Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,460Referência 22,832GitHub PoC 14,991VulnCheck XDB 8,829Nuclei 4,357Metasploit 3,489✓ verified onlyrecentpopularrisk
19,066 exploits
Exploit-DB✓ VexDay Proof
Paid To Read Script 2.0.5 - 'uid' / 'fnum' / 'fn' SQL Injection
Paid To Read Script 2.0.5 has SQL Injection via the admin/userview.php uid parameter, the admin/viewemcamp.php fnum para
23RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component JEXTN Video Gallery 3.0.5 - 'id' SQL Injection
The JEXTN Video Gallery extension 3.0.5 for Joomla! has SQL Injection via the id parameter in a view=category action.
23RISK
open ↗Exploit-DB✓ VexDay Proof
GNU C Library Dynamic Loader glibc ld.so - Memory Leak / Buffer Overflow
A memory leak in glibc 2.1.1 (released on May 24, 1999) can be reached and amplified through the LD_HWCAP_MASK environme
23RISK
open ↗Exploit-DB✓ VexDay Proof
GNU C Library Dynamic Loader glibc ld.so - Memory Leak / Buffer Overflow
A buffer overflow in glibc 2.5 (released on September 29, 2006) and can be triggered through the LD_LIBRARY_PATH environ
23RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component JEXTN Question And Answer 3.1.0 - SQL Injection
The "JEXTN Question And Answer" extension 3.1.0 for Joomla! has SQL Injection via the an parameter in a view=tags action
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple macOS - Kernel Code Execution due to Lack of Bounds Checking in AppleIntelCapriController::GetLinkConfig
An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "Intel Graph
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple macOS/iOS - Kernel Double Free due to Incorrect API Usage in Flow Divert Socket Option Handling
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple XNU Kernel - Memory Corruption due to Integer Overflow in __offsetof Usage in posix_spawn on 32-bit Platforms
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple macOS/iOS - Multiple Kernel Use-After-Frees due to Incorrect IOKit Object Lifetime Management in IOTimeSyncClockManagerUserClient
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. The is
23RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component JBuildozer 1.4.1 - 'appid' SQL Injection
The JBuildozer extension 1.4.1 for Joomla! has SQL Injection via the appid parameter in an entriessearch action.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Multiplex Movie Theater Booking Script 3.1.5 - 'moid' / 'eid' SQL Injection
Multiplex Movie Theater Booking Script 3.1.5 has SQL Injection via the trailer-detail.php moid parameter, show-time.php
23RISK
open ↗Exploit-DB✓ VexDay Proof
Multireligion Responsive Matrimonial 4.7.2 - 'succid' SQL Injection
Multireligion Responsive Matrimonial 4.7.2 has SQL Injection via the success-story.php succid parameter.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple macOS - 'necp_get_socket_attributes' so_pcb Type Confusion
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RISK
open ↗Exploit-DB✓ VexDay Proof
Laundry Booking Script 1.0 - 'list?city' SQL Injection
Laundry Booking Script 1.0 has SQL Injection via the /list city parameter.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Resume Clone Script 2.0.5 - SQL Injection
Resume Clone Script 2.0.5 has SQL Injection via the preview.php id parameter.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Foodspotting Clone Script 1.0 - 'quicksearch.php?q' SQL Injection
Foodspotting Clone Script 1.0 has SQL Injection via the quicksearch.php q parameter.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Car Rental Script 2.0.4 - 'val' SQL Injection
Car Rental Script 2.0.4 has SQL Injection via the countrycode1.php val parameter.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Advanced Real Estate Script 4.0.7 - SQL Injection
Advanced Real Estate Script 4.0.7 has SQL Injection via the search-results.php Projectmain, proj_type, searchtext, sell_
23RISK
open ↗Exploit-DB✓ VexDay Proof
Vanguard 1.4 - SQL Injection
Vanguard Marketplace Digital Products PHP 1.4 has SQL Injection via the PATH_INFO to the /p URI.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple macOS - 'getrusage' Stack Leak Through struct Padding
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RISK
open ↗Exploit-DB✓ VexDay Proof
Kickstarter Clone Acript 2.0 - 'projid' SQL Injection
Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Single Theater Booking Script 3.2.1 - 'findcity.php?q' SQL Injection
Single Theater Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Food Order Script 1.0 - 'list?city' SQL Injection
Food Order Script 1.0 has SQL Injection via the /list city parameter.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Responsive Events & Movie Ticket Booking Script 3.2.1 - 'findcity.php?q' SQL Injection
Responsive Events And Movie Ticket Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Online Exam Test Application Script 1.6 - 'exams.php?sort' SQL Injection
Online Exam Test Application Script 1.6 has SQL Injection via the exams.php sort parameter.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Opensource Classified Ads Script 3.2 - SQL Injection
Opensource Classified Ads Script 3.2 has SQL Injection via the advance_result.php keyword parameter.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Readymade Video Sharing Script 3.2 - SQL Injection
Readymade Video Sharing Script 3.2 has SQL Injection via the single-video-detail.php report_videos array parameter.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Secure E-commerce Script 2.0.1 - 'searchcat' / 'searchmain' SQL Injection
Secure E-commerce Script 2.0.1 has SQL Injection via the category.php searchmain or searchcat parameter, or the single_d
23RISK
open ↗Exploit-DB✓ VexDay Proof
Responsive Realestate Script 3.2 - 'property-list?tbud' SQL Injection
Responsive Realestate Script 3.2 has SQL Injection via the property-list tbud parameter.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Readymade PHP Classified Script 3.3 - 'subctid' / 'mctid' SQL Injection
Readymade PHP Classified Script 3.3 has SQL Injection via the /categories subctid or mctid parameter.
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.