Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,466Referência 23,051GitHub PoC 15,051VulnCheck XDB 8,883Nuclei 4,361Metasploit 3,493✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
SFS EZ BIZ PRO - SQL Injection
SQL injection vulnerability in track.php in Scripts For Sites (SFS) EZ BIZ PRO allows remote attackers to execute arbitr
23RISK
open ↗Referência✓ VexDay Proof
SFS EZ Webring - 'cat' SQL Injection
SQL injection vulnerability in category.php in Scripts For Sites (SFS) EZ Webring allows remote attackers to execute arb
23RISK
open ↗Referência✓ VexDay Proof
PHPMyRing 4.2.0 - 'view_com.php' SQL Injection
SQL injection vulnerability in view_com.php in Nicolas Grandjean PHPMyRing 4.2.0 and earlier allows remote attackers to
23RISK
open ↗Referência✓ VexDay Proof
Sciurus Hosting Panel - Remote Code Injection
Direct static code injection vulnerability in acp/savenews.php in Sciurus Hosting Panel, possibly 2.0.3, allows remote a
23RISK
open ↗Referência✓ VexDay Proof
Apple Safari / QuickTime 7.3 - RTSP Content-Type Remote Buffer Overflow
Stack-based buffer overflow in Apple QuickTime before 7.3.1, as used in QuickTime Player on Windows XP and Safari on Mac
50RISK
open ↗Referência✓ VexDay Proof
e107 Plugin BLOG Engine 2.1.4 - SQL Injection
SQL injection vulnerability in macgurublog_menu/macgurublog.php in the MacGuru BLOG Engine plugin 2.2 for e107 allows re
23RISK
open ↗Referência✓ VexDay Proof
e107 Plugin BLOG Engine 2.2 - 'uid' Blind SQL Injection
SQL injection vulnerability in macgurublog_menu/macgurublog.php in the MacGuru BLOG Engine plugin 2.2 for e107 allows re
23RISK
open ↗Referência✓ VexDay Proof
VWar 1.50 R14 - 'online.php' SQL Injection
SQL injection vulnerability in extra/online.php in Virtual War (VWar) 1.5.0 R14 and earlier allows remote attackers to e
23RISK
open ↗Referência✓ VexDay Proof
6rbScript 3.3 - 'section.php' Local File Inclusion
Directory traversal vulnerability in section.php in 6rbScript 3.3, when magic_quotes_gpc is disabled, allows remote atta
23RISK
open ↗Referência✓ VexDay Proof
6rbScript 3.3 - 'singerid' SQL Injection
SQL injection vulnerability in section.php in 6rbScript 3.3 allows remote attackers to execute arbitrary SQL commands vi
23RISK
open ↗Referência✓ VexDay Proof
e107 Plugin Image Gallery 0.9.6.2 - SQL Injection
SQL injection vulnerability in image_gallery.php in the Akira Powered Image Gallery (image_gallery) plugin 0.9.6.2 for e
23RISK
open ↗Referência✓ VexDay Proof
KB-Bestellsystem - 'kb_whois.cgi' Command Execution
kb_whois.cgi in K+B-Bestellsystem (aka KB-Bestellsystem) allows remote attackers to execute arbitrary commands via shell
23RISK
open ↗Referência✓ VexDay Proof
TuMusika Evolution 1.7R5 - Remote File Disclosure
Multiple directory traversal vulnerabilities in TuMusika Evolution 1.7R5 allow remote attackers to include and execute a
23RISK
open ↗Referência✓ VexDay Proof
Chaussette 080706 - '_BASE' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Chaussette 080706 and earlier allow remote attackers to execute ar
28RISK
open ↗Referência✓ VexDay Proof
phpPrintAnalyzer 1.2 - Remote File Inclusion
PHP remote file inclusion vulnerability in inc/header.inc.php in phpPrintAnalyzer 1.2 and earlier allows remote attacker
23RISK
open ↗Referência✓ VexDay Proof
Seditio CMS 121 - SQL Injection
SQL injection vulnerability in plugins/search/search.php in Neocrome Seditio CMS 121 and earlier allows remote attackers
23RISK
open ↗Referência✓ VexDay Proof
HP OpenView Network Node Manager 07.50 - CGI Remote Buffer Overflow
Multiple stack-based buffer overflows in HP OpenView Network Node Manager (OV NNM) 6.41, 7.01, and 7.51 allow remote att
50RISK
open ↗Referência✓ VexDay Proof
KML share 1.1 - 'region.php?layer' Remote File Disclosure
Directory traversal vulnerability in region.php in KML share 1.1 allows remote attackers to read arbitrary files via a .
23RISK
open ↗Referência✓ VexDay Proof
SFS EZ Hot or Not - 'phid' SQL Injection
SQL injection vulnerability in viewcomments.php in Scripts For Sites (SFS) EZ Hot or Not allows remote attackers to exec
23RISK
open ↗Referência✓ VexDay Proof
MyPHP Forum 3.0 - Edit Topics / Blind SQL Injection
Multiple SQL injection vulnerabilities in MyPHP Forum 3.0 and earlier allow remote attackers to execute arbitrary SQL co
23RISK
open ↗Referência✓ VexDay Proof
Absolute Banner Manager - Insecure Cookie Handling
Absolute Banner Manager .NET 4.0 allows remote attackers to bypass authentication and gain administrative access by sett
23RISK
open ↗Referência✓ VexDay Proof
Absolute Control Panel XE 1.5 - Insecure Cookie Handling
Xigla Software Absolute Control Panel XE 1.5 allows remote attackers to bypass authentication and gain administrative ac
23RISK
open ↗Referência✓ VexDay Proof
Absolute Live Support 5.1 - Insecure Cookie Handling
Xigla Software Absolute Live Support .NET 5.1 allows remote attackers to bypass authentication and gain administrative a
23RISK
open ↗Referência✓ VexDay Proof
merlix educate servert - Authentication Bypass / File Disclosure
Merlix Educate Server allows remote attackers to bypass intended security restrictions and obtain sensitive information
23RISK
open ↗Referência✓ VexDay Proof
merlix educate servert - Authentication Bypass / File Disclosure
Merlix Educate Server stores db.mdb under the web root with insufficient access control, which allows remote attackers t
23RISK
open ↗Referência✓ VexDay Proof
ProjectButler 0.8.4 - 'rootdir' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in WebDynamite ProjectButler 0.8.4 allow remote attackers to execute
23RISK
open ↗Referência✓ VexDay Proof
ExoPHPDesk 1.2 Final - Authentication Bypass
SQL injection vulnerability in admin.php in Exocrew ExoPHPDesk 1.2 Final allows remote attackers to execute arbitrary SQ
23RISK
open ↗Referência✓ VexDay Proof
ThePortal 2.2 - Arbitrary File Upload
Unrestricted file upload vulnerability in admin/galeria.php in ThePortal2 2.2 allows remote attackers to execute arbitra
23RISK
open ↗Referência✓ VexDay Proof
TaskDriver 1.3 - Remote Change Admin Password
profileedit.php TaskDriver 1.3 and earlier allows remote attackers to bypass authentication and gain administrative acce
23RISK
open ↗Referência✓ VexDay Proof
dotProject 2.0.4 - 'baseDir' Remote File Inclusion
PHP remote file inclusion vulnerability in classes/query.class.php in dotProject 2.0.4 and earlier allows remote attacke
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.