Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,466Referência 23,051GitHub PoC 15,051VulnCheck XDB 8,883Nuclei 4,361Metasploit 3,493✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
MySpeach 3.0.7 - Local/Remote File Inclusion
Directory traversal vulnerability in chat.php in Sky GUNNING MySpeach 3.0.7 and earlier allows remote attackers to inclu
23RISK
open ↗Referência✓ VexDay Proof
MyBloggie 2.1.6 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in myWebland myBloggie 2.1.6 allow remote attackers to execute arbitrary SQL comm
23RISK
open ↗Referência✓ VexDay Proof
Winamp 5.3 - '.wmv' Remote Denial of Service
Buffer overflow in Nullsoft Winamp 5.3 allows user-assisted remote attackers to cause a denial of service (crash) via a
23RISK
open ↗Referência✓ VexDay Proof
AimStats 3.2 - 'process.php?update' Remote Code Execution
Static code injection vulnerability in process.php in AimStats 3.2 allows remote attackers to inject PHP code into confi
35RISK
open ↗Referência✓ VexDay Proof
Mozzers SubSystem final - 'subs.php' Remote Code Execution
Static code injection vulnerability in add.php in Mozzers SubSystem 1.0 allows remote attackers to inject PHP code into
23RISK
open ↗Referência✓ VexDay Proof
WEBInsta FM 0.1.4 - 'login.php' absolute_path Remote File Inclusion
PHP remote file inclusion vulnerability in admin/login.php in Webinsta FM Manager 0.1.4 and earlier allows remote attack
23RISK
open ↗Referência✓ VexDay Proof
PHP-Ring Webring System 0.9 - SQL Injection
SQL injection vulnerability in index.php in PHP-Ring Webring System (aka uPHP_ring_website) 0.9 allows remote attackers
23RISK
open ↗Referência✓ VexDay Proof
Microsoft Internet Explorer 6 / Ademco co. ltd. ATNBaseLoader100 Module - Remote Buffer Overflow
Buffer overflow in the BaseRunner ActiveX control in the Ademco ATNBaseLoader100 Module (ATNBaseLoader100.dll) 5.4.0.6,
35RISK
open ↗Referência✓ VexDay Proof
FlaP 1.0b - 'pachtofile' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in FlaP 1.0b (1.0 Beta) allow remote attackers to execute arbitrary P
23RISK
open ↗Referência✓ VexDay Proof
vBulletin vBGSiteMap 2.41 - 'root' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in the creator in vBulletin Google Yahoo Site Map (vBGSiteMap) 2.41 f
23RISK
open ↗Referência✓ VexDay Proof
OpenBASE 0.6a - 'root_prefix' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in OpenBASE Alpha 0.6 allow remote attackers to execute arbitrary PHP
23RISK
open ↗Referência✓ VexDay Proof
DESlock+ < 3.2.6 - 'DLMFDISK.sy's Local kernel Ring0 SYSTEM
DLMFDISK.sys 1.2.0.27 in DESlock+ 3.2.6 and earlier allows local users to gain privileges via a certain DLKFDISK_IOCTL r
23RISK
open ↗Referência✓ VexDay Proof
DESlock+ < 3.2.6 - 'LIST' Local Kernel Memory Leak
Memory leak in DLMFENC.sys 1.0.0.26 in DESlock+ 3.2.6 and earlier allows local users to cause a denial of service (kerne
23RISK
open ↗Referência✓ VexDay Proof
Pheap 2.0 - Authentication Bypass / Remote Code Execution
Pheap 2.0 allows remote attackers to bypass authentication by setting a pheap_login cookie value to the administrator's
23RISK
open ↗Referência✓ VexDay Proof
ZYXEL ZyWALL Quagga/Zebra - 'Default Password' Remote Code Execution
ZyXEL ZyWALL 1050 has a hard-coded password for the Quagga and Zebra processes that is not changed when it is set by a u
28RISK
open ↗Referência✓ VexDay Proof
phpComasy 0.8 - 'mod_project_id' SQL Injection
SQL injection vulnerability in index.php in phpComasy 0.8 allows remote attackers to execute arbitrary SQL commands via
23RISK
open ↗Referência✓ VexDay Proof
Affiliate Market 0.1 Beta - Cross-Site Scripting / SQL Injection
SQL injection vulnerability in shop/detail.php in Affiliate Market (affmarket) 0.1 BETA allows remote attackers to execu
23RISK
open ↗Referência✓ VexDay Proof
WebSPELL 4.01.02 - 'picture.php' File Disclosure
Directory traversal vulnerability in picture.php in WebSPELL 4.01.02 and earlier, when PHP before 4.3.0 is used, allows
23RISK
open ↗Referência✓ VexDay Proof
phpMyNewsletter 0.8 (beta5) - Multiple Vulnerabilities
admin/index.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier provides access to configuration modification
23RISK
open ↗Referência✓ VexDay Proof
Internet Download Accelerator 5.2 - Remote Buffer Overflow (PoC)
Buffer overflow in the NotSafe function in the idaiehlp ActiveX control in idaiehlp.dll 1.9.1.74 in Internet Download Ac
23RISK
open ↗Referência✓ VexDay Proof
EDraw Office Viewer Component - Unsafe Method
A certain ActiveX control in the EDraw Office Viewer Component (edrawofficeviewer.ocx) 4.0.5.20, and other versions befo
23RISK
open ↗Referência✓ VexDay Proof
Ripe Website Manager (CMS) 0.8.9 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Ripe Website Manager 0.8.9 and earlier allow remote attackers to e
35RISK
open ↗Referência✓ VexDay Proof
Buddy Zone 1.5 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in Buddy Zone 1.5 and earlier allow remote attackers to execute arbitrary SQL com
23RISK
open ↗Referência✓ VexDay Proof
Traffic Stats - 'referralUrl.php?offset' SQL Injection
SQL injection vulnerability in referralUrl.php in Traffic Stats allows remote attackers to execute arbitrary SQL command
23RISK
open ↗Referência✓ VexDay Proof
Microsoft Windows RSH daemon 1.7 - Remote Buffer Overflow
Stack-based buffer overflow in Mike Dubman Windows RSH daemon (rshd) 1.7 allows remote attackers to execute arbitrary co
28RISK
open ↗Referência✓ VexDay Proof
paBugs 2.0 Beta 3 - 'main.php?cid' SQL Injection
SQL injection vulnerability in main.php in paBugs 2.0 Beta 3 and earlier allows remote attackers to execute arbitrary SQ
23RISK
open ↗Referência✓ VexDay Proof
Microsoft Windows - DHCP Client Broadcast (MS06-036)
Buffer overflow in the DHCP Client service for Microsoft Windows 2000 SP4, Windows XP SP1 and SP2, and Server 2003 up to
45RISK
open ↗Referência✓ VexDay Proof
PHP 5.2.0 (Windows x86) - 'PHP_win32sti' Local Buffer Overflow
Buffer overflow in php_win32std.dll in the win32std extension for PHP 5.2.0 and earlier allows context-dependent attacke
23RISK
open ↗Referência✓ VexDay Proof
Remote Mouse GUI 3.008 - Local Privilege Escalation
Emote Interactive Remote Mouse 3.008 on Windows allows attackers to execute arbitrary programs as Administrator by using
23RISK
open ↗Referência✓ VexDay Proof
Friendly 1.0d1 - 'friendly_path' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Friendly 1.0d1 and earlier allow remote attackers to execute arbit
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.