Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,466Referência 23,051GitHub PoC 15,051VulnCheck XDB 8,883Nuclei 4,361Metasploit 3,493✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
SoftBB 0.1 - 'cmd' Remote Command Execution
index.php in SoftBB 0.1, and possibly earlier, allows remote attackers to obtain the installation path via a null or inv
23RISK
open ↗Referência✓ VexDay Proof
GeekLog 1.4.0sr3 - '_CONF[path]' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in GeekLog 1.4 allow remote attackers to execute arbitrary code via a
23RISK
open ↗Referência✓ VexDay Proof
Woltlab Burning Board Lite 1.0.2 - 'decode_cookie()' SQL Injection
SQL injection vulnerability in the decode_cookie function in thread.php in Woltlab Burning Board Lite 1.0.2 allows remot
23RISK
open ↗Referência✓ VexDay Proof
Magic News Pro 1.0.3 - 'script_path' Remote File Inclusion
PHP remote file inclusion vulnerability in scripts/news_page.php in Reamday Enterprises Magic News Pro 1.0.3 and earlier
23RISK
open ↗Referência✓ VexDay Proof
The Classified Ad System 1.0 - 'main' SQL Injection
Multiple SQL injection vulnerabilities in PWP Technologies The Classified Ad System allow remote attackers to execute ar
23RISK
open ↗Referência✓ VexDay Proof
Mambo Component Shambo2 - 'itemID' SQL Injection
SQL injection vulnerability in index.php in the Shambo2 (com_shambo2) component for Mambo and Joomla! allows remote atta
23RISK
open ↗Referência✓ VexDay Proof
Ipswitch WS_FTP Server with SSH 6.1.0.0 - Remote Buffer Overflow (PoC)
Buffer overflow in Ipswitch WS_FTP Server with SSH 6.1.0.0 allows remote authenticated users to cause a denial of servic
28RISK
open ↗Referência✓ VexDay Proof
Linux Kernel 2.6.17 < 2.6.24.1 - 'vmsplice' Local Privilege Escalation (2)
The vmsplice_to_pipe function in Linux kernel 2.6.17 through 2.6.24.1 does not validate a certain userspace pointer befo
23RISK
open ↗Referência✓ VexDay Proof
All Club CMS 0.0.2 - 'index.php' SQL Injection
SQL injection vulnerability in index.php in All Club CMS (ACCMS) 0.0.1f and earlier allows remote attackers to execute a
23RISK
open ↗Referência✓ VexDay Proof
All Club CMS 0.0.1f - 'index.php' Local File Inclusion
Directory traversal vulnerability in index.php in All Club CMS (ACCMS) 0.0.1f and earlier allows remote attackers to inc
23RISK
open ↗Referência✓ VexDay Proof
Mambo Component 'com_awesom' 0.3.2 - 'listid' SQL Injection
SQL injection vulnerability in index.php in the amazOOP Awesom! (com_awesom) 0.3.2component for Mambo and Joomla! allows
23RISK
open ↗Referência✓ VexDay Proof
RMSOFT Gallery System 2.0 - 'id' SQL Injection
SQL injection vulnerability in rmgs/images.php in the RMSOFT Gallery System 2.0 module for XOOPS allows remote attackers
23RISK
open ↗Referência✓ VexDay Proof
PhotoKorn Gallery 1.543 - 'pic' SQL Injection
SQL injection vulnerability in index.php in Photokorn Gallery 1.543 allows remote attackers to execute arbitrary SQL com
23RISK
open ↗Referência✓ VexDay Proof
NERO Media Player 1.4.0.35b - '.m3u' File Buffer Overflow (PoC)
Buffer overflow in NeroMediaPlayer.exe in Nero Media Player 1.4.0.35 and earlier allows remote attackers to execute arbi
28RISK
open ↗Referência✓ VexDay Proof
GNUTURK 2G - 't_id' SQL Injection
SQL injection vulnerability in mods.php in GNUTurk 2G and earlier allows remote attackers to execute arbitrary SQL comma
23RISK
open ↗Referência✓ VexDay Proof
PHP-Update 2.7 - '/admin/uploads.php' Remote Code Execution
Unrestricted file upload vulnerability in admin/uploads.php in PHP-Update 2.7 and earlier allows remote authenticated us
23RISK
open ↗Referência✓ VexDay Proof
PHP-Update 2.7 - Multiple Vulnerabilities
Unrestricted file upload vulnerability in admin/uploads.php in PHP-Update 2.7 and earlier allows remote authenticated us
23RISK
open ↗Referência✓ VexDay Proof
ProgSys 0.156 - 'RR.php' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/pear/Net/DNS/RR.php in ProgSys 0.151 and earlier allows remote attac
23RISK
open ↗Referência✓ VexDay Proof
Digital WebShop 1.128 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Cardway (aka Frederic Boudaud) DigitalWebShop 1.128 and earlier al
23RISK
open ↗Referência✓ VexDay Proof
BCWB 0.99 - 'ROOT_PATH' Remote File Inclusion
PHP remote file inclusion vulnerability in include/startup.inc.php in CMSDevelopment Business Card Web Builder (BCWB) 0.
23RISK
open ↗Referência✓ VexDay Proof
Web-News 1.6.3 - 'template.php' Remote File Inclusion
PHP remote file inclusion vulnerability in webnews/template.php in Web-News 1.6.3 and earlier allows remote attackers to
23RISK
open ↗Referência✓ VexDay Proof
PBLang 4.66z - 'temppath' Remote File Inclusion
PHP remote file inclusion vulnerability in templates/pb/language/lang_nl.php in PBLang (PBL) 4.66z and earlier allows re
23RISK
open ↗Referência✓ VexDay Proof
PHP-Stats 0.1.9.1b - 'ip' SQL Injection
Multiple SQL injection vulnerabilities in php-stats.recphp.php in PHP-Stats 0.1.9.1b and earlier allow remote attackers
23RISK
open ↗Referência✓ VexDay Proof
NaviCOPA Web Server 2.01 - 'GET' Remote Buffer Overflow
Buffer overflow in InterVations NaviCOPA Web Server 2.01 allows remote attackers to execute arbitrary code via a long HT
50RISK
open ↗Referência✓ VexDay Proof
phpMyTeam 2.0 - 'smileys_dir' Remote File Inclusion
PHP remote file inclusion vulnerability in images/smileys/smileys_packs.php in phpMyTeam 2.0, when register_globals is e
23RISK
open ↗Referência✓ VexDay Proof
Claroline 1.8.0 rc1 - 'import.lib.php' Remote File Inclusion
PHP remote file inclusion vulnerability in claroline/inc/lib/import.lib.php in Claroline 1.8.0 and earlier allows remote
23RISK
open ↗Referência✓ VexDay Proof
phpBB Prillian French Mod 0.8.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in language/lang_french/lang_prillian_faq.php in the Prillian French 0.8.0 and e
23RISK
open ↗Referência✓ VexDay Proof
PHPMyConferences 8.0.2 - 'menu.inc.php' File Inclusion
PHP remote file inclusion vulnerability in common/visiteurs/include/menus.inc.php in J-Pierre DEZELUS Les Visiteurs 2.0.
23RISK
open ↗Referência✓ VexDay Proof
phpBB News Defilante Horizontale 4.1.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in includes/functions_newshr.php in the News Defilante Horizontale 4.1.1 and ear
23RISK
open ↗Referência✓ VexDay Proof
phpBB SearchIndexer Mod - 'archive_topic.php' Remote File Inclusion
PHP remote file inclusion vulnerability in archive/archive_topic.php in pbpbb archive for search engines (SearchIndexer)
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.