Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,460Referência 22,832GitHub PoC 14,991VulnCheck XDB 8,829Nuclei 4,357Metasploit 3,489✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
Serv-U FTP Server 7.3 - (Authenticated) Remote FTP File Replacement
Directory traversal vulnerability in the FTP server in Serv-U 7.0.0.1 through 7.3, including 7.2.0.1, allows remote auth
28RISK
open ↗Referência✓ VexDay Proof
CS-Cart 1.3.5 - Authentication Bypass
SQL injection vulnerability in core/user.php in CS-Cart 1.3.5 and earlier allows remote attackers to execute arbitrary S
23RISK
open ↗Referência✓ VexDay Proof
Oreon 1.4 / Centreon 1.4.1 - Multiple Remote File Inclusion Vulnerabilities
Multiple PHP remote file inclusion vulnerabilities in Centreon 1.4.1 (aka Oreon 1.4) allow remote attackers to execute a
28RISK
open ↗Referência✓ VexDay Proof
PowerNews 2.5.6 - Local File Inclusion
Multiple directory traversal vulnerabilities in PowerScripts PowerNews 2.5.6 allow remote attackers to read and include
23RISK
open ↗Referência✓ VexDay Proof
Mambo Component com_gallery - SQL Injection
SQL injection vulnerability in index.php in the Gallery (com_gallery) component for Mambo and Joomla! allows remote atta
23RISK
open ↗Referência✓ VexDay Proof
HotScripts Clone - 'cid' SQL Injection
SQL injection vulnerability in showcategory.php in Hotscripts Clone allows remote attackers to execute arbitrary SQL com
23RISK
open ↗Referência✓ VexDay Proof
Ol BookMarks Manager 0.7.5 - Local File Inclusion
Directory traversal vulnerability in show.php in ol'bookmarks manager 0.7.5 and earlier allows remote attackers to inclu
23RISK
open ↗Referência✓ VexDay Proof
Joomla! / Mambo Component SWmenu 4.0 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in the SWmenu (com_swmenupro and com_swmenufree) 4.0 component for Ma
28RISK
open ↗Referência✓ VexDay Proof
Fastpublish CMS 1.9999 - config[fsBase] Remote File Inclusion
PHP remote file inclusion vulnerability in adminbereich/designconfig.php in Fastpublish CMS 1.9999 allows remote attacke
28RISK
open ↗Referência✓ VexDay Proof
jetAudio 7.0.5 - '.asx' Remote Stack Overflow (PoC)
Stack-based buffer overflow in COWON America jetAudio 7.0.5 and earlier allows user-assisted remote attackers to execute
23RISK
open ↗Referência✓ VexDay Proof
Explay CMS 2.1 - Insecure Cookie Handling
Explay CMS 2.1 and earlier allows remote attackers to bypass authentication and gain administrative access by setting th
23RISK
open ↗Referência✓ VexDay Proof
AJ Auction Pro Platinum Skin - 'item_id' SQL Injection
SQL injection vulnerability in detail.php in AJ Auction Pro Platinum Skin 2 allows remote attackers to execute arbitrary
23RISK
open ↗Referência✓ VexDay Proof
docpile:we 0.2.2 - 'INIT_PATH' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Wim Fleischhauer docpile: wim's edition (docpile:we) 0.2.2 and ear
28RISK
open ↗Referência✓ VexDay Proof
GdPicture Pro - ActiveX 'gdpicture4s.ocx' File Overwrite / Exec
The GdPicture (1) Light Imaging Toolkit 4.7.1 GdPicture4S.Imaging ActiveX control (gdpicture4s.ocx) 4.7.0.1 and (2) Pro
28RISK
open ↗Referência✓ VexDay Proof
Social Site Generator 2.0 - 'sgc_id' SQL Injection
Multiple SQL injection vulnerabilities in Social Site Generator (SSG) 2.0 allow remote attackers to execute arbitrary SQ
23RISK
open ↗Referência✓ VexDay Proof
Social Site Generator 2.0 - Multiple Remote File Disclosure Vulnerabilities
Social Site Generator (SSG) 2.0 allows remote attackers to read arbitrary files via the file parameter to (1) filedload.
23RISK
open ↗Referência✓ VexDay Proof
Pagode 0.5.8 - 'navigator_ok.php?asolute' Remote File Disclosure
Directory traversal vulnerability in navigator/navigator_ok.php in Pagode 0.5.8 allows remote attackers to read and poss
28RISK
open ↗Referência✓ VexDay Proof
Sun jre1.6.0_X - isInstalled.dnsResolve Function Overflow
Buffer overflow in the Sun Java Web Start ActiveX control in Java Runtime Environment (JRE) 1.6.0_X allows remote attack
28RISK
open ↗Referência✓ VexDay Proof
Linux Kernel 2.6.21.1 - IPv6 Jumbo Bug Remote Denial of Service
The Linux kernel 2.6.20 through 2.6.21.1 allows remote attackers to cause a denial of service (panic) via a certain IPv6
28RISK
open ↗Referência✓ VexDay Proof
sflog! 0.96 - Remote File Disclosure
Multiple directory traversal vulnerabilities in sflog! 0.96 allow remote attackers to read arbitrary files via a .. (dot
23RISK
open ↗Referência✓ VexDay Proof
BloofoxCMS 0.3.4 - 'lang' Local File Inclusion
Directory traversal vulnerability in plugins/spaw2/dialogs/dialog.php in BloofoxCMS 0.3.4 allows remote attackers to rea
28RISK
open ↗Referência✓ VexDay Proof
ComicShout 2.8 - 'news_id' SQL Injection
SQL injection vulnerability in news.php in ComicShout 2.8 allows remote attackers to execute arbitrary SQL commands via
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component NeoGallery 1.1 - SQL Injection
SQL injection vulnerability in index.php in the Neogallery (com_neogallery) 1.1 component for Joomla! allows remote atta
23RISK
open ↗Referência✓ VexDay Proof
HiveMaker Directory 1.0.2 - 'cid' SQL Injection
SQL injection vulnerability in index.php in Hivemaker Professional 1.0.2 and earlier, when magic_quotes_gpc is disabled,
23RISK
open ↗Referência✓ VexDay Proof
VUPlayer 2.49 - '.pls' Universal Buffer Overflow
Buffer overflow in VUPlayer 2.49 and earlier allows user-assisted attackers to execute arbitrary code via a long URL in
50RISK
open ↗Referência✓ VexDay Proof
AIMP 2.51 build 330 - ID3v1/ID3v2 Tag Remote Stack Buffer Overflow (PoC) (SEH)
Stack-based buffer overflow in AIMP 2.51 build 330 allows remote attackers to execute arbitrary code via an MP3 file wit
28RISK
open ↗Referência✓ VexDay Proof
HiveMaker Professional 1.0.2 - 'cid' SQL Injection
SQL injection vulnerability in index.php in Hivemaker Professional 1.0.2 and earlier, when magic_quotes_gpc is disabled,
23RISK
open ↗Referência✓ VexDay Proof
Libxine 1.14 - MPEG Stream Buffer Overflow (PoC)
Buffer overflow in demuxers/demux_asf.c (aka the ASF demuxer) in the xineplug_dmx_asf.so plugin in xine-lib before 1.1.1
28RISK
open ↗Referência✓ VexDay Proof
e107 Plugin BLOG Engine 2.2 - 'uid' SQL Injection
SQL injection vulnerability in macgurublog_menu/macgurublog.php in the MacGuru BLOG Engine plugin 2.2 for e107 allows re
23RISK
open ↗Referência✓ VexDay Proof
SolidState 0.4 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in SolidState 0.4 and earlier allow remote attackers to execute arbit
28RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.