Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,107cataloged exploits
34,679CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,692GitHub PoC 13,812VulnCheck XDB 8,460Nuclei 4,233Metasploit 3,467✓ verified onlyrecentpopularrisk
21,692 exploits
Referência✓ VexDay Proof
XOOPS Module resmanager 1.21 - Blind SQL Injection
SQL injection vulnerability in edit_day.php in the ResManager 1.2.1 and earlier module for Xoops allows remote attackers
23RISK
open ↗Referência✓ VexDay Proof
Achievo 1.1.0 - 'config_atkroot' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in Achievo 1.1.0 allows remote attackers to execute arbitrary PHP c
23RISK
open ↗Referência✓ VexDay Proof
FAQEngine 4.16.03 - 'question.php?questionref' SQL Injection
SQL injection vulnerability in question.php in FAQEngine 4.16.03 and earlier allows remote attackers to execute arbitrar
23RISK
open ↗Referência✓ VexDay Proof
PHPGlossar 0.8 - 'format_menue' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in PHPGlossar 0.8 allow remote attackers to execute arbitrary PHP cod
23RISK
open ↗Referência✓ VexDay Proof
CA BrightStor Backup 11.5.2.0 - 'caloggderd.exe' Denial of Service
(1) caloggerd.exe (camt70.dll) and (2) mediasvr.exe (catirpc.dll and rwxdr.dll) in CA BrightStor Backup 11.5.2.0 SP2 all
28RISK
open ↗Referência✓ VexDay Proof
CA BrightStor Backup 11.5.2.0 - 'Mediasvr.exe' Denial of Service
(1) caloggerd.exe (camt70.dll) and (2) mediasvr.exe (catirpc.dll and rwxdr.dll) in CA BrightStor Backup 11.5.2.0 SP2 all
28RISK
open ↗Referência✓ VexDay Proof
Alstrasoft Live Support 1.21 - Admin Credential Retrieve
AlstraSoft Live Support 1.21 sends a redirect to the web browser but does not exit when administrative credentials are m
23RISK
open ↗Referência✓ VexDay Proof
Alstrasoft Template Seller Pro 3.25 - Remote Code Execution
Unrestricted file upload vulnerability in admin/addsptemplate.php in AlstraSoft Template Seller Pro 3.25 and earlier all
23RISK
open ↗Referência✓ VexDay Proof
Libstats 1.0.3 - 'template_csv.php' Remote File Inclusion
PHP remote file inclusion vulnerability in template_csv.php in Libstats 1.0.3 and earlier allows remote attackers to exe
23RISK
open ↗Referência✓ VexDay Proof
LeadTools Thumbnail Browser Control - 'lttmb14E.ocx' Remote Buffer Overflow
Stack-based buffer overflow in the BrowseDir function in the (1) lttmb14E.ocx or (2) LTRTM14e.DLL ActiveX control in Lea
23RISK
open ↗Referência✓ VexDay Proof
Ol BookMarks Manager 0.7.4 - 'root' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in ol'bookmarks 0.7.4 allow remote attackers to execute arbitrary PHP
28RISK
open ↗Referência
CVE-2007-2821
SQL injection vulnerability in wp-admin/admin-ajax.php in WordPress before 2.2 allows remote attackers to execute arbitr
23RISK
open ↗Referência✓ VexDay Proof
TutorialCMS 1.01 - Authentication Bypass
TutorialCMS 1.01 and earlier, when register_globals is enabled, allows remote attackers to bypass authentication via the
23RISK
open ↗Referência✓ VexDay Proof
LeadTools Raster Variant - 'LTRVR14e.dll' Remote File Overwrite
A certain ActiveX control in LeadTools Raster Variant Object Library (LTRVR14e.dll) 14.5.0.44 allows remote attackers to
23RISK
open ↗Referência✓ VexDay Proof
Virtual CD 9.0.0.2 - 'vc9api.DLL' Remote Shell Commands Execution
The VCDAPILibApi ActiveX control in vc9api.DLL 9.0.0.57 in Virtual CD 9.0.0.2 allows remote attackers to execute arbitra
23RISK
open ↗Referência✓ VexDay Proof
BtiTracker 1.4.1 - Become Admin SQL Injection
Multiple SQL injection vulnerabilities in account_change.php in BtiTracker 1.4.1 and earlier allow remote attackers to e
23RISK
open ↗Referência
CVE-2009-5134
Buffer overflow in the "create torrent dialog" functionality in uTorrent 1.8.3 build 15772, and possibly other versions
23RISK
open ↗Referência✓ VexDay Proof
Microsoft Visual Basic 6.0 Project - Company Name Stack Overflow (PoC)
Multiple stack-based buffer overflows in Microsoft Visual Basic 6 allow user-assisted remote attackers to cause a denial
35RISK
open ↗Referência✓ VexDay Proof
Microsoft Visual Basic 6.0 Project - Description Stack Overflow (PoC)
Multiple stack-based buffer overflows in Microsoft Visual Basic 6 allow user-assisted remote attackers to cause a denial
35RISK
open ↗Referência✓ VexDay Proof
UltraISO 8.6.2.2011 - '.cue/'.bin' Local Buffer Overflow (PoC)
Stack-based buffer overflow in UltraISO 8.6.2.2011 and earlier allows user-assisted remote attackers to execute arbitrar
50RISK
open ↗Referência✓ VexDay Proof
CPCommerce 1.1.0 - 'id_category' SQL Injection
SQL injection vulnerability in category.php in cpCommerce 1.1.0 and earlier allows remote attackers to execute arbitrary
23RISK
open ↗Referência✓ VexDay Proof
OpenBASE 0.6a - 'root_prefix' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in OpenBASE Alpha 0.6 allow remote attackers to execute arbitrary PHP
23RISK
open ↗Referência✓ VexDay Proof
Pheap 2.0 - Authentication Bypass / Remote Code Execution
Pheap 2.0 allows remote attackers to bypass authentication by setting a pheap_login cookie value to the administrator's
23RISK
open ↗Referência✓ VexDay Proof
AdminBot 9.0.5 - 'live_status.lib.php' Remote File Inclusion
PHP remote file inclusion vulnerability in lib/live_status.lib.php in AdminBot MX 9.0.5 allows remote attackers to execu
35RISK
open ↗Referência✓ VexDay Proof
Acoustica MP3 CD Burner 4.51 Build 147 - '.asx' Local Buffer Overflow
Buffer overflow in Acoustica MP3 CD Burner 4.32 allows user-assisted remote attackers to execute arbitrary code via a .a
23RISK
open ↗Referência✓ VexDay Proof
Microsoft Windows Message Queuing Service - RPC Buffer Overflow (MS07-065) (1)
Stack-based buffer overflow in the Microsoft Message Queuing (MSMQ) service in Microsoft Windows 2000 Server SP4, Window
50RISK
open ↗Referência✓ VexDay Proof
Microsoft Windows Message Queuing Service - RPC Buffer Overflow (MS07-065) (2)
Stack-based buffer overflow in the Microsoft Message Queuing (MSMQ) service in Microsoft Windows 2000 Server SP4, Window
50RISK
open ↗Referência✓ VexDay Proof
Microsoft Windows Server 2000 SP4 (Advanced Server) - Message Queue (MS07-065)
Stack-based buffer overflow in the Microsoft Message Queuing (MSMQ) service in Microsoft Windows 2000 Server SP4, Window
50RISK
open ↗Referência✓ VexDay Proof
PNPHPBB2 < 1.2 - 'index.php' SQL Injection
SQL injection vulnerability in index.php in the PNphpBB2 1.2i and earlier module for PostNuke allows remote attackers to
23RISK
open ↗Referência✓ VexDay Proof
Particle Gallery 1.0.1 - SQL Injection
SQL injection vulnerability in viewimage.php in Particle Soft Particle Gallery 1.0.1 and earlier allows remote attackers
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.