Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,313cataloged exploits
34,834CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,797GitHub PoC 13,885VulnCheck XDB 8,484Nuclei 4,237Metasploit 3,467✓ verified onlyrecentpopularrisk
21,692 exploits
Referência
CVE-2010-0632
SQL injection vulnerability in the Parkview Consultants SimpleFAQ (com_simplefaq) component for Joomla! allows remote at
23RISK
open ↗Referência✓ VexDay Proof
RichStrong CMS - 'cat' SQL Injection
SQL injection vulnerability in showproduct.asp in RichStrong CMS allows remote attackers to execute arbitrary SQL comman
23RISK
open ↗Referência✓ VexDay Proof
FaScript FaPersian Petition - SQL Injection
SQL injection vulnerability in show.php in FaScript FaPersian Petition allows remote attackers to execute arbitrary SQL
23RISK
open ↗Referência✓ VexDay Proof
Aria 0.99-6 - 'page' Local File Inclusion
Directory traversal vulnerability in arias/help/effect.php in aria 0.99-6 allows remote attackers to include and execute
23RISK
open ↗Referência
CVE-2010-0642
Cisco Collaboration Server (CCS) 5 allows remote attackers to read the source code of JHTML files via URL encoded charac
23RISK
open ↗Referência✓ VexDay Proof
PHP-RESIDENCE 0.7.2 - 'Search' SQL Injection
SQL injection vulnerability in visualizza_tabelle.php in php-residence 0.7.2 and 1.0 allows remote attackers to execute
23RISK
open ↗Referência✓ VexDay Proof
PHPEcho CMS 2.0 - 'id' SQL Injection
SQL injection vulnerability in index.php in the forum module in PHPEcho CMS, probably 2.0-rc3 and earlier, allows remote
23RISK
open ↗Referência✓ VexDay Proof
Small Axe 0.3.1 - 'cfile' Remote File Inclusion
PHP remote file inclusion vulnerability in inc/linkbar.php in Small Axe Weblog 0.3.1 allows remote attackers to execute
35RISK
open ↗Referência✓ VexDay Proof
Crystal Reports XI Release 2 (Enterprise Tree Control) - ActiveX Buffer Overflow (Denial of Service) (PoC)
Race condition in the Enterprise Tree ActiveX control (EnterpriseControls.dll 11.5.0.313) in Crystal Reports XI Release
23RISK
open ↗Referência✓ VexDay Proof
Digital Data Communications - 'RtspVaPgCtrl' Class Remote Buffer Overflow
Buffer overflow in the Digital Data Communications RtspVaPgCtrl ActiveX control (RtspVapgDecoder.dll 1.1.0.29) allows re
28RISK
open ↗Referência✓ VexDay Proof
MyBulletinBoard (MyBB) 1.2.10 - Multiple Vulnerabilities
Multiple eval injection vulnerabilities in MyBB 1.2.10 and earlier allow remote attackers to execute arbitrary code via
35RISK
open ↗Referência✓ VexDay Proof
MyBulletinBoard (MyBB) 1.2.10 - Remote Code Execution
Multiple eval injection vulnerabilities in MyBB 1.2.10 and earlier allow remote attackers to execute arbitrary code via
35RISK
open ↗Referência✓ VexDay Proof
OpenBSD 4.2 - 'rtlabel_id2name()' Local Null Pointer Dereference Denial of Service
OpenBSD 4.2 allows local users to cause a denial of service (kernel panic) by calling the SIOCGIFRTLABEL IOCTL on an int
23RISK
open ↗Referência✓ VexDay Proof
alitalk 1.9.1.1 - Multiple Vulnerabilities
inc/elementz.php in aliTalk 1.9.1.1 does not properly verify authentication, which allows remote attackers to add an arb
23RISK
open ↗Referência✓ VexDay Proof
Microsoft Visual Basic Enterprise 6 SP6 - '.dsr' File Handling Buffer Overflow
Multiple buffer overflows in Microsoft Visual Basic Enterprise Edition 6.0 SP6 allow user-assisted remote attackers to e
35RISK
open ↗Referência✓ VexDay Proof
Alstrasoft Forum Pay Per Post Exchange 2.0 - SQL Injection
SQL injection vulnerability in index.php in AlstraSoft Forum Pay Per Post Exchange 2.0 allows remote attackers to execut
23RISK
open ↗Referência✓ VexDay Proof
360 Web Manager 3.0 - 'IDFM' SQL Injection
SQL injection vulnerability in form.php in 360 Web Manager 3.0 allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗Referência✓ VexDay Proof
flinx 1.3 - 'id' SQL Injection
SQL injection vulnerability in category.php in Flinx 1.3 and earlier allows remote attackers to execute arbitrary SQL co
23RISK
open ↗Referência✓ VexDay Proof
Persits XUpload 3.0 - 'AddFile()' Remote Buffer Overflow
Stack-based buffer overflow in the Persits.XUpload.2 ActiveX control in XUpload.ocx 3.0.0.4 and earlier in Persits XUplo
43RISK
open ↗Referência✓ VexDay Proof
Bigware Shop 2.0 - 'pollid' SQL Injection
SQL injection vulnerability in main_bigware_53.tpl.php in Bigware Shop 2.0 allows remote attackers to execute arbitrary
23RISK
open ↗Referência✓ VexDay Proof
phpMyClub 0.0.1 - 'page_courante' Local File Inclusion
Directory traversal vulnerability in phpMyClub 0.0.1 allows remote attackers to include and execute arbitrary local file
23RISK
open ↗Referência✓ VexDay Proof
Mambo Component EstateAgent 0.1 - SQL Injection
SQL injection vulnerability in index.php in the Darko Selesi EstateAgent (com_estateagent) 0.1 component for Mambo 4.5.x
23RISK
open ↗Referência✓ VexDay Proof
Mambo Component Recipes 1.00 - 'id' SQL Injection
SQL injection vulnerability in index.php in the Recipes (com_recipes) 1.00 component for Mambo and Joomla! allows remote
23RISK
open ↗Referência✓ VexDay Proof
Mambo Component jokes 1.0 - 'cat' SQL Injection
SQL injection vulnerability in index.php in the Atapin Jokes (com_jokes) 1.0 component for Mambo and Joomla! allows remo
23RISK
open ↗Referência✓ VexDay Proof
Simple Forum 3.2 - File Disclosure / Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in forum.php in Gerd Tentler Simple Forum 3.2 allow remote attackers
23RISK
open ↗Referência✓ VexDay Proof
PHP Links 1.3 - 'id' SQL Injection
SQL injection vulnerability in vote.php in DeltaScripts PHP Links 1.3 and earlier allows remote attackers to execute arb
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component ChronoForms 2.3.5 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in ChronoEngine ChronoForms (com_chronocontact) 2.3.5 component for J
35RISK
open ↗Referência✓ VexDay Proof
Mindmeld 1.2.0.10 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Mindmeld 1.2.0.10 allow remote attackers to execute arbitrary PHP
28RISK
open ↗Referência✓ VexDay Proof
SafeNet 10.4.0.12 - 'IPSecDrv.sys' Local kernel Ring0 SYSTEM
IPSecDrv.sys 10.4.0.12 in SafeNET HighAssurance Remote and SoftRemote allows local users to gain privileges via a crafte
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.