Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,466Referência 23,051GitHub PoC 15,051VulnCheck XDB 8,883Nuclei 4,361Metasploit 3,493✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
Thyme Calendar 1.3 - SQL Injection
SQL injection vulnerability in event_view.php in Thyme Calendar 1.3 allows remote attackers to execute arbitrary SQL com
23RISK
open ↗Referência✓ VexDay Proof
jaxultrabb 2.0 - Local File Inclusion / Cross-Site Scripting
Directory traversal vulnerability in viewprofile.php in JaxUltraBB 2.0 and earlier allows remote attackers to read arbit
23RISK
open ↗Referência✓ VexDay Proof
Data Dynamics ActiveReport - ActiveX 'actrpt2.dll 2.5' Insecure Method
Absolute path traversal vulnerability in the Data Dynamics ActiveReport (ActiveReports) ActiveX control in actrpt2.dll 2
23RISK
open ↗Referência✓ VexDay Proof
PHPWebGallery 1.3.4 - Cross-Site Scripting / Local File Inclusion
Multiple directory traversal vulnerabilities in PhpWebGallery 1.3.4 allow remote attackers to include and execute arbitr
23RISK
open ↗Referência✓ VexDay Proof
doop CMS 1.3.7 - Local File Inclusion
Directory traversal vulnerability in doop CMS 1.3.7 and earlier allows remote attackers to include and execute arbitrary
23RISK
open ↗Referência✓ VexDay Proof
Connectix Boards 0.8.2 - 'template_path' Remote File Inclusion
PHP remote file inclusion vulnerability in templates/Official/part_userprofile.php in Connectix Boards 0.8.2 and earlier
23RISK
open ↗Referência✓ VexDay Proof
PHPMyCart 1.3 - 'cat' SQL Injection
SQL injection vulnerability in shop.php in Conkurent PHPMyCart allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗Referência✓ VexDay Proof
phpBookingCalendar 1.0c - 'details_view.php' SQL Injection
SQL injection vulnerability in details_view.php in PHP Booking Calendar 1.0c and earlier allows remote attackers to exec
23RISK
open ↗Referência✓ VexDay Proof
PHP Coupon Script 3.0 - 'bus' SQL Injection
SQL injection vulnerability in index.php in PHP Coupon Script 3.0 allows remote attackers to execute arbitrary SQL comma
23RISK
open ↗Referência✓ VexDay Proof
Micro CMS 0.3.5 - Remote Add/Delete/Password Change
microcms-admin-home.php in Implied by Design Micro CMS (Micro-CMS) 3.5 (aka 0.3.5) does not require authentication as an
23RISK
open ↗Referência✓ VexDay Proof
xml2owl 0.1.1 - 'showcode.php' Remote Command Execution
showCode.php in xml2owl 0.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the path
23RISK
open ↗Referência✓ VexDay Proof
PEEL CMS 3.x - Admin Hash Extraction / Arbitrary File Upload
PEEL, possibly 3.x and earlier, allows remote attackers to obtain configuration information via a direct request to phpi
23RISK
open ↗Referência✓ VexDay Proof
vhostadmin 0.1 - 'MODULES_DIR' Remote File Inclusion
PHP remote file inclusion vulnerability in modules/mail/main.php in Inter7 vHostAdmin 1.0 allows remote attackers to exe
23RISK
open ↗Referência✓ VexDay Proof
jGallery 1.3 - 'index.php' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in jGallery 1.3 allows remote attackers to execute arbitrary PHP co
23RISK
open ↗Referência✓ VexDay Proof
Zomplog 3.8.2 - 'newuser.php' Arbitrary Add Admin
Zomplog 3.8.2 and earlier allows remote attackers to gain administrative access by creating an admin account via a direc
23RISK
open ↗Referência✓ VexDay Proof
Squirrelcart 1.x - 'cart.php' Remote File Inclusion
PHP remote file inclusion vulnerability in popup_window.php in Squirrelcart 1.x.x and earlier allows remote attackers to
23RISK
open ↗Referência✓ VexDay Proof
PacPoll 4.0 - Database Disclosure
PacPoll 4.0 stores sensitive information under the web root with insufficient access control, which allows remote attack
23RISK
open ↗Referência✓ VexDay Proof
webid 0.5.4 - Multiple Vulnerabilities
WeBid auction script 0.5.4 stores sensitive information under the web root with insufficient access control, which allow
23RISK
open ↗Referência✓ VexDay Proof
PHP Photo Gallery 1.0 - 'photo_id' SQL Injection
Terong PHP Photo Gallery (aka Advanced Web Photo Gallery) 1.0 stores passwords in cleartext in a MySQL database, which a
23RISK
open ↗Referência✓ VexDay Proof
WebAlbum 2.02pl - COOKIE[skin2] Remote Code Execution
Directory traversal vulnerability in start.php in WebAlbum 2.02 allows remote attackers to include arbitrary files and e
23RISK
open ↗Referência✓ VexDay Proof
Cartweaver 3 - 'prodId' Blind SQL Injection
SQL injection vulnerability in details.php in Application Dynamics Cartweaver 3.0 allows remote attackers to execute arb
23RISK
open ↗Referência✓ VexDay Proof
iWare Pro 5.0.4 - 'chat_panel.php' Remote Code Execution
Static code injection vulnerability in chat_panel.php in the SimpleChat 1.0.0 module for iWare Professional CMS allows r
23RISK
open ↗Referência✓ VexDay Proof
TorrentFlux 2.2 - 'downloaddetails.php' Local File Disclosure
Directory traversal vulnerability in viewnfo.php in (1) TorrentFlux before 2.2 and (2) torrentflux-b4rt before 2.1-b4rt-
23RISK
open ↗Referência✓ VexDay Proof
NewsCMSLite - 'newsCMS.mdb' Remote Password Disclosure
newsCMSlite stores sensitive information under the web root with insufficient access control, which allows remote attack
23RISK
open ↗Referência✓ VexDay Proof
Pakupaku CMS 0.4 - Arbitrary File Upload / Local File Inclusion
Unrestricted file upload vulnerability in index.php in Pakupaku CMS 0.4 and earlier allows remote attackers to upload an
23RISK
open ↗Referência✓ VexDay Proof
Exero CMS 1.0.1 - 'theme' Multiple Local File Inclusions
Multiple directory traversal vulnerabilities in the Default theme in Exero CMS 1.0.1 allow remote attackers to include a
23RISK
open ↗Referência✓ VexDay Proof
Boite de News 4.0.1 - 'index.php' Remote File Inclusion
PHP remote file inclusion vulnerability in boitenews4/index.php in Boite de News 4.0.1 allows remote attackers to execut
23RISK
open ↗Referência✓ VexDay Proof
phpAtm 1.21 - 'include_location' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in PHP Advanced Transfer Manager (phpAtm) 1.21 and earlier allow remo
23RISK
open ↗Referência✓ VexDay Proof
OtomiGen.x 2.2 - 'lang' Local File Inclusion
Multiple directory traversal vulnerabilities in OtomiGenX 2.2 allow remote attackers to include and execute arbitrary lo
23RISK
open ↗Referência✓ VexDay Proof
e107 < 0.75 - 'e107language_e107cookie' Local File Inclusion
Directory traversal vulnerability in class2.php in e107 0.7.5 and earlier allows remote attackers to read and execute PH
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.