Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,012cataloged exploits
35,274CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,446Referência 22,166GitHub PoC 14,072VulnCheck XDB 8,604Nuclei 4,251Metasploit 3,473✓ verified onlyrecentpopularrisk
21,899 exploits
Referência✓ VexDay Proof
Oceandir 2.9 - 'show_vote.php' SQL Injection
SQL injection vulnerability in show_vote.php in Oceandir 2.9 and earlier allows remote attackers to execute arbitrary SQ
23RISK
open ↗Referência✓ VexDay Proof
easyLink 1.1.0 - 'detail.php' SQL Injection
SQL injection vulnerability in detail.php in MountainGrafix easyLink 1.1.0 allows remote attackers to execute arbitrary
23RISK
open ↗Referência
CVE-2014-6030
Multiple SQL injection vulnerabilities in ClassApps SelectSurvey.NET before 4.125.002 allow (1) remote attackers to exec
23RISK
open ↗Referência✓ VexDay Proof
Blogator-script 0.95 - Change User Password
_blogadata/include/init_pass2.php in Blogator-script 0.95 allows remote attackers to change the password for arbitrary u
23RISK
open ↗Referência✓ VexDay Proof
Drake CMS 0.4.11 - Blind SQL Injection
SQL injection vulnerability in the guestbook component (components/guestbook/guestbook.php) in Drake CMS 0.4.11 and earl
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component versioning 1.0.2 - 'id' SQL Injection
SQL injection vulnerability in the Versioning component (com_versioning) 1.0.2 in Joomla! and Mambo allows remote attack
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component Flash Tree Gallery 1.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in admin.treeg.php in the Flash Tree Gallery (com_treeg) component 1.0 for Jooml
28RISK
open ↗Referência✓ VexDay Proof
Mole Group Taxi Calc Dist Script - Authentication Bypass
SQL injection vulnerability in login.php in Mole Group Taxi Map Script (aka Taxi Calc Dist Script) allows remote attacke
23RISK
open ↗Referência✓ VexDay Proof
Quake 3 Engine Client - 'CG_ServerCommand()' Remote Overflow
Stack-based buffer overflow in the CG_ServerCommand function in Quake 3 Engine as used by Soldier of Fortune 2 (SOF2MP)
23RISK
open ↗Referência✓ VexDay Proof
SoftComplex PHP Image Gallery - 'ctg' SQL Injection
SQL injection vulnerability in index.php in SoftComplex PHP Image Gallery allows remote attackers to execute arbitrary S
23RISK
open ↗Referência✓ VexDay Proof
DigiAffiliate 1.4 - Authentication Bypass
Multiple SQL injection vulnerabilities in login.asp in Digiappz DigiAffiliate 1.4 and earlier allow remote attackers to
23RISK
open ↗Referência✓ VexDay Proof
SoftComplex PHP Image Gallery 1.0 - Authentication Bypass
SQL injection vulnerability in index.php in SoftComplex PHP Image Gallery 1.0 allows remote attackers to execute arbitra
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component MyAlbum 1.0 - 'album' SQL Injection
SQL injection vulnerability in MyAlbum component (com_myalbum) 1.0 for Joomla! allows remote attackers to execute arbitr
23RISK
open ↗Referência✓ VexDay Proof
FLABER 1.1 RC1 - Remote Command Execution
function/update_xml.php in FLABER 1.1 and earlier allows remote attackers to overwrite arbitrary files by specifying the
23RISK
open ↗Referência✓ VexDay Proof
Easy News Content Management - Database Disclosure
Easy Content Management Publishing stores sensitive information under the web root with insufficient access control, whi
23RISK
open ↗Referência✓ VexDay Proof
ASP User Engine .NET - Remote Database Disclosure
ASP User Engine.NET stores sensitive information under the web root with insufficient access control, which allows remot
23RISK
open ↗Referência✓ VexDay Proof
XAMPP 1.6.8 - Cross-Site Request Forgery (Change Administrative Password)
security/xamppsecurity.php in XAMPP 1.6.8 performs an extract operation on the SERVER superglobal array, which allows re
23RISK
open ↗Referência✓ VexDay Proof
Andy's PHP KnowledgeBase 0.92.9 - Arbitrary File Upload
Unrestricted file upload vulnerability in saa.php in Andy's PHP Knowledgebase (aphpkb) 0.92.9 allows remote attackers to
23RISK
open ↗Referência✓ VexDay Proof
VidiScript (Avatar) - Arbitrary File Upload
Unrestricted file upload vulnerability in the profile feature in VidiScript allows registered remote authenticated users
23RISK
open ↗Referência✓ VexDay Proof
Xitami Web Server 2.5c2 - LRWP Processing Format String (PoC)
Format string vulnerability in Xitami Web Server 2.2a through 2.5c2, and possibly other versions, allows remote attacker
23RISK
open ↗Referência✓ VexDay Proof
OpenInvoice 0.9 - Arbitrary Change User Password
auth.php in openInvoice 0.90 beta and earlier allows remote attackers to bypass authentication and gain privileges by se
23RISK
open ↗Referência✓ VexDay Proof
GO4I.NET ASP Forum 1.0 - SQL Injection
SQL injection vulnerability in forum.asp in GO4I.NET ASP Forum 1.0 allows remote attackers to execute arbitrary SQL comm
23RISK
open ↗Referência✓ VexDay Proof
TmaxSoft JEUS - Alternate Data Streams File Disclosure
NTFS TmaxSoft JEUS 5 before Fix 26 allows remote attackers to read the source code for scripts by appending ::$DATA to t
23RISK
open ↗Referência✓ VexDay Proof
PayPal eStore - Admin Password Change
admin/settings.php in PayPal eStores allows remote attackers to bypass intended access restrictions and change the admin
23RISK
open ↗Referência
CVE-2009-4549
Stack-based buffer overflow in A2 Media Player Pro 2.51 allows remote attackers to execute arbitrary code via a long str
23RISK
open ↗Referência✓ VexDay Proof
PhpAddEdit 1.3 - 'cookie' Authentication Bypass
login.php in PhpAddEdit 1.3 allows remote attackers to bypass authentication and gain administrative access by setting t
23RISK
open ↗Referência✓ VexDay Proof
Miniweb 2.0 - Authentication Bypass
SQL injection vulnerability in index.php in Miniweb 2.0 allows remote attackers to execute arbitrary SQL commands via th
23RISK
open ↗Referência✓ VexDay Proof
LightNEasy sqlite / no database 1.2.2 - Multiple Vulnerabilities
thumbsup.php in Thumbs-Up 1.12, as used in LightNEasy "no database" (aka flat) and SQLite 1.2.2 and earlier, allows remo
23RISK
open ↗Referência✓ VexDay Proof
PicoFlat CMS 0.5.9 (Windows) - Local File Inclusion
Directory traversal vulnerability in index.php in PicoFlat CMS 0.5.9 allows remote attackers to include and execute arbi
23RISK
open ↗Referência✓ VexDay Proof
2WIRE DSL Router - 'xslt' Denial of Service
Cross-site request forgery (CSRF) vulnerability in the xslt script in the web-based management interface on the 2wire 17
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.