Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,460Referência 22,832GitHub PoC 14,991VulnCheck XDB 8,829Nuclei 4,357Metasploit 3,489✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
Soulseek 157 NS - Remote Buffer Overflow (SEH)
Stack-based buffer overflow in Soulseek 156 and 157 NS allows remote attackers to execute arbitrary code via a long sear
23RISK
open ↗Referência✓ VexDay Proof
ClanLite 2.x - SQL Injection / Cross-Site Scripting
SQL injection vulnerability in service/profil.php in ClanLite 2.2006.05.20 allows remote attackers to execute arbitrary
23RISK
open ↗Referência✓ VexDay Proof
FREEze Greetings 1.0 - Remote Password Retrieve
ScriptsEz FREEze Greetings 1.0 stores pwd.txt under the web root with insufficient access control, which allows remote a
23RISK
open ↗Referência✓ VexDay Proof
AJ Article 1.0 - 'featured_article.php' SQL Injection
SQL injection vulnerability in featured_article.php in AJ Article 1.0 allows remote attackers to execute arbitrary SQL c
23RISK
open ↗Referência✓ VexDay Proof
wPortfolio 0.3 - Arbitrary File Upload
Unrestricted file upload vulnerability in admin/upload_form.php in wPortfolio 0.3 and earlier allows remote attackers to
28RISK
open ↗Referência✓ VexDay Proof
Winamp 5.551 - MAKI Parsing Integer Overflow (PoC)
The Nullsoft Modern Skins Support module (gen_ff.dll) in Nullsoft Winamp before 5.552 allows remote attackers to execute
50RISK
open ↗Referência✓ VexDay Proof
Chilkat Crypt - ActiveX Arbitrary File Creation/Execution
Insecure method vulnerability in the ChilkatCrypt2.ChilkatCrypt2.1 ActiveX control (ChilkatCrypt2.dll 4.3.2.1) in Chilka
50RISK
open ↗Referência✓ VexDay Proof
Cisco Phone 7940 - Remote Denial of Service
Cisco IP Phone 7940 with firmware P0S3-08-7-00 allows remote attackers to cause a denial of service ("486 Busy" response
23RISK
open ↗Referência✓ VexDay Proof
AirvaeCommerce 3.0 - 'pid' SQL Injection
SQL injection vulnerability in index.php in Airvae Commerce 3.0 allows remote attackers to execute arbitrary SQL command
23RISK
open ↗Referência✓ VexDay Proof
Lightweight news portal (LNP) 1.0b - Multiple Vulnerabilities
Lightweight news portal (LNP) 1.0b does not properly restrict access to administrator functionality, which allows remote
23RISK
open ↗Referência✓ VexDay Proof
Winamp 5.551 - MAKI Parsing Integer Overflow
The Nullsoft Modern Skins Support module (gen_ff.dll) in Nullsoft Winamp before 5.552 allows remote attackers to execute
50RISK
open ↗Referência✓ VexDay Proof
TNT Forum 0.9.4 - Local File Inclusion
Directory traversal vulnerability in index.php in TNT Forum 0.9.4, when magic_quotes_gpc is disabled, allows remote atta
23RISK
open ↗Referência✓ VexDay Proof
Experts 1.0.0 - 'answer.php' SQL Injection
SQL injection vulnerability in answer.php in Experts 1.0.0, when magic_quotes_gpc is disabled, allows remote attackers t
23RISK
open ↗Referência✓ VexDay Proof
ASPPortal Free Version - 'Topic_Id' SQL Injection
SQL injection vulnerability in content/forums/reply.asp in ASPPortal allows remote attackers to execute arbitrary SQL co
23RISK
open ↗Referência✓ VexDay Proof
pSys 0.7.0.a - 'shownews' SQL Injection
SQL injection vulnerability in index.php in pSys 0.7.0 alpha allows remote attackers to execute arbitrary SQL commands v
23RISK
open ↗Referência✓ VexDay Proof
Yuhhu 2008 SuperStar - 'board' SQL Injection
SQL injection vulnerability in view.topics.php in Yuhhu Superstar 2008 allows remote attackers to execute arbitrary SQL
23RISK
open ↗Referência✓ VexDay Proof
OneCMS 2.4 - SQL Injection / Upload
Unrestricted file upload vulnerability in the add2 action in a_upload.php in OneCMS 2.4, and possibly earlier, allows re
23RISK
open ↗Referência✓ VexDay Proof
SyndeoCMS 2.6.0 - Local File Inclusion / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in Fred Stuurman SyndeoCMS 2.6.0 allows remote attackers to inject
23RISK
open ↗Referência✓ VexDay Proof
Discloser 0.0.4 - 'fileloc' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Bob Jewell Discloser 0.0.4 and earlier allow remote attackers to e
23RISK
open ↗Referência✓ VexDay Proof
Todd Woolums ASP News Management 2.2 - SQL Injection
SQL injection vulnerability in viewnews.asp in Todd Woolums ASP News Management 2.2 allows remote attackers to execute a
23RISK
open ↗Referência✓ VexDay Proof
Clean CMS 1.5 - Blind SQL Injection
SQL injection vulnerability in full_txt.php in Werner Hilversum Clean CMS 1.5 allows remote attackers to execute arbitra
23RISK
open ↗Referência✓ VexDay Proof
Clean CMS 1.5 - Blind SQL Injection / Cross-Site Scripting
SQL injection vulnerability in full_txt.php in Werner Hilversum Clean CMS 1.5 allows remote attackers to execute arbitra
23RISK
open ↗Referência✓ VexDay Proof
Foxit Reader 9.7.1 - Remote Command Execution (Javascript API)
Foxit Reader before 10.0 allows Remote Command Execution via the app.opencPDFWebPage JavsScript API. An attacker can exe
35RISK
open ↗Referência✓ VexDay Proof
phpBB All Topics Mod 1.5.0 - 'start' SQL Injection
SQL injection vulnerability in alltopics.php in the All Topics Hack 1.5.0 and earlier for phpBB 2.0.21 allows remote att
23RISK
open ↗Referência✓ VexDay Proof
Clean CMS 1.5 - Blind SQL Injection / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in full_txt.php in Werner Hilversum Clean CMS 1.5 allows remote attackers to in
23RISK
open ↗Referência✓ VexDay Proof
Booby 1.0.1 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Brim (formerly Booby) 1.0.1 allow remote attackers to execute arbi
35RISK
open ↗Referência✓ VexDay Proof
Socketmail 2.2.8 - 'fnc-readmail3.php' Remote File Inclusion
PHP remote file inclusion vulnerability in content/fnc-readmail3.php in SocketMail 2.2.8 allows remote attackers to exec
23RISK
open ↗Referência✓ VexDay Proof
VideoGirls BiZ - Blind SQL Injection
SQL injection vulnerability in view_snaps.php in VideoGirls BiZ allows remote attackers to execute arbitrary SQL command
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component AgoraGroup 0.3.5.3 - Blind SQL Injection
SQL injection vulnerability in the JoomlaMe AgoraGroups (aka AG or com_agoragroup) component 0.3.5.3 for Joomla! allows
23RISK
open ↗Referência✓ VexDay Proof
WebStudio eHotel - Blind SQL Injection
SQL injection vulnerability in index.php in WebStudio eHotel allows remote attackers to execute arbitrary SQL commands v
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.