Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,466Referência 23,051GitHub PoC 15,051VulnCheck XDB 8,883Nuclei 4,361Metasploit 3,493✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
MiniHTTPServer Web Forum & File Sharing Server 4.0 - Add User
join.asp in MiniHTTP Web Forum & File Server PowerPack 4.0 allows remote attackers to add or modify arbitrary user accou
23RISK
open ↗Referência✓ VexDay Proof
SH-News 3.0 - Insecure Cookie Handling
action.php in SH-News 3.0 allows remote attackers to bypass authentication and gain administrator privileges by setting
23RISK
open ↗Referência✓ VexDay Proof
ScarNews 1.2.1 - 'sn_admin_dir' Local File Inclusion
Directory traversal vulnerability in scarnews.inc.php in ScarNews 1.2.1 allows remote attackers to include and execute a
23RISK
open ↗Referência✓ VexDay Proof
My Little Forum 1.7 - 'user.php?id' SQL Injection
SQL injection vulnerability in user.php in My Little Forum 1.7 and earlier allows remote attackers to execute arbitrary
23RISK
open ↗Referência✓ VexDay Proof
Absolute Form Processor 4.0 - Insecure Cookie Handling
Xigla Software Absolute Form Processor .NET 4.0 allows remote attackers to bypass authentication and gain administrative
23RISK
open ↗Referência✓ VexDay Proof
DreamLog 0.5 - 'upload.php' Arbitrary File Upload
Unrestricted file upload vulnerability in upload.php in dreamLog (aka dreamblog) 0.5 allows remote attackers to upload a
23RISK
open ↗Referência✓ VexDay Proof
LinPHA 1.3.1 - 'new_images.php' Blind SQL Injection
SQL injection vulnerability in include/img_view.class.php in LinPHA 1.3.1 and earlier allows remote attackers to execute
23RISK
open ↗Referência✓ VexDay Proof
ProManager 0.73 - 'config.php' Local File Inclusion
Directory traversal vulnerability in inc/config.php in ProManager 0.73 allows remote attackers to include and execute ar
23RISK
open ↗Referência✓ VexDay Proof
Thyme Calendar 1.3 - SQL Injection
SQL injection vulnerability in event_view.php in Thyme Calendar 1.3 allows remote attackers to execute arbitrary SQL com
23RISK
open ↗Referência✓ VexDay Proof
jaxultrabb 2.0 - Local File Inclusion / Cross-Site Scripting
Directory traversal vulnerability in viewprofile.php in JaxUltraBB 2.0 and earlier allows remote attackers to read arbit
23RISK
open ↗Referência✓ VexDay Proof
Data Dynamics ActiveReport - ActiveX 'actrpt2.dll 2.5' Insecure Method
Absolute path traversal vulnerability in the Data Dynamics ActiveReport (ActiveReports) ActiveX control in actrpt2.dll 2
23RISK
open ↗Referência✓ VexDay Proof
PHPWebGallery 1.3.4 - Cross-Site Scripting / Local File Inclusion
Multiple directory traversal vulnerabilities in PhpWebGallery 1.3.4 allow remote attackers to include and execute arbitr
23RISK
open ↗Referência✓ VexDay Proof
doop CMS 1.3.7 - Local File Inclusion
Directory traversal vulnerability in doop CMS 1.3.7 and earlier allows remote attackers to include and execute arbitrary
23RISK
open ↗Referência✓ VexDay Proof
Connectix Boards 0.8.2 - 'template_path' Remote File Inclusion
PHP remote file inclusion vulnerability in templates/Official/part_userprofile.php in Connectix Boards 0.8.2 and earlier
23RISK
open ↗Referência✓ VexDay Proof
iScripts Socialware - 'id' SQL Injection
iScripts SocialWare stores passwords in cleartext in a database, which allows context-dependent attackers to obtain sens
23RISK
open ↗Referência✓ VexDay Proof
IndexScript 2.8 - 'cat_id' SQL Injection
SQL injection vulnerability in show_cat.php in IndexScript 2.8 and earlier allows remote attackers to execute arbitrary
23RISK
open ↗Referência✓ VexDay Proof
BtiTracker 1.4.7 / xbtit 2.0.542 - SQL Injection
SQL injection vulnerability in scrape.php in BtiTracker 1.4.7 and earlier and xBtiTracker 2.0.542 and earlier allows rem
23RISK
open ↗Referência✓ VexDay Proof
PHPMyCart 1.3 - 'cat' SQL Injection
SQL injection vulnerability in shop.php in Conkurent PHPMyCart allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗Referência✓ VexDay Proof
phpBookingCalendar 1.0c - 'details_view.php' SQL Injection
SQL injection vulnerability in details_view.php in PHP Booking Calendar 1.0c and earlier allows remote attackers to exec
23RISK
open ↗Referência✓ VexDay Proof
PHP Coupon Script 3.0 - 'bus' SQL Injection
SQL injection vulnerability in index.php in PHP Coupon Script 3.0 allows remote attackers to execute arbitrary SQL comma
23RISK
open ↗Referência✓ VexDay Proof
Micro CMS 0.3.5 - Remote Add/Delete/Password Change
microcms-admin-home.php in Implied by Design Micro CMS (Micro-CMS) 3.5 (aka 0.3.5) does not require authentication as an
23RISK
open ↗Referência✓ VexDay Proof
xml2owl 0.1.1 - 'showcode.php' Remote Command Execution
showCode.php in xml2owl 0.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the path
23RISK
open ↗Referência✓ VexDay Proof
ADN Forum 1.0b - Insecure Cookie Handling
index.php in ADN Forum 1.0b and earlier allows remote attackers to bypass authentication and gain sysop access via a fpu
23RISK
open ↗Referência✓ VexDay Proof
Flat PHP Board 1.2 - Multiple Vulnerabilities
Flat PHP Board 1.2 and earlier allows remote attackers to bypass authentication and obtain limited access to an arbitrar
23RISK
open ↗Referência✓ VexDay Proof
RantX 1.0 - Insecure Admin Authentication
The admin.php file in Rantx allows remote attackers to bypass authentication and gain privileges by setting the logininf
23RISK
open ↗Referência✓ VexDay Proof
Acc PHP eMail 1.1 - Insecure Cookie Handling
Acc PHP eMail 1.1 allows remote attackers to bypass authentication and gain administrative access by setting the NEWSLET
23RISK
open ↗Referência✓ VexDay Proof
minimal ablog 0.4 - SQL Injection / Arbitrary File Upload / Authentication Bypass
uploader.php in minimal-ablog 0.4 does not properly restrict access, which allows remote attackers to gain administrativ
23RISK
open ↗Referência✓ VexDay Proof
TurnkeyForms - Text Link Sales Authentication Bypass
admin.php in TurnkeyForms Text Link Sales allows remote attackers to bypass authentication and gain administrative privi
23RISK
open ↗Referência✓ VexDay Proof
Exjune Officer Message System 1 - Multiple Vulnerabilities
exJune Office Message System 1 does not properly restrict access to (1) configure.asp and (2) addmessage2.asp, which all
23RISK
open ↗Referência✓ VexDay Proof
DreamAccount 3.1 - 'da_path' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in DreamAccount 3.1 and earlier, when register_globals is enabled, al
28RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.