Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,313cataloged exploits
34,834CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,797GitHub PoC 13,885VulnCheck XDB 8,484Nuclei 4,237Metasploit 3,467✓ verified onlyrecentpopularrisk
21,692 exploits
Referência✓ VexDay Proof
blogme 3.0 - Cross-Site Scripting / Authentication Bypass
Multiple SQL injection vulnerabilities in admin_login.asp in BlogMe 3.0 allow remote attackers to execute arbitrary SQL
23RISK
open ↗Referência
CVE-2009-4680
SQL injection vulnerability in search.php in phpDirectorySource 1.x allows remote attackers to execute arbitrary SQL com
23RISK
open ↗Referência✓ VexDay Proof
Powies pForum 1.29a - 'editpoll.php' SQL Injection
SQL injection vulnerability in editpoll.php in Powie's PHP Forum (pForum) 1.29a and earlier allows remote attackers to e
23RISK
open ↗Referência✓ VexDay Proof
WORK System E-Commerce 3.0.1 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Laurent Van den Reysen WORK system e-commerce 3.0.2, and other ver
23RISK
open ↗Referência✓ VexDay Proof
PHPWebThings 1.5.2 - 'editor.php' Remote File Inclusion
PHP remote file inclusion vulnerability in core/editor.php in phpWebThings 1.5.2 and earlier, when register_globals is e
23RISK
open ↗Referência✓ VexDay Proof
Etomite CMS 0.6.1.2 - '/manager/index.php' Local File Inclusion
Directory traversal vulnerability in manager/index.php in Etomite 0.6.1.2 allows remote authenticated administrators to
23RISK
open ↗Referência✓ VexDay Proof
XMPlay 3.3.0.4 - '.M3U' Filename Local Buffer Overflow
Stack-based buffer overflow in Un4seen XMPlay 3.3.0.5 and earlier allows remote attackers to execute arbitrary code via
50RISK
open ↗Referência
CVE-2009-4688
Multiple cross-site scripting (XSS) vulnerabilities in index.php in PHP Shopping Cart Selling Website Script allow remot
23RISK
open ↗Referência✓ VexDay Proof
FipsCMS 4.5 - 'index.asp' SQL Injection
SQL injection vulnerability in index.asp in fipsCMS 4.5 and earlier allows remote attackers to execute arbitrary SQL com
23RISK
open ↗Referência✓ VexDay Proof
fipsForum 2.6 - 'default2.asp' SQL Injection
SQL injection vulnerability in default2.asp in fipsForum 2.6 and earlier allows remote attackers to execute arbitrary SQ
23RISK
open ↗Referência
CVE-2009-4689
SQL injection vulnerability in index.php in PHP Shopping Cart Selling Website Script allows remote attackers to execute
23RISK
open ↗Referência✓ VexDay Proof
fipsGallery 1.5 - 'index1.asp' SQL Injection
SQL injection vulnerability in index1.asp in fipsGallery 1.5 and earlier allows remote attackers to execute arbitrary SQ
23RISK
open ↗Referência✓ VexDay Proof
Sisfo Kampus 0.8 - Remote File Inclusion / Download
Multiple PHP remote file inclusion vulnerabilities in Sisfo Kampus 0.8 allow remote attackers to execute arbitrary PHP c
23RISK
open ↗Referência✓ VexDay Proof
Sisfo Kampus 0.8 - Remote File Inclusion / Download
Directory traversal vulnerability in download.php in Sisfo Kampus 0.8 allows remote attackers to list arbitrary director
23RISK
open ↗Referência✓ VexDay Proof
Liberum Help Desk 0.97.3 - SQL Injection
SQL injection vulnerability in details.asp in Doug Luxem Liberum Help Desk 0.97.3 and earlier allows remote attackers to
23RISK
open ↗Referência
CVE-2024-27199
In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible
100RISK
open ↗Referência
CVE-2022-44877
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execut
100RISK
open ↗Referência
CVE-2022-44877
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execut
100RISK
open ↗Referência
CVE-2022-44877
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execut
100RISK
open ↗Referência
CVE-2006-6184
Multiple stack-based buffer overflows in Allied Telesyn TFTP Server (AT-TFTP) 1.9, and possibly earlier, allow remote at
50RISK
open ↗Referência
CVE-2006-6184
Multiple stack-based buffer overflows in Allied Telesyn TFTP Server (AT-TFTP) 1.9, and possibly earlier, allow remote at
50RISK
open ↗Referência✓ VexDay Proof
SimpleBlog 2.3 - '/admin/edit.asp' SQL Injection
SQL injection vulnerability in admin/edit.asp in 8pixel.net simpleblog 2.3 and earlier allows remote attackers to execut
23RISK
open ↗Referência✓ VexDay Proof
Hacks List phpBB Mod 1.21 - SQL Injection
SQL injection vulnerability in admin_hacks_list.php in the Nivisec Hacks List 1.21 and earlier phpBB module allows remot
23RISK
open ↗Referência✓ VexDay Proof
Recipes Complete Website 1.1.14 - SQL Injection
Multiple SQL injection vulnerabilities in Recipes Website (Recipes Complete Website) 1.1.14 allow remote attackers to ex
23RISK
open ↗Referência✓ VexDay Proof
GeekLog 1.4.0sr3 - '_CONF[path]' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in GeekLog 1.4 allow remote attackers to execute arbitrary code via a
23RISK
open ↗Referência✓ VexDay Proof
S9Y Serendipity 1.0.3 - 'comment.php' Local File Inclusion
Multiple directory traversal vulnerabilities in Serendipity 1.0.3 and earlier allow remote attackers to read or include
23RISK
open ↗Referência✓ VexDay Proof
Songbird Media Player 0.2 - Format String Denial of Service (PoC)
Format string vulnerability in Songbird Media Player 0.2 and earlier allows remote attackers to cause a denial of servic
23RISK
open ↗Referência✓ VexDay Proof
VUPlayer 2.44 - '.m3u' UNC Name Buffer Overflow (Metasploit)
Stack-based buffer overflow in VUPlayer 2.44 and earlier allows remote attackers to execute arbitrary code via a long st
50RISK
open ↗Referência✓ VexDay Proof
Quintessential Player 4.50.1.82 - Playlist Denial of Service (PoC)
Buffer overflow in Quintessential Player 4.50.1.82 and earlier allows remote attackers to cause a denial of service (cra
23RISK
open ↗Referência✓ VexDay Proof
CoolPlayer 2.17 - '.m3u' Local Stack Overflow
Multiple buffer overflows in Niek Albers CoolPlayer 216 and earlier allow remote attackers to execute arbitrary code via
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.