Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,460Referência 22,832GitHub PoC 14,991VulnCheck XDB 8,829Nuclei 4,357Metasploit 3,489✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
yahoo answers - 'id' SQL Injection
SQL injection vulnerability in index.php in PHPStore Yahoo Answers allows remote attackers to execute arbitrary SQL comm
23RISK
open ↗Referência✓ VexDay Proof
SlimCMS 1.0.0 - 'edit.php' SQL Injection
SQL injection vulnerability in edit.php in SlimCMS 1.0.0 and earlier allows remote attackers to execute arbitrary SQL co
23RISK
open ↗Referência✓ VexDay Proof
VeryPDF PDFView - OCX ActiveX OpenPDF Heap Overflow (PoC)
Heap-based buffer overflow in the PDFVIEW.PdfviewCtrl.1 ActiveX control in pdfview.ocx 2.0.0.1 in VeryDOC PDF Viewer OCX
50RISK
open ↗Referência✓ VexDay Proof
PHPstore Wholesale - 'id' SQL Injection
SQL injection vulnerability in track.php in PHPStore Wholesales (aka Wholesale) allows remote attackers to execute arbit
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component Contact Info 1.0 - SQL Injection
SQL injection vulnerability in the Contact Information Module (com_contactinfo) component 1.0 for Joomla! allows remote
23RISK
open ↗Referência✓ VexDay Proof
PozScripts Business Directory Script - 'cid' SQL Injection
SQL injection vulnerability in showcategory.php in PozScripts Business Directory Script allows remote attackers to execu
23RISK
open ↗Referência✓ VexDay Proof
Apache Geronimo 2.1.3 - Multiple Directory Traversal Vulnerabilities
Multiple directory traversal vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1
35RISK
open ↗Referência✓ VexDay Proof
postecards - SQL Injection / File Disclosure
SQL injection vulnerability in sendcard.cfm in PostEcards allows remote attackers to execute arbitrary SQL commands via
23RISK
open ↗Referência✓ VexDay Proof
postecards - SQL Injection / File Disclosure
PostEcards stores sensitive information under the web root with insufficient access control, which allows remote attacke
23RISK
open ↗Referência✓ VexDay Proof
Netref 4.0 - Multiple SQL Injections
SQL injection vulnerability in Netref 4.0 allows remote attackers to execute arbitrary SQL commands via the id parameter
23RISK
open ↗Referência✓ VexDay Proof
DL PayCart 1.34 - Admin Password Changing
Cross-site request forgery (CSRF) vulnerability in admin/settings.php in DL PayCart 1.34 and earlier allows remote attac
23RISK
open ↗Referência✓ VexDay Proof
Bonza Cart 1.10 - Admin Password Changing
Cross-site request forgery (CSRF) vulnerability in admin/ad_settings.php in Bonza Cart 1.10 and earlier allows remote at
23RISK
open ↗Referência✓ VexDay Proof
Mambo Component SOBI2 RC 2.8.2 - SQL Injection
SQL injection vulnerability in the Sigsiu Online Business Index 2 (SOBI2, com_sobi2) RC 2.8.2 component for Joomla! and
23RISK
open ↗Referência✓ VexDay Proof
Professional Download Assistant 0.1 - Authentication Bypass
SQL injection vulnerability in admin/login.asp in Professional Download Assistant 0.1 allows remote attackers to execute
23RISK
open ↗Referência✓ VexDay Proof
Trend Micro OfficeScan - ObjRemoveCtrl ActiveX Control Buffer Overflow
Buffer overflow in the ObjRemoveCtrl Class ActiveX control in OfficeScanRemoveCtrl.dll 7.3.0.1020 in Trend Micro OfficeS
35RISK
open ↗Referência✓ VexDay Proof
Professional Download Assistant 0.1 - Database Disclosure
Professional Download Assistant 0.1 stores sensitive information under the web root with insufficient access control, wh
23RISK
open ↗Referência✓ VexDay Proof
PLE CMS 1.0 Beta 4.2 - Blind SQL Injection
SQL injection vulnerability in login.php in Pre Lecture Exercises (PLEs) CMS 1.0 beta 4.2 allows remote attackers to exe
23RISK
open ↗Referência✓ VexDay Proof
sCssBoard (Multiple Versions) - 'pwnpack' Remote s
Multiple SQL injection vulnerabilities in index.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allow remote attackers to exec
23RISK
open ↗Referência✓ VexDay Proof
Nukedit 4.9.x - Remote Create Admin
SQL injection vulnerability in utilities/login.asp in Nukedit 4.9.x, and possibly earlier, allows remote attackers to ex
23RISK
open ↗Referência✓ VexDay Proof
lcxbbportal 0.1 alpha 2 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in lcxBBportal 0.1 Alpha 2 allow remote attackers to execute arbitrar
23RISK
open ↗Referência✓ VexDay Proof
Netartmedia Car Portal 1.0 - Authentication Bypass
SQL injection vulnerability in the login feature in NetArt Media Car Portal 1.0 allows remote attackers to execute arbit
23RISK
open ↗Referência✓ VexDay Proof
RankEm - 'siteID' SQL Injection
SQL injection vulnerability in rankup.asp in Katy Whitton RankEm allows remote attackers to execute arbitrary SQL comman
23RISK
open ↗Referência✓ VexDay Proof
GOM Player 2.1.6.3499 - 'GomWeb3.dll 1.0.0.12' Remote Overflow
Buffer overflow in the GomManager (GomWeb Control) ActiveX control in GomWeb3.dll 1.0.0.12 in Gretech Online Movie Playe
60RISK
open ↗Referência✓ VexDay Proof
Rankem - Authentication Bypass
SQL injection vulnerability in processlogin.asp in Katy Whitton RankEm allows remote attackers to execute arbitrary SQL
23RISK
open ↗Referência✓ VexDay Proof
Product Sale Framework 0.1b - SQL Injection
SQL injection vulnerability in customer.forumtopic.php in Kalptaru Infotech Product Sale Framework 0.1 beta allows remot
23RISK
open ↗Referência✓ VexDay Proof
nightfall personal diary 1.0 - Cross-Site Scripting / File Disclosure
Cross-site scripting (XSS) vulnerability in login.asp in Nightfall Personal Diary 1.0 allows remote attackers to inject
23RISK
open ↗Referência✓ VexDay Proof
Elecard AVC HD player - '.m3u' / '.xpl' Local Stack Overflow (PoC)
Stack-based buffer overflow in Elecard AVC HD PLAYER 5.5.90116 allows remote attackers to execute arbitrary code via an
23RISK
open ↗Referência✓ VexDay Proof
ASP AutoDealer - SQL Injection / File Disclosure
SQL injection vulnerability in detail.asp in ASP AutoDealer allows remote attackers to execute arbitrary SQL commands vi
23RISK
open ↗Referência✓ VexDay Proof
Microsoft Windows - '.doc' Malformed Pointers Denial of Service
Microsoft Windows Explorer on Windows 2000 SP4 FR and XP SP2 FR, and possibly other versions and platforms, allows remot
35RISK
open ↗Referência✓ VexDay Proof
Ikon ADManager 2.1 - Remote Database Disclosure
Ikon AdManager 2.1 and earlier stores sensitive information under the web root with insufficient access control, which a
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.