Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,460Referência 22,832GitHub PoC 14,991VulnCheck XDB 8,829Nuclei 4,357Metasploit 3,489✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
DM Guestbook 0.4.1 - Multiple Local File Inclusions
Multiple directory traversal vulnerabilities in DM Guestbook 0.4.1 and earlier allow remote attackers to include and exe
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component com_school 1.4 - 'classid' SQL Injection
SQL injection vulnerability in the ComSchool (com_school) component 1.4 for Joomla! allows remote attackers to execute a
23RISK
open ↗Referência✓ VexDay Proof
nuBoard 0.5 - 'site' Remote File Inclusion
PHP remote file inclusion vulnerability in admin/index.php in nuBoard 0.5 allows remote attackers to execute arbitrary P
35RISK
open ↗Referência✓ VexDay Proof
Cold BBS - Remote Database Disclosure
Cold BBS stores sensitive information under the web root with insufficient access control, which allows remote attackers
23RISK
open ↗Referência✓ VexDay Proof
NCTAudioStudio2 - ActiveX DLL 2.6.1.148 'CreateFile()'/ Insecure Method
A certain ActiveX control in NCTWavChunksEditor2.dll 2.6.1.148 in NCTAudioStudio (NCTAudioStudio2) 2.7, as used by Sienz
35RISK
open ↗Referência✓ VexDay Proof
ASPTicker 1.0 - Remote Database Disclosure
ASPTicker 1.0 stores sensitive information under the web root with insufficient access control, which allows remote atta
23RISK
open ↗Referência✓ VexDay Proof
My Simple Forum 3.0 - Local File Inclusion
Directory traversal vulnerability in index.php in My Simple Forum 3.0 and 4.1, when magic_quotes_gpc is disabled, allows
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component com_colorlab 1.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in admin.color.php in the com_colorlab (aka com_color) 1.0 component for Joomla!
35RISK
open ↗Referência✓ VexDay Proof
MyCars Automotive - Authentication Bypass
SQL injection vulnerability in admin/index.php in Jared Eckersley MyCars, when magic_quotes_gpc is disabled, allows remo
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component JMovies 1.1 - 'id' SQL Injection
SQL injection vulnerability in the JMovies (aka JM or com_jmovies) component 1.1 for Joomla! allows remote attackers to
23RISK
open ↗Referência✓ VexDay Proof
ASP AutoDealer - Remote Database Disclosure
ASP AutoDealer stores sensitive information under the web root with insufficient access control, which allows remote att
23RISK
open ↗Referência✓ VexDay Proof
Microsoft Visual Studio 6.0 - 'PDWizard.ocx' Remote Command Execution
A certain ActiveX control in PDWizard.ocx 6.0.0.9782 and earlier in Microsoft Visual Studio 6.0 exposes dangerous (1) St
35RISK
open ↗Referência✓ VexDay Proof
GuppY 4.6.3 - 'index.php?selskin' Remote File Inclusion
Directory traversal vulnerability in inc/includes.inc in GuppY 4.6.3 allows remote attackers to include and execute arbi
23RISK
open ↗Referência✓ VexDay Proof
ASP AutoDealer - SQL Injection / File Disclosure
ASP AutoDealer stores sensitive information under the web root with insufficient access control, which allows remote att
23RISK
open ↗Referência✓ VexDay Proof
XOOPS Module XT-Conteudo - 'spaw_root' Remote File Inclusion
PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the XT-Conteudo module for XOOPS allows
35RISK
open ↗Referência✓ VexDay Proof
WholeHogSoftware Ware Support - Insecure Cookie Handling
Whole Hog Ware Support 1.x allows remote attackers to bypass authentication and obtain administrative access via an inte
23RISK
open ↗Referência✓ VexDay Proof
PHP::HTML 0.6.4 - 'PHPhtml.php' Remote File Inclusion
PHP remote file inclusion vulnerability in phphtml.php in Idan Sofer PHP::HTML 0.6.4 allows remote attackers to execute
35RISK
open ↗Referência✓ VexDay Proof
virtue news - SQL Injection / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in news_detail.php in Virtue News Manager allows remote attackers to inject arb
23RISK
open ↗Referência✓ VexDay Proof
GuppY 4.5.16 - Remote Command Execution
Directory traversal vulnerability in error.php in GuppY 4.6.3, 4.5.16, and earlier allows remote attackers to include an
23RISK
open ↗Referência✓ VexDay Proof
Fuzzylime Forum 1.0 - 'low.php?topic' SQL Injection
Cross-site scripting (XSS) vulnerability in low.php in Fuzzylime Forum 1.0 allows remote attackers to inject arbitrary w
23RISK
open ↗Referência✓ VexDay Proof
XOOPS Module horoscope 2.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in footer.php in the Horoscope 1.0 module for XOOPS allows remote attackers to e
45RISK
open ↗Referência✓ VexDay Proof
Microsoft Windows Mobile 6.0 - Device Long Name Remote Reboot (Denial of Service)
Microsoft Windows Mobile 6.0 on HTC Wiza 200 and HTC MDA 8125 devices does not properly handle the first attempt to esta
35RISK
open ↗Referência✓ VexDay Proof
Profense Web Application Firewall 2.6.2 - Cross-Site Request Forgery / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in proxy.html in Profense Web Application Firewall 2.6.2 and 2.6.3 allows remot
23RISK
open ↗Referência✓ VexDay Proof
xoops module tinycontent 1.5 - Remote File Inclusion
PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the TinyContent 1.5 module for XOOPS all
35RISK
open ↗Referência✓ VexDay Proof
tbdev 01-01-2008 - Multiple Vulnerabilities
Multiple open redirect vulnerabilities in TBDev.NET 01-01-08 allow remote attackers to redirect users to arbitrary web s
23RISK
open ↗Referência✓ VexDay Proof
Roundcube Webmail 0.2-3 Beta - Code Execution
html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail)
35RISK
open ↗Referência✓ VexDay Proof
XM Easy Personal FTP Server 5.6.0 - Remote Denial of Service
XM Easy Personal FTP Server 5.6.0 allows remote authenticated users to cause a denial of service via a crafted argument
50RISK
open ↗Referência✓ VexDay Proof
PHPMyInventory 2.8 - 'global.inc.php' Remote File Inclusion
PHP remote file inclusion vulnerability in Includes/global.inc.php in phpMyInventory 2.8 allows remote attackers to exec
23RISK
open ↗Referência✓ VexDay Proof
campus virtual-lms - Cross-Site Scripting / SQL Injection
Multiple cross-site request forgery (CSRF) vulnerabilities in Campus Virtual-LMS allow (1) remote attackers to hijack th
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component flash fun! 1.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in admin.joomlaflashfun.php in the Flash Fun! (com_joomlaflashfun) 1.0 component
28RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.