Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,794cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,459Referência 22,721GitHub PoC 14,946VulnCheck XDB 8,829Nuclei 4,350Metasploit 3,489✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
Microsoft Works 7 - 'WkImgSrv.dll' ActiveX Remote Buffer Overflow
A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and
50RISK
open ↗Referência✓ VexDay Proof
Borland Interbase 2007 - 'ibserver.exe' Buffer Overflow (PoC)
Stack-based buffer overflow in the database service (ibserver.exe) in Borland InterBase 2007 SP2 allows remote attackers
23RISK
open ↗Referência✓ VexDay Proof
pNews 2.08 - 'shownews' SQL Injection
SQL injection vulnerability in index.php in Powie pNews 2.08 and 2.10, when magic_quotes_gpc is disabled, allows remote
23RISK
open ↗Referência✓ VexDay Proof
LaserNet CMS 1.5 - SQL Injection
SQL injection vulnerability in index.php in Lasernet CMS 1.5 and 1.11, when magic_quotes_gpc is disabled, allows remote
23RISK
open ↗Referência✓ VexDay Proof
BlogWorx 1.0 - 'id' SQL Injection
SQL injection vulnerability in view.asp in DevWorx BlogWorx 1.0 allows remote attackers to execute arbitrary SQL command
23RISK
open ↗Referência✓ VexDay Proof
5th Avenue Shopping Cart - 'category_id' SQL Injection
SQL injection vulnerability in store_pages/category_list.php in 5th Avenue Shopping Cart 1.2 trial edition allows remote
23RISK
open ↗Referência✓ VexDay Proof
Galatolo Web Manager 1.0 - Cross-Site Scripting / Local File Inclusion
Multiple directory traversal vulnerabilities in Galatolo WebManager (GWM) 1.0 allow remote attackers to include and exec
23RISK
open ↗Referência✓ VexDay Proof
PreProject Multi-Vendor Shopping Malls - Multiple Vulnerabilities
SQL injection vulnerability in buyer_detail.php in Pre Multi-Vendor Shopping Malls allows remote attackers to execute ar
23RISK
open ↗Referência✓ VexDay Proof
Zune Software - ActiveX Arbitrary File Overwrite
Absolute path traversal vulnerability in a certain ActiveX control in Zune allows user-assisted remote attackers to over
28RISK
open ↗Referência✓ VexDay Proof
Crazy Goomba 1.2.1 - 'id' SQL Injection
SQL injection vulnerability in commentaires.php in Crazy Goomba 1.2.1 allows remote attackers to execute arbitrary SQL c
23RISK
open ↗Referência✓ VexDay Proof
Classifieds Caffe - 'cat_id' SQL Injection
SQL injection vulnerability in index.php in Classifieds Caffe allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗Referência✓ VexDay Proof
Web Calendar 4.1 - Blind SQL Injection
SQL injection vulnerability in one_day.php in Web Calendar Pro 4.1 and earlier allows remote attackers to execute arbitr
23RISK
open ↗Referência✓ VexDay Proof
TR News 2.1 - 'nb' SQL Injection
SQL injection vulnerability in news.php in Tr Script News 2.1 allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗Referência✓ VexDay Proof
SFS EZ Webstore - 'where' SQL Injection
SQL injection vulnerability in SearchResults.php in Scripts For Sites (SFS) EZ e-store allows remote attackers to execut
23RISK
open ↗Referência✓ VexDay Proof
TR News 2.1 - 'nb' SQL Injection
Unrestricted file upload vulnerability in the ajout_cat mode in admin/main.php in Tr Script News 2.1 allows remote authe
23RISK
open ↗Referência✓ VexDay Proof
Jadu Galaxies - 'categoryId' Blind SQL Injection
SQL injection vulnerability in scripts/documents.php in Jadu Galaxies allows remote attackers to execute arbitrary SQL c
23RISK
open ↗Referência✓ VexDay Proof
WordPress Plugin wordTube 1.43 - 'wpPATH' Remote File Inclusion
PHP remote file inclusion vulnerability in wordtube-button.php in the wordTube 1.43 and earlier plugin for WordPress, wh
35RISK
open ↗Referência✓ VexDay Proof
WordPress Plugin wp-Table 1.43 - 'inc_dir' Remote File Inclusion
Directory traversal vulnerability in js/wptable-button.php in the wp-Table 1.43 and earlier plugin for WordPress, when r
23RISK
open ↗Referência✓ VexDay Proof
WordPress Plugin wp-Table 1.43 - 'inc_dir' Remote File Inclusion
PHP remote file inclusion vulnerability in js/wptable-button.php in the wp-Table 1.43 and earlier plugin for WordPress,
35RISK
open ↗Referência✓ VexDay Proof
AllMyGuests 0.4.1 - 'AMG_id' SQL Injection
SQL injection vulnerability in index.php in Voice Of Web AllMyGuests 0.4.1 allows remote attackers to execute arbitrary
23RISK
open ↗Referência✓ VexDay Proof
Aterr 0.9.1 - PHP5 Local File Inclusion
Multiple directory traversal vulnerabilities in Aterr 0.9.1 allow remote attackers to include and execute arbitrary loca
23RISK
open ↗Referência✓ VexDay Proof
Formbankserver 1.9 - 'Name' Directory Traversal
Directory traversal vulnerability in formbankcgi.exe/AbfrageForm in Formbankserver 1.9 allows remote attackers to read a
23RISK
open ↗Referência✓ VexDay Proof
WordPress Plugin myflash 1.00 - 'wppath' Remote File Inclusion
PHP remote file inclusion vulnerability in myflash-button.php in the myflash 1.00 and earlier plugin for WordPress allow
35RISK
open ↗Referência✓ VexDay Proof
PostNuke Module v4bJournal - SQL Injection
SQL injection vulnerability in index.php in the v4bJournal module for PostNuke allows remote authenticated users to exec
23RISK
open ↗Referência✓ VexDay Proof
Hedgehog-CMS 1.21 - 'header.php' Local File Inclusion
Directory traversal vulnerability in includes/header.php in Hedgehog-CMS 1.21 allows remote attackers to include and exe
23RISK
open ↗Referência✓ VexDay Proof
Excel Viewer OCX 3.1.0.6 - Multiple Denial of Service Vulnerabilities
Multiple stack-based buffer overflows in the ExcelOCX ActiveX control in ExcelViewer.ocx 3.1.0.6 allow remote attackers
23RISK
open ↗Referência✓ VexDay Proof
1024 CMS 0.7 - 'download.php' Remote File Disclosure
Directory traversal vulnerability in includes/download.php in Treble Designs 1024 CMS 0.7 allows remote attackers to rea
23RISK
open ↗Referência✓ VexDay Proof
E-topbiz ADManager 4 - 'group' Blind SQL Injection
SQL injection vulnerability in view.php in E-topbiz AdManager 4 allows remote attackers to execute arbitrary SQL command
23RISK
open ↗Referência✓ VexDay Proof
Bluo CMS 1.2 - Blind SQL Injection
SQL injection vulnerability in index.php in Bluo CMS 1.2 allows remote attackers to execute arbitrary SQL commands via t
23RISK
open ↗Referência✓ VexDay Proof
z1exchange 1.0 - 'site' SQL Injection
SQL injection vulnerability in edit.php in Z1Exchange 1.0 allows remote attackers to execute arbitrary SQL commands via
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.