Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,449cataloged exploits
35,552CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,367GitHub PoC 14,225VulnCheck XDB 8,649Nuclei 4,283Metasploit 3,474✓ verified onlyrecentpopularrisk
22,367 exploits
Referência
CVE-2017-17585
FS Monster Clone 1.0 has SQL Injection via the Employer_Details.php id parameter.
23RISK
open ↗Referência✓ VexDay Proof
Web Slider 0.6 - 'path' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Marco Antonio Islas Cruz Web Slider (WebSlider) 0.6 allow remote a
23RISK
open ↗Referência
CVE-2017-17585
FS Monster Clone 1.0 has SQL Injection via the Employer_Details.php id parameter.
23RISK
open ↗Referência✓ VexDay Proof
StoreFront for Gallery - 'GALLERY_BASEDIR' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in the StoreFront mods for Gallery allow remote attackers to execute
23RISK
open ↗Referência✓ VexDay Proof
openMairie 1.10 - '/scr/soustab.php' Local File Inclusion
Directory traversal vulnerability in scr/soustab.php in openMairie 1.11 and earlier allows remote attackers to include a
23RISK
open ↗Referência✓ VexDay Proof
SunShop Shopping Cart 3.5 - 'abs_path' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools SunShop Shopping Cart before 3.5.1 allow remote
23RISK
open ↗Referência✓ VexDay Proof
xoops module tsdisplay4xoops 0.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in blocks/tsdisplay4xoops_block2.php in tsdisplay4xoops (TSD4XOOPS, aka the Team
23RISK
open ↗Referência✓ VexDay Proof
ShoutPro 1.5.2 - 'shout.php' Remote Code Injection
Direct static code injection vulnerability in shoutbox.php in ShoutPro 1.5.2 allows remote attackers to inject arbitrary
35RISK
open ↗Referência
CVE-2017-17586
FS Olx Clone 1.0 has SQL Injection via the subpage.php scat parameter or the message.php pid parameter.
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component Template Be2004-2 - 'index.php' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in the Be2004-2 template for Joomla! allows remote attackers to exe
23RISK
open ↗Referência
CVE-2017-17586
FS Olx Clone 1.0 has SQL Injection via the subpage.php scat parameter or the message.php pid parameter.
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component JoomlaPack 1.0.4a2 RE - 'CAltInstaller.php' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/CAltInstaller.php in the JoomlaPack (com_jpack) 1.0.4a2 RE component
23RISK
open ↗Referência✓ VexDay Proof
Cabron Connector 1.1.0-Full - Remote File Inclusion
PHP remote file inclusion vulnerability in services/samples/inclusionService.php in Cabron Connector 1.1.0 allows remote
23RISK
open ↗Referência
CVE-2017-17587
FS Indiamart Clone 1.0 has SQL Injection via the catcompany.php token parameter, buyleads-details.php id parameter, or c
23RISK
open ↗Referência✓ VexDay Proof
Rezervi 0.9 - 'root' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Rezervi Generic 0.9 allow remote attackers to execute arbitrary PH
28RISK
open ↗Referência✓ VexDay Proof
AimStats 3.2 - 'process.php?update' Remote Code Execution
Static code injection vulnerability in process.php in AimStats 3.2 allows remote attackers to inject PHP code into confi
35RISK
open ↗Referência
CVE-2017-17588
FS IMDB Clone 1.0 has SQL Injection via the movie.php f parameter, tvshow.php s parameter, or show_misc_video.php id par
23RISK
open ↗Referência✓ VexDay Proof
Mozzers SubSystem final - 'subs.php' Remote Code Execution
Static code injection vulnerability in add.php in Mozzers SubSystem 1.0 allows remote attackers to inject PHP code into
23RISK
open ↗Referência✓ VexDay Proof
Winamp 5.3 - '.wmv' Remote Denial of Service
Buffer overflow in Nullsoft Winamp 5.3 allows user-assisted remote attackers to cause a denial of service (crash) via a
23RISK
open ↗Referência✓ VexDay Proof
WEBInsta FM 0.1.4 - 'login.php' absolute_path Remote File Inclusion
PHP remote file inclusion vulnerability in admin/login.php in Webinsta FM Manager 0.1.4 and earlier allows remote attack
23RISK
open ↗Referência✓ VexDay Proof
PHP-Ring Webring System 0.9 - SQL Injection
SQL injection vulnerability in index.php in PHP-Ring Webring System (aka uPHP_ring_website) 0.9 allows remote attackers
23RISK
open ↗Referência✓ VexDay Proof
Supasite 1.23b - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Supasite 1.23b allow remote attackers to execute arbitrary PHP cod
23RISK
open ↗Referência
Microsoft Windows 11 - Kernel Privilege Escalation
Windows Kernel Elevation of Privilege Vulnerability
83RISK
open ↗Referência✓ VexDay Proof
WebSPELL 4.01.02 - 'picture.php' File Disclosure
picture.php in WebSPELL 4.01.02 and earlier allows remote attackers to read arbitrary files via the file parameter.
23RISK
open ↗Referência
CVE-2017-17592
Website Auction Marketplace 2.0.5 has SQL Injection via the search.php cat_id parameter.
23RISK
open ↗Referência✓ VexDay Proof
WebSPELL 4.01.02 - 'picture.php' File Disclosure
Directory traversal vulnerability in picture.php in WebSPELL 4.01.02 and earlier, when PHP before 4.3.0 is used, allows
23RISK
open ↗Referência
CVE-2017-17592
Website Auction Marketplace 2.0.5 has SQL Injection via the search.php cat_id parameter.
23RISK
open ↗Referência✓ VexDay Proof
phpMyNewsletter 0.8 (beta5) - Multiple Vulnerabilities
admin/index.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier provides access to configuration modification
23RISK
open ↗Referência✓ VexDay Proof
Sendcard 3.4.1 - 'sendcard.php?form' Local File Inclusion
Directory traversal vulnerability in sendcard.php in Sendcard 3.4.1 and earlier allows remote attackers to read arbitrar
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.