Referência✓ VexDay Proof
ibase 2.03 - Remote File Disclosure
Directory traversal vulnerability in download.php in Interface Medien ibase 2.03 and earlier allows remote attackers to
23RISK
open ↗Referência✓ VexDay Proof
JChit counter 1.0.0 - 'imgsrv.php?ac' Remote File Disclosure
Directory traversal vulnerability in imgsrv.php in jchit counter 1.0.0 allows remote attackers to read arbitrary files v
23RISK
open ↗Referência✓ VexDay Proof
Quick 'n Easy Mail Server 3.3 (Demo) - Remote Denial of Service (PoC)
Pablo Software Solutions Quick 'n Easy Mail Server 3.3 allows remote attackers to cause a denial of service (daemon outa
23RISK
open ↗Referência✓ VexDay Proof
MiniWeb HTTP Server 0.8.x - Remote Denial of Service
http.c in MiniWeb Http Server 0.8.x allows remote attackers to cause a denial of service (application crash) via a negat
23RISK
open ↗Referência✓ VexDay Proof
vidshare pro - SQL Injection / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in search.php in VidSharePro allows remote attackers to inject arbitrary web sc
23RISK
open ↗Referência✓ VexDay Proof
Picturesolution 2.1 - 'config.php?path' Remote File Inclusion
PHP remote file inclusion vulnerability in install/config.php in Picturesolution 2.1 and earlier allows remote attackers
23RISK
open ↗Referência✓ VexDay Proof
kontakt formular 1.4 - Remote File Inclusion
PHP remote file inclusion vulnerability in includes/function.php in Kontakt Formular 1.4 allows remote attackers to exec
23RISK
open ↗Referência✓ VexDay Proof
Noticeware E-mail Server 5.1.2.2 - 'POP3' Denial of Service
NoticeWare Email Server NG 5.1.2.2 allows remote attackers to cause a denial of service (crash) via multiple POP3 reques
23RISK
open ↗Referência✓ VexDay Proof
BolinOS 4.6.1 - Local File Inclusion / Cross-Site Scripting
BolinOS 4.6.1 allows remote attackers to obtain sensitive information via a direct request to system/actionspages/_b/con
23RISK
open ↗Referência✓ VexDay Proof
phpWebSite 0.10.0-full - 'topics.php' SQL Injection
SQL injection vulnerability in topics.php in Appalachian State University phpWebSite 0.10.2 and earlier allows remote at
23RISK
open ↗Referência✓ VexDay Proof
OPT Max 1.2.0 - 'CRM_inc' Remote File Inclusion
PHP remote file inclusion vulnerability in include/urights.php in Outreach Project Tool (OPT) Max 1.2.6 and earlier allo
23RISK
open ↗Referência✓ VexDay Proof
phpFullAnnu 5.1 - 'repmod' Remote File Inclusion
PHP remote file inclusion vulnerability in modules/home.module.php in phpFullAnnu 5.1 and earlier allows remote attacker
23RISK
open ↗Referência✓ VexDay Proof
TorrentTrader Classic 1.09 - Multiple Vulnerabilities
backup-database.php in TorrentTrader Classic 1.09 does not require administrative authentication, which allows remote at
23RISK
open ↗Referência✓ VexDay Proof
Star FTP Server 1.10 - 'RETR' Remote Denial of Service
Fightersoft Multimedia Star FTP server 1.10 allows remote attackers to cause a denial of service (crash) via multiple RE
23RISK
open ↗Referência✓ VexDay Proof
photokron 1.7 - Remote Database Disclosure
PhotoKorn allows remote attackers to obtain database credentials via a direct request to update/update3.php, which inclu
23RISK
open ↗Referência✓ VexDay Proof
WoW Roster 1.5.1 - 'subdir' Remote File Inclusion
PHP remote file inclusion vulnerability in conf.php in WoWRoster (aka World of Warcraft Roster) 1.5.1 and earlier allows
23RISK
open ↗Referência✓ VexDay Proof
LinPHA 1.3.3 Plugin Maps - Remote Command Execution
plugins/maps/db_handler.php in LinPHA 1.3.3 and earlier does not require authentication for a settings action that modif
23RISK
open ↗Referência✓ VexDay Proof
HLStats 1.34 - 'hlstats.php' SQL Injection
HLstats 1.20 through 1.34 allows remote attackers to obtain sensitive information via playinfo mode, with certain values
23RISK
open ↗Referência✓ VexDay Proof
Pet Grooming Management System 2.0 - Arbitrary Add Admin
Pet Grooming Management System 2.0 allows remote attackers to gain privileges via a direct request to useradded.php with
23RISK
open ↗Referência✓ VexDay Proof
Poplar Gedcom Viewer 2.0 - 'common.php' Remote File Inclusion
PHP remote file inclusion vulnerability in include/common.php in Poplar Gedcom Viewer 2.0 and earlier allows remote atta
23RISK
open ↗Referência✓ VexDay Proof
Pooya Site Builder (PSB) 6.0 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in Pooya Site Builder (PSB) 6.0 allow remote attackers to execute arbitrary SQL c
23RISK
open ↗Referência✓ VexDay Proof
Pharmacy System 2.0 - 'index.php?ID' SQL Injection
index.php in Pharmacy System 2 and earlier allows remote attackers to obtain sensitive information via a ' (quote) chara
23RISK
open ↗Referência✓ VexDay Proof
eFiction 3.0 - 'toplists.php' SQL Injection
SQL injection vulnerability in toplists.php in eFiction 3.0 and 3.4.3, when magic_quotes_gpc is disabled, allows remote
23RISK
open ↗Referência✓ VexDay Proof
LokiCMS 0.3.3 - Arbitrary File Delete
Directory traversal vulnerability in admin.php in LokiCMS 0.3.3 and earlier allows remote attackers to delete arbitrary
23RISK
open ↗Referência✓ VexDay Proof
celerbb 0.0.2 - Multiple Vulnerabilities
showme.php in CelerBB 0.0.2 allows remote attackers to obtain "reserved information" via the user parameter.
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.