Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,386cataloged exploits
36,533CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,466Referência 23,104GitHub PoC 15,075VulnCheck XDB 8,883Nuclei 4,365Metasploit 3,493✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
webSPELL 4.01.02 - 'showonly' Blind SQL Injection
SQL injection vulnerability in news.php in webSPELL 4.01.02, when register_globals is enabled, allows remote attackers t
23RISK
open ↗Referência✓ VexDay Proof
Snitz Forums 2000 3.1 SR4 - 'pop_profile.asp' SQL Injection
SQL injection vulnerability in pop_profile.asp in Snitz Forums 2000 3.1 SR4 allows remote attackers to execute arbitrary
23RISK
open ↗Referência✓ VexDay Proof
XLAtunes 0.1 - 'album' SQL Injection
SQL injection vulnerability in view.php in XLAtunes 0.1 and earlier allows remote attackers to execute arbitrary SQL com
23RISK
open ↗Referência✓ VexDay Proof
Vivvo Article Manager 3.4 - 'root' Local File Inclusion
Directory traversal vulnerability in include/db_conn.php in SpoonLabs Vivvo Article Management CMS 3.4 allows remote att
23RISK
open ↗Referência✓ VexDay Proof
PHP-Nuke Module Emporium 2.3.0 - SQL Injection
SQL injection vulnerability in the category file in modules.php in the Emporium 2.3.0 and earlier module for PHP-Nuke al
23RISK
open ↗Referência✓ VexDay Proof
Xpression News 1.0.1 - 'archives.php' Remote File Disclosure
Directory traversal vulnerability in archives.php in Xpression News (X-News) 1.0.1 allows remote attackers to include ar
23RISK
open ↗Referência✓ VexDay Proof
News Rover 12.1 Rev 1 - Stack Overflow (1)
Multiple stack-based buffer overflows in S&H Computer Systems News Rover 12.1 Rev 1 allow remote attackers to execute ar
23RISK
open ↗Referência✓ VexDay Proof
TurboFTP Server 5.30 Build 572 - 'newline/LIST' Multiple Remote Denial of Service Vulnerabilities
Multiple heap-based buffer overflows in TurboFTP 5.30 Build 572 allow remote servers to cause a denial of service via (1
23RISK
open ↗Referência✓ VexDay Proof
PHP-MIP 0.1 - 'top.php?laypath' Remote File Inclusion
PHP remote file inclusion vulnerability in top.php in PHP Module Implementation (PHP-MIP) 0.1 allows remote attackers to
23RISK
open ↗Referência✓ VexDay Proof
phpBB Module NoMoKeTos Rules 0.0.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in includes/functions_nomoketos_rules.php in the NoMoKeTos Rules 0.0.1 module fo
23RISK
open ↗Referência✓ VexDay Proof
Coppermine Photo Gallery 1.3.x - Blind SQL Injection
SQL injection vulnerability in thumbnails.php in Coppermine Photo Gallery (CPG) 1.3.x allows remote authenticated users
23RISK
open ↗Referência✓ VexDay Proof
CS-Gallery 2.0 - 'index.php?album' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in Christian Schneider CS-Gallery 2.0 and earlier allows remote att
23RISK
open ↗Referência✓ VexDay Proof
Sinapis 2.2 Gastebuch - 'sinagb.php?fuss' Remote File Inclusion
PHP remote file inclusion vulnerability in sinagb.php in Sinapis Gastebuch 2.2 allows remote attackers to execute arbitr
23RISK
open ↗Referência✓ VexDay Proof
Sinapis Forum 2.2 - 'sinapis.php?fuss' Remote File Inclusion
PHP remote file inclusion vulnerability in sinapis.php in Sinapis Forum 2.2 allows remote attackers to execute arbitrary
23RISK
open ↗Referência✓ VexDay Proof
FCRing 1.31 - 'fcring.php?s_fuss' Remote File Inclusion
PHP remote file inclusion vulnerability in fcring.php in FCRing 1.3 allows remote attackers to execute arbitrary PHP cod
23RISK
open ↗Referência✓ VexDay Proof
webSPELL 4.01.02 - 'topic' SQL Injection
SQL injection vulnerability in printview.php in webSPELL 4.01.02 and earlier allows remote attackers to execute arbitrar
23RISK
open ↗Referência✓ VexDay Proof
NukeSentinel 2.5.05 - 'nukesentinel.php' File Disclosure
SQL injection vulnerability in nukesentinel.php in NukeSentinel 2.5.05, and possibly earlier, allows remote attackers to
23RISK
open ↗Referência✓ VexDay Proof
Plan 9 Kernel - 'devenv.c OTRUNC/pwrite' Local Privilege Escalation
Integer overflow in the envwrite function in the Alcatel-Lucent Bell Labs Plan 9 kernel allows local users to overwrite
23RISK
open ↗Referência✓ VexDay Proof
SonicMailer Pro 3.2.3 - 'index.php' SQL Injection
SQL injection vulnerability in index.php in Triexa SonicMailer Pro 3.2.3 and earlier allows remote attackers to execute
23RISK
open ↗Referência✓ VexDay Proof
AssetMan 2.4a - 'download_pdf.php' Remote File Disclosure
Directory traversal vulnerability in download_pdf.php in AssetMan 2.4a and earlier allows remote attackers to read arbit
23RISK
open ↗Referência✓ VexDay Proof
creative Guestbook 1.0 - Multiple Vulnerabilities
Creative Guestbook 1.0 allows remote attackers to add an administrative account via a direct request to createadmin.php
23RISK
open ↗Referência✓ VexDay Proof
wbblog - Cross-Site Scripting / SQL Injection
SQL injection vulnerability in index.php in WBBlog allows remote attackers to execute arbitrary SQL commands via the e_i
23RISK
open ↗Referência✓ VexDay Proof
wbblog - Cross-Site Scripting / SQL Injection
Cross-site scripting (XSS) vulnerability in index.php in WBBlog allows remote attackers to inject arbitrary web script o
23RISK
open ↗Referência✓ VexDay Proof
WebLog - 'index.php' Remote File Disclosure
Directory traversal vulnerability in index.php in Sascha Schroeder (aka CyberTeddy or Cyber-inside) WebLog allows remote
23RISK
open ↗Referência✓ VexDay Proof
Avant Browser 11.0 build 26 - Remote Stack Overflow Crash
Stack-based buffer overflow in Avant Browser 11.0 build 26 allows remote attackers to cause a denial of service (crash)
23RISK
open ↗Referência✓ VexDay Proof
osTicket 1.11 - Cross-Site Scripting / Local File Inclusion
In osTicket before 1.12, XSS exists via /upload/file.php, /upload/scp/users.php?do=import-users, and /upload/scp/ajax.ph
23RISK
open ↗Referência✓ VexDay Proof
pNews 1.1.0 - 'nbs' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/global.php in Joshua Wilson pNews System 1.1.0 (aka PowerNews) allow
23RISK
open ↗Referência✓ VexDay Proof
Webmin 1.910 - 'Package Updates' Remote Command Execution (Metasploit)
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root pr
60RISK
open ↗Referência✓ VexDay Proof
Guestbara 1.2 - Change Admin Login and Password
admin/configuration.php in Guestbara 1.2 and earlier allows remote attackers to modify the e-mail, name, and password of
23RISK
open ↗Referência✓ VexDay Proof
NetVIOS Portal - 'page.asp' SQL Injection
SQL injection vulnerability in News/page.asp in NetVIOS Portal allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.