Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,620cataloged exploits
35,647CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,429GitHub PoC 14,270VulnCheck XDB 8,693Nuclei 4,299Metasploit 3,474✓ verified onlyrecentpopularrisk
22,429 exploits
Referência✓ VexDay Proof
Back-End CMS 0.7.2.2 - 'BE_config.php' Remote File Inclusion
PHP remote file inclusion vulnerability in BE_config.php in Back-End CMS 0.7.2.1 and earlier allows remote attackers to
23RISK
open ↗Referência✓ VexDay Proof
Camera Life 2.6.2b4 - SQL Injection / Cross-Site Scripting
SQL injection vulnerability in album.php in Camera Life 2.6.2b4 allows remote attackers to execute arbitrary SQL command
23RISK
open ↗Referência✓ VexDay Proof
Informium 0.12.0 - 'common-menu.php' Remote File Inclusion
PHP remote file inclusion vulnerability in common-menu.php in Cameron McKay Informium 0.12.0 allows remote attackers to
23RISK
open ↗Referência✓ VexDay Proof
Redaxo 3.2 - 'INCLUDE_PATH' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Redaxo 3.0 allow remote attackers to execute arbitrary PHP code vi
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component Joomtracker 1.01 - SQL Injection
SQL injection vulnerability in the Joomtracker (com_joomtracker) 1.01 module for Joomla! allows remote attackers to exec
23RISK
open ↗Referência✓ VexDay Proof
e107 Plugin ZoGo-Shop 1.15.4 - 'product' SQL Injection
SQL injection vulnerability in product_details.php in the Mytipper Zogo-shop 1.15.4 plugin for e107 allows remote attack
23RISK
open ↗Referência✓ VexDay Proof
Wikiwig 4.1 - 'wk_lang.php' Remote File Inclusion
PHP remote file inclusion vulnerability in _wk/wk_lang.php in Wikiwig 4.1 and earlier allows remote attackers to execute
23RISK
open ↗Referência✓ VexDay Proof
Limbo CMS Module event 1.0 - Remote File Inclusion
PHP remote file inclusion in eventcal/mod_eventcal.php in the event module 1.0 for Limbo CMS allows remote attackers to
23RISK
open ↗Referência
CVE-2026-10236
SourceCodester Water Billing Management System User Management Endpoint Users.php save improper authorization
33RISK
open ↗Referência
CVE-2026-23760
SmarterTools SmarterMail < Build 9511 Authentication Bypass via Password Reset API
100RISK
open ↗Referência
CVE-2026-9377
SourceCodester SUP Online Shopping productedit.php cross site scripting
33RISK
open ↗Referência✓ VexDay Proof
KwsPHP 1.3.456 Module Galerie - 'id_gal' SQL Injection
SQL injection vulnerability in index.php in the galerie module for KwsPHP 1.3.456 allows remote attackers to execute arb
23RISK
open ↗Referência✓ VexDay Proof
MyBB Plugin Custom Pages 1.0 - SQL Injection
SQL injection vulnerability in pages.php in Custom Pages 1.0 plugin for MyBulletinBoard (MyBB) allows remote attackers t
23RISK
open ↗Referência✓ VexDay Proof
2532/Gigs 1.2.2 - Arbitrary Database Backup/Download
2532designs 2532|Gigs 1.2.2 and earlier allows remote attackers to trigger a backup and obtain sensitive information via
23RISK
open ↗Referência
glibc 2.38 - Buffer Overflow
Glibc: buffer overflow in ld.so leading to privilege escalation
100RISK
open ↗Referência✓ VexDay Proof
Cobalt 0.1 - Multiple SQL Injections
SQL injection vulnerability in CoBaLT 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter
23RISK
open ↗Referência
CVE-2008-6209
SQL injection vulnerability in view_product.php in Vastal I-Tech Software Zone allows remote attackers to execute arbitr
23RISK
open ↗Referência✓ VexDay Proof
Vastal I-Tech Software Zone - 'cat_id' SQL Injection
SQL injection vulnerability in view_product.php in Vastal I-Tech Software Zone allows remote attackers to execute arbitr
23RISK
open ↗Referência✓ VexDay Proof
Dream4 Koobi 4.4/5.4 - gallery SQL Injection
SQL injection vulnerability in index.php in dream4 Koobi 4.4 and 5.4 allows remote attackers to execute arbitrary SQL co
23RISK
open ↗Referência
CVE-2012-1153
Unrestricted file upload vulnerability in addons/uploadify/uploadify.php in appRain CMF 0.1.5 and earlier allows remote
50RISK
open ↗Referência✓ VexDay Proof
PreProject Multi-Vendor Shopping Malls - Multiple Vulnerabilities
SQL injection vulnerability in buyer_detail.php in Pre Multi-Vendor Shopping Malls allows remote attackers to execute ar
23RISK
open ↗Referência
CVE-2023-23956
A user can supply malicious HTML and JavaScript code that will be executed in the client browser
33RISK
open ↗Referência
CVE-2020-11530
A blind SQL injection vulnerability is present in Chop Slider 3, a WordPress plugin. The vulnerability is introduced in
60RISK
open ↗Referência
CVE-2020-11530
A blind SQL injection vulnerability is present in Chop Slider 3, a WordPress plugin. The vulnerability is introduced in
60RISK
open ↗Referência✓ VexDay Proof
PreProject Multi-Vendor Shopping Malls - Multiple Vulnerabilities
Pre Multi-Vendor Shopping Malls allows remote attackers to bypass authentication and gain administrative access by setti
23RISK
open ↗Referência
CVE-2009-2235
SQL injection vulnerability in page.php in Your Articles Directory allows remote attackers to execute arbitrary SQL comm
23RISK
open ↗Referência
CVE-2011-4862
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka k
60RISK
open ↗Referência✓ VexDay Proof
Jadu Galaxies - 'categoryId' Blind SQL Injection
SQL injection vulnerability in scripts/documents.php in Jadu Galaxies allows remote attackers to execute arbitrary SQL c
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.