Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,302cataloged exploits
35,469CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,301GitHub PoC 14,141VulnCheck XDB 8,646Nuclei 4,289Metasploit 3,474✓ verified onlyrecentpopularrisk
22,266 exploits
Referência✓ VexDay Proof
CF_Forum - Blind SQL Injection
SQL injection vulnerability in forummessages.cfm in CF_Forum allows remote attackers to execute arbitrary SQL commands v
23RISK
open ↗Referência✓ VexDay Proof
ProQuiz 1.0 - Authentication Bypass
SQL injection vulnerability in index.php in ProQuiz 1.0 allows remote attackers to execute arbitrary SQL commands via th
23RISK
open ↗Referência
CVE-2010-3742
Multiple PHP remote file inclusion vulnerabilities in themes/default/index.php in Free Simple CMS 1.0 allow remote attac
23RISK
open ↗Referência✓ VexDay Proof
Butterfly ORGanizer 2.0.1 - 'id' SQL Injection
SQL injection vulnerability in view.php in Butterfly Organizer 2.0.0 and 2.0.1 allows remote attackers to execute arbitr
23RISK
open ↗Referência✓ VexDay Proof
Pre Job Board - Authentication Bypass
SQL injection vulnerability in Employee/login.asp in Pre ASP Job Board allows remote attackers to execute arbitrary SQL
23RISK
open ↗Referência✓ VexDay Proof
MyTopix 1.3.0 - SQL Injection
SQL injection vulnerability in index.php in MyTopix 1.3.0 and earlier allows remote authenticated users to execute arbit
23RISK
open ↗Referência✓ VexDay Proof
Simple Customer 1.2 - Authentication Bypass
SQL injection vulnerability in login.php in Simple Customer 1.2 allows remote attackers to execute arbitrary SQL command
23RISK
open ↗Referência✓ VexDay Proof
RSS Simple News - SQL Injection
SQL injection vulnerability in news.php in RSS Simple News (RSSSN), when magic_quotes_gpc is disabled, allows remote att
23RISK
open ↗Referência✓ VexDay Proof
PostNuke 0.763 - 'PNSV lang' Remote Code Execution
Directory traversal vulnerability in error.php in PostNuke 0.763 and earlier allows remote attackers to include and exec
23RISK
open ↗Referência
CVE-2026-7226
SourceCodester Pizzafy Ecommerce System ajax.php login2 sql injection
33RISK
open ↗Referência
CVE-2026-7225
SourceCodester Pizzafy Ecommerce System ajax.php delete_menu sql injection
33RISK
open ↗Referência
CVE-2026-7224
SourceCodester Pizzafy Ecommerce System ajax.php delete_cart sql injection
33RISK
open ↗Referência
CVE-2026-7223
BigSweetPotatoStudio HyperChat AI Proxy Middleware aiProxyMiddleware.mts fetch server-side request forgery
33RISK
open ↗Referência
CVE-2017-6086
Multiple cross-site request forgery (CSRF) vulnerabilities in the addAction and purgeAction functions in ViMbAdmin 3.0.1
23RISK
open ↗Referência
CVE-2017-6090
Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authentica
60RISK
open ↗Referência
CVE-2010-3962
Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary cod
100RISK
open ↗Referência
CVE-2017-6090
Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authentica
60RISK
open ↗Referência
CVE-2010-5004
SQL injection vulnerability in searchvote.php in 2daybiz Polls (aka Advanced Poll) Script allows remote attackers to exe
23RISK
open ↗Referência✓ VexDay Proof
Mumbo Jumbo Media OP4 - Blind SQL Injection
SQL injection vulnerability in Mumbo Jumbo Media OP4 allows remote attackers to execute arbitrary SQL commands via the i
23RISK
open ↗Referência
CVE-2017-6178
The IofCallDriver function in USBPcap 1.1.0.0 allows local users to gain privileges via a crafted 0x00090028 IOCTL call,
23RISK
open ↗Referência
CVE-2017-6371
Synchronet BBS 3.16c for Windows allows remote attackers to cause a denial of service (service crash) via a long string
23RISK
open ↗Referência
CVE-2017-6444
The MikroTik Router hAP Lite 6.25 has no protection mechanism for unsolicited TCP ACK packets in the case of a fast netw
28RISK
open ↗Referência
CVE-2017-6506
In Azure Data Expert Ultimate 2.2.16, the SMTP verification function suffers from a buffer overflow vulnerability, leadi
28RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.