Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,302cataloged exploits
35,469CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,301GitHub PoC 14,141VulnCheck XDB 8,646Nuclei 4,289Metasploit 3,474✓ verified onlyrecentpopularrisk
22,301 exploits
Referência✓ VexDay Proof
BosNews 4.0 - 'article' SQL Injection
SQL injection vulnerability in news.php in BosDev BosNews 4.0 allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗Referência
CVE-2017-17576
FS Gigs Script 1.0 has SQL Injection via the browse-category.php cat parameter, browse-scategory.php sc parameter, or se
23RISK
open ↗Referência✓ VexDay Proof
My PHP Dating - 'id' SQL Injection
SQL injection vulnerability in success_story.php in php Online Dating Software MyPHPDating allows remote attackers to ex
23RISK
open ↗Referência
CVE-2017-17576
FS Gigs Script 1.0 has SQL Injection via the browse-category.php cat parameter, browse-scategory.php sc parameter, or se
23RISK
open ↗Referência✓ VexDay Proof
Vbgooglemap Hotspot Edition 1.0.3 - SQL Injection
SQL injection vulnerability in VBGooglemap Hotspot Edition 1.0.3, a vBulletin module, allows remote attackers to execute
23RISK
open ↗Referência
CVE-2026-8981
Lazy Blocks < 4.3.0 - Admin+ Stored XSS via Custom Block Frontend HTML
28RISK
open ↗Referência
CVE-2026-11585
CodeAstro Student Attendance Management System createClassArms.php sql injection
33RISK
open ↗Referência✓ VexDay Proof
Top Auction 1.0 - 'viewcat.php' SQL Injection
SQL injection vulnerability in PHP Labs Top Auction allows remote attackers to execute arbitrary SQL commands via the (1
23RISK
open ↗Referência
CVE-2017-17577
FS Trademe Clone 1.0 has SQL Injection via the search_item.php search parameter or the general_item_details.php id param
23RISK
open ↗Referência
CVE-2026-7315
eiceblue spire-pdf-mcp-server PDF File server.py get_pdf_path path traversal
33RISK
open ↗Referência
CVE-2017-17577
FS Trademe Clone 1.0 has SQL Injection via the search_item.php search parameter or the general_item_details.php id param
23RISK
open ↗Referência
CVE-2017-17578
FS Crowdfunding Script 1.0 has SQL Injection via the latest_news_details.php id parameter.
23RISK
open ↗Referência
CVE-2017-17578
FS Crowdfunding Script 1.0 has SQL Injection via the latest_news_details.php id parameter.
23RISK
open ↗Referência
CVE-2017-17579
FS Freelancer Clone 1.0 has SQL Injection via the profile.php u parameter.
23RISK
open ↗Referência
CVE-2017-17579
FS Freelancer Clone 1.0 has SQL Injection via the profile.php u parameter.
23RISK
open ↗Referência
CVE-2026-11477
hs-web hsweb-framework OAuth2 Client OAuth2Client.java OAuth2Client redirect
33RISK
open ↗Referência
CVE-2017-17609
Chartered Accountant Booking Script 1.0 has SQL Injection via the /service-list city parameter.
23RISK
open ↗Referência✓ VexDay Proof
1st News - SQL Injection
SQL injection vulnerability in products.php in 1st News 4 Professional (PR 1) allows remote attackers to execute arbitra
23RISK
open ↗Referência
CVE-2017-17609
Chartered Accountant Booking Script 1.0 has SQL Injection via the /service-list city parameter.
23RISK
open ↗Referência
CVE-2010-3404
Multiple SQL injection vulnerabilities in eshtery CMS (aka eshtery.com) allow remote attackers to execute arbitrary SQL
23RISK
open ↗Referência✓ VexDay Proof
YourFreeWorld Downline Builder - 'tr.php' SQL Injection
SQL injection vulnerability in tr.php in YourFreeWorld Downline Builder allows remote attackers to execute arbitrary SQL
23RISK
open ↗Referência
CVE-2017-17610
E-commerce MLM Software 1.0 has SQL Injection via the service_detail.php pid parameter, event_detail.php eventid paramet
23RISK
open ↗Referência
CVE-2017-17610
E-commerce MLM Software 1.0 has SQL Injection via the service_detail.php pid parameter, event_detail.php eventid paramet
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.