Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,020cataloged exploits
35,276CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,446Referência 22,166GitHub PoC 14,080VulnCheck XDB 8,604Nuclei 4,251Metasploit 3,473✓ verified onlyrecentpopularrisk
22,103 exploits
Referência✓ VexDay Proof
MindDezign Photo Gallery 2.2 - SQL Injection
SQL injection vulnerability in MindDezign Photo Gallery 2.2, when magic_quotes_gpc is disabled, allows remote attackers
23RISK
open ↗Referência✓ VexDay Proof
MindDezign Photo Gallery 2.2 - Arbitrary Add Admin
SQL injection vulnerability in MindDezign Photo Gallery 2.2 allows remote attackers to execute arbitrary SQL commands vi
23RISK
open ↗Referência✓ VexDay Proof
PumpKIN TFTP Server 2.7.2.0 - Denial of Service (Metasploit)
PumpKIN TFTP Server 2.7.2.0 allows remote attackers to cause a denial of service via a write request with a long mode fi
23RISK
open ↗Referência✓ VexDay Proof
Vibro-School-CMS - 'nID' SQL Injection
SQL injection vulnerability in view_news.php in nicLOR Vibro-School-CMS allows remote attackers to execute arbitrary SQL
23RISK
open ↗Referência✓ VexDay Proof
PHPwebnews 0.2 MySQL Edition - 'id_kat' SQL Injection
SQL injection vulnerability in index.php in phpWebNews 0.2 MySQL Edition allows remote attackers to execute arbitrary SQ
23RISK
open ↗Referência✓ VexDay Proof
Lanifex DMO 2.3b - '_incMgr' Remote File Inclusion
PHP remote file inclusion vulnerability in LFXlib/access_manager.php in Lanifex Database of Managed Objects (DMO) 2.3 Be
23RISK
open ↗Referência✓ VexDay Proof
Mambo Component SimpleBoard 1.0.1 - Arbitrary File Upload
Unrestricted file upload vulnerability in image_upload.php in the SimpleBoard (com_simpleboard) component 1.0.1 and earl
23RISK
open ↗Referência✓ VexDay Proof
A-Link WL54AP3 / WL54AP2 - Cross-Site Request Forgery / Cross-Site Scripting
The management interface on the A-LINK WL54AP3 and WL54AP2 access points has a blank default password for the admin acco
23RISK
open ↗Referência✓ VexDay Proof
PHP-revista 1.1.2 - Remote File Inclusion / SQL Injection / Authentication Bypass / Cross-Site Scripting
PHP remote file inclusion vulnerability in index.php in Longino Jacome php-Revista 1.1.2 allows remote attackers to exec
23RISK
open ↗Referência✓ VexDay Proof
PHP-revista 1.1.2 - Remote File Inclusion / SQL Injection / Authentication Bypass / Cross-Site Scripting
Multiple SQL injection vulnerabilities in Longino Jacome php-Revista 1.1.2 allow remote attackers to execute arbitrary S
23RISK
open ↗Referência✓ VexDay Proof
GrapAgenda 0.1 - 'page' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in GrapAgenda 0.11 and earlier, when register_globals is enabled, a
23RISK
open ↗Referência✓ VexDay Proof
BinGo News 3.01 - 'bnrep' Remote File Inclusion
PHP remote file inclusion vulnerability in bp_ncom.php in BinGo News (BP News) 3.01 and earlier allows remote attackers
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component DBQuery 1.4.1.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in the Green Mountain Information Technology and Consulting Database Query (com_
23RISK
open ↗Referência✓ VexDay Proof
Pluck CMS 4.6.1 - 'module_pages_site.php' Local File Inclusion
Directory traversal vulnerability in data/modules/blog/module_pages_site.php in Pluck 4.6.1 allows remote attackers to i
23RISK
open ↗Referência✓ VexDay Proof
phpGreetCards - Cross-Site Scripting / Arbitrary File Upload
Cross-site scripting (XSS) vulnerability in index.php in phpGreetCards 3.7 allows remote attackers to inject arbitrary w
23RISK
open ↗Referência✓ VexDay Proof
phpGreetCards - Cross-Site Scripting / Arbitrary File Upload
Unrestricted file upload vulnerability in index.php in phpGreetCards 3.7 allows remote attackers to execute arbitrary PH
23RISK
open ↗Referência✓ VexDay Proof
PHPLD 3.3 - Blind SQL Injection
SQL injection vulnerability in page.php in PHP Link Directory (phpLD) 3.3, when register_globals is enabled and magic_qu
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component Ice Gallery 0.5b2 - 'catid' Blind SQL Injection
SQL injection vulnerability in the Ice Gallery (com_ice) component 0.5 beta 2 for Joomla! allows remote attackers to exe
23RISK
open ↗Referência✓ VexDay Proof
CMS NetCat 3.0/3.12 - Blind SQL Injection
SQL injection vulnerability in modules/poll/index.php in AIST NetCat 3.0 and 3.12 allows remote attackers to execute arb
23RISK
open ↗Referência✓ VexDay Proof
Absolute News Feed 1.0 - Remote Insecure Cookie Handling
Xigla Software Absolute News Feed 1.0 and possibly 1.5 allows remote attackers to bypass authentication and gain adminis
23RISK
open ↗Referência✓ VexDay Proof
Absolute News Manager 5.1 - Insecure Cookie Handling
Xigla Software Absolute News Manager.NET 5.1 allows remote attackers to bypass authentication and gain administrative ac
23RISK
open ↗Referência✓ VexDay Proof
Absolute Podcast 1.0 - Remote Insecure Cookie Handling
Absolute Podcast .NET 1.0 allows remote attackers to bypass authentication and gain administrative access by setting a c
23RISK
open ↗Referência✓ VexDay Proof
Absolute Poll Manager XE 4.1 - Insecure Cookie Handling
Xigla Software Absolute Poll Manager XE 4.1 allows remote attackers to bypass authentication and gain administrative acc
23RISK
open ↗Referência
CVE-2008-6887
SQL injection vulnerability in detailad.asp in Pre Classified Listings 1.0 allows remote attackers to execute arbitrary
23RISK
open ↗Referência✓ VexDay Proof
Getleft 1.2 - Remote Buffer Overflow (PoC)
Multiple buffer overflows in Getleft.exe in Andres Garcia Getleft 1.2 allow remote attackers to cause a denial of servic
23RISK
open ↗Referência
CVE-2008-6898
Buffer overflow in the XHTTP Module 4.1.0.0 in the ActiveX control for SaschArt SasCam Webcam Server 2.6.5 allows remote
50RISK
open ↗Referência✓ VexDay Proof
SasCam WebCam Server 2.6.5 - ActiveX Remote Buffer Overflow
Buffer overflow in the XHTTP Module 4.1.0.0 in the ActiveX control for SaschArt SasCam Webcam Server 2.6.5 allows remote
50RISK
open ↗Referência✓ VexDay Proof
AvailScript Article Script - Arbitrary File Upload
Unrestricted file upload vulnerability in "Add Pen/Author Name" feature in addpen.php in AvailScript Article Script allo
23RISK
open ↗Referência✓ VexDay Proof
2532/Gigs 1.2.2 Stable - Multiple Vulnerabilities
Unrestricted file upload vulnerability in upload_flyer.php in 2532designs 2532|Gigs 1.2.2 Stable allows remote attackers
23RISK
open ↗Referência✓ VexDay Proof
BabbleBoard 1.1.6 - Cross-Site Request Forgery/Cookie Grabber
Cross-site request forgery (CSRF) vulnerability in index.php in BabbleBoard 1.1.6 allows remote authenticated users to h
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.