Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,460Referência 22,832GitHub PoC 14,991VulnCheck XDB 8,829Nuclei 4,357Metasploit 3,489✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
Joomla! Component ongumatimesheet20 4b - Remote File Inclusion
PHP remote file inclusion vulnerability in lib/onguma.class.php in the Onguma Time Sheet (com_ongumatimesheet20) 2.0 4b
28RISK
open ↗Referência✓ VexDay Proof
DevelopItEasy Photo Gallery 1.2 - SQL Injection
Multiple SQL injection vulnerabilities in DevelopItEasy Photo Gallery 1.2 allow remote attackers to execute arbitrary SQ
23RISK
open ↗Referência✓ VexDay Proof
BlogPHP 2 - 'id' Cross-Site Scripting / SQL Injection
SQL injection vulnerability in index.php in BlogPHP 2.0 allows remote attackers to execute arbitrary SQL commands via th
23RISK
open ↗Referência✓ VexDay Proof
Black Ice Software Annotation Plugin - 'BiAnno.ocx' Remote Buffer Overflow
Stack-based buffer overflow in BiAnno ActiveX Control (BiAnno.ocx) in Black Ice Software Annotation Plugin 10.95 allows
28RISK
open ↗Referência✓ VexDay Proof
BXCP 0.2.9.9 - 'tid' SQL Injection
SQL injection vulnerability in index.php in BXCP 0.299 allows remote attackers to execute arbitrary SQL commands via the
23RISK
open ↗Referência✓ VexDay Proof
TurnkeyForms Business Survey Pro 1.0 - 'id' SQL Injection
SQL injection vulnerability in survey_results_text.php in TurnkeyForms Business Survey Pro 1.0 allows remote attackers t
23RISK
open ↗Referência✓ VexDay Proof
Online Media Technologies 'AVSMJPEGFILE.DLL 1.1' - Remote Buffer Overflow (PoC)
Buffer overflow in a certain ActiveX control in Online Media Technologies AVSMJPEGFILE.DLL 1.1.1.102 allows remote attac
28RISK
open ↗Referência✓ VexDay Proof
ASP-CMS 1.0 - 'cha' SQL Injection
SQL injection vulnerability in index.asp in ASP-CMS 1.0 allows remote attackers to execute arbitrary SQL commands via th
23RISK
open ↗Referência✓ VexDay Proof
Oracle Internet Directory 10.1.4 - Remote Denial of Service
Unspecified vulnerability in the Oracle Internet Directory component in Oracle Application Server 9.0.4.3, 10.1.2.3, and
28RISK
open ↗Referência✓ VexDay Proof
WordPress Plugin st_newsletter - SQL Injection
SQL injection vulnerability in shiftthis-preview.php in the ShiftThis Newsletter (st_newsletter) plugin for WordPress al
23RISK
open ↗Referência✓ VexDay Proof
evCal Events Calendar - Database Disclosure
evCal Events Calendar stores sensitive information under the web root with insufficient access control, which allows rem
23RISK
open ↗Referência✓ VexDay Proof
MyCal Personal Events Calendar - Database Disclosure
MyCal Personal Events Calendar stores sensitive information under the web root with insufficient access control, which a
23RISK
open ↗Referência✓ VexDay Proof
Social Groupie - 'id' SQL Injection
SQL injection vulnerability in group_index.php in Social Groupie allows remote attackers to execute arbitrary SQL comman
23RISK
open ↗Referência✓ VexDay Proof
Bytehoard 2.1 - 'server.php' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/webdav/server.php in Bytehoard 2.1 Epsilon/Delta allows remote attac
28RISK
open ↗Referência✓ VexDay Proof
DesignWorks Professional 4.3.1 - '.CCT' File Local Stack Buffer Overflow (PoC)
Stack-based buffer overflow in DesignWorks Professional 4.3.1 and 5.0.7 allows remote attackers to execute arbitrary cod
23RISK
open ↗Referência✓ VexDay Proof
Site@School 2.4.02 - Arbitrary File Upload
Multiple PHP remote file inclusion vulnerabilities in Site@School (S@S) 2.4.02 and earlier allow remote attackers to exe
28RISK
open ↗Referência✓ VexDay Proof
Joomla! Component NeoReferences 1.3.1 - 'catid' SQL Injection
SQL injection vulnerability in index.php in the NeoReferences (com_neoreferences) 1.3.1 and 1.3.3 component for Joomla!
23RISK
open ↗Referência✓ VexDay Proof
Ad Management Java - Authentication Bypass
SQL injection vulnerability in logon.jsp in Ad Server Solutions Ad Management Software Java allows remote attackers to e
23RISK
open ↗Referência✓ VexDay Proof
ITechBids 5.0 - 'item_id' SQL Injection
SQL injection vulnerability in bidhistory.php in iTechBids 3 Gold and 5.0 allows remote attackers to execute arbitrary S
23RISK
open ↗Referência✓ VexDay Proof
Affiliate Software Java 4.0 - Authentication Bypass
SQL injection vulnerability in logon.jsp in Ad Server Solutions Affiliate Software Java 4.0 allows remote attackers to e
23RISK
open ↗Referência✓ VexDay Proof
Ocean12 Contact Manager Pro - SQL Injection / Cross-Site Scripting / File Disclosure
SQL injection vulnerability in default.asp in Ocean12 Contact Manager Pro 1.02 allows remote attackers to execute arbitr
23RISK
open ↗Referência✓ VexDay Proof
Codefixer MailingListPro - Database Disclosure
CodefixerSoftware MailingListPro Free Edition stores sensitive information under the web root with insufficient access c
23RISK
open ↗Referência✓ VexDay Proof
Multi SEO phpBB 1.1.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in include/global.php in Multi SEO phpBB 1.1.0 allows remote attackers to execut
23RISK
open ↗Referência✓ VexDay Proof
Calendar MX Professional 2.0.0 - Blind SQL Injection
SQL injection vulnerability in calendar_Eventupdate.asp in Calendar Mx Professional 2.0.0 allows remote attackers to exe
23RISK
open ↗Referência✓ VexDay Proof
CA BrightStor ARCserve 11.5.2.0 - 'catirpc.dll' RPC Server Denial of Service
The RPC Server service (catirpc.exe) in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 SP2 and earlie
28RISK
open ↗Referência✓ VexDay Proof
Active Web Helpdesk 2 - 'categoryId' Blind SQL Injection
SQL injection vulnerability in default.aspx in Active Web Helpdesk 2.0 allows remote attackers to execute arbitrary SQL
23RISK
open ↗Referência✓ VexDay Proof
CandyPress eCommerce suite 4.1.1.26 - Multiple Vulnerabilities
admin/SA_shipFedExMeter.asp in CandyPress (CP) 4.1.1.26, and possibly other 4.x and 3.x versions, allows remote attacker
23RISK
open ↗Referência✓ VexDay Proof
Quick Tree View .NET 3.1 - Database Disclosure
Quick Tree View .NET 3.1 stores sensitive information under the web root with insufficient access control, which allows
23RISK
open ↗Referência✓ VexDay Proof
Rapid Classified 3.1 - Database Disclosure
Rapid Classified 3.1 and 3.15 stores sensitive information under the web root with insufficient access control, which al
23RISK
open ↗Referência✓ VexDay Proof
Visual Events Calendar 1.1 - 'cfg_dir' Remote File Inclusion
PHP remote file inclusion vulnerability in calendar.php in Visual Events Calendar 1.1 allows remote attackers to execute
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.