Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,460Referência 22,910GitHub PoC 14,997VulnCheck XDB 8,843Nuclei 4,358Metasploit 3,489✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
Data Dynamics ActiveBar (Actbar3.ocx 3.2) - Multiple Insecure Methods
The Data Dynamics ActiveBar ActiveX control (actbar3.ocx) 3.2 and earlier allows remote attackers to create or overwrite
23RISK
open ↗Referência✓ VexDay Proof
CA BrightStor ARCserve Backup r11.5 - ActiveX Remote Buffer Overflow
Stack-based buffer overflow in the ListCtrl ActiveX Control (ListCtrl.ocx), as used in multiple CA products including Br
50RISK
open ↗Referência✓ VexDay Proof
Pluxml 0.3.1 - Remote Code Execution
Unrestricted file upload vulnerability in admin/images.php in Pluxml 0.3.1 allows remote attackers to upload and execute
23RISK
open ↗Referência✓ VexDay Proof
Simple Machines Forum (SMF) 1.1.6 - Code Execution
Cross-site request forgery (CSRF) vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 be
23RISK
open ↗Referência✓ VexDay Proof
phpAuction - 'profile.php' SQL Injection (1)
SQL injection vulnerability in profile.php in PHPAuctions.info PHPAuctions (aka PHPAuctionSystem) allows remote attacker
23RISK
open ↗Referência✓ VexDay Proof
PHP Live Helper 2.0 - 'abs_path' Remote File Inclusion
PHP remote file inclusion vulnerability in global.php in Turnkey Web Tools PHP Live Helper 2.0 and earlier allows remote
23RISK
open ↗Referência✓ VexDay Proof
XLPortal 2.2.4 - 'Search' SQL Injection
SQL injection vulnerability in index.php in XLPortal 2.2.4 and earlier allows remote attackers to execute arbitrary SQL
23RISK
open ↗Referência✓ VexDay Proof
nweb2fax 0.2.7 - Multiple Vulnerabilities
viewrq.php in nweb2fax 0.2.7 and earlier allows remote attackers to execute arbitrary code via shell metacharacters in t
23RISK
open ↗Referência✓ VexDay Proof
WebChat 0.77 - 'defines.php?WEBCHATPATH' Remote File Inclusion
PHP remote file inclusion vulnerability in defines.php in WebChat 0.77 allows remote attackers to execute arbitrary PHP
23RISK
open ↗Referência✓ VexDay Proof
Apartment Search Script - Arbitrary File Upload / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in listtest.php in Apartment Search Script allows remote attackers to inject ar
23RISK
open ↗Referência✓ VexDay Proof
TeamSpeak 2.0 (Windows Release) - Remote Denial of Service
TeamSpeak WebServer 2.0 for Windows does not validate parameter value lengths and does not expire TCP sessions, which al
23RISK
open ↗Referência✓ VexDay Proof
Maian Weblog 4.0 - Insecure Cookie Handling
admin/index.php in Maian Weblog 4.0 and earlier allows remote attackers to bypass authentication and gain administrative
23RISK
open ↗Referência✓ VexDay Proof
mcGalleryPRO 2006 - 'path_to_folder' Remote File Inclusion
PHP remote file inclusion vulnerability in random2.php in mcGalleryPRO 2006 allows remote attackers to execute arbitrary
23RISK
open ↗Referência✓ VexDay Proof
xeCMS 1.0.0 RC2 - Insecure Cookie Handling
admin.php in xeCMS 1.0.0 RC2 and earlier allows remote attackers to bypass authentication and access the admin panel by
28RISK
open ↗Referência✓ VexDay Proof
Jasmine CMS 1.0 - SQL Injection / Remote Code Execution
Multiple SQL injection vulnerabilities in Jasmine CMS 1.0 allow remote attackers to execute arbitrary SQL commands via (
23RISK
open ↗Referência✓ VexDay Proof
BitDefender Online Scanner 8 - ActiveX Heap Overflow
A certain ActiveX control in (1) OScan8.ocx and (2) Oscan81.ocx in BitDefender Online Anti-Virus Scanner 8.0 allows remo
23RISK
open ↗Referência✓ VexDay Proof
Yahoo! JukeBox MediaGrid - 'AddBitmap()' ActiveX Buffer Overflow
Buffer overflow in the MediaGrid ActiveX control (mediagrid.dll) in Yahoo! Music Jukebox 2.2.2.56 allows remote attacker
23RISK
open ↗Referência✓ VexDay Proof
Pre ADS Portal 2.0 - Authentication Bypass / Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Pre ADS Portal 2.0 and earlier allow remote attackers to inject a
23RISK
open ↗Referência✓ VexDay Proof
TOSMO/Mambo 1.4.13a - 'absolute_path' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in MiniBB Forum 1.5a and earlier, as used by TOSMO/Mambo 4.0.12 and p
23RISK
open ↗Referência✓ VexDay Proof
Pre ADS Portal 2.0 - Authentication Bypass / Cross-Site Scripting
homeadmin/adminhome.php in Pre ADS Portal 2.0 and earlier does not require administrative authentication, which allows r
23RISK
open ↗Referência✓ VexDay Proof
FirmWorX 0.1.2 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in FirmWorX 0.1.2 allow remote attackers to execute arbitrary PHP cod
23RISK
open ↗Referência✓ VexDay Proof
NVR SP2 2.0 'nvUtility.dll 1.0.14.0' - 'DeleteXMLFile()' Insecure Method
Multiple absolute path traversal vulnerabilities in the nvUtility.Utility.1 ActiveX control in nvUtility.dll 1.0.14.0 in
23RISK
open ↗Referência✓ VexDay Proof
MiGCMS 2.0.5 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in MiGCMS 2.0.5, when register_globals is enabled, allow remote attac
23RISK
open ↗Referência✓ VexDay Proof
U&M Software Signup 1.1 - Authentication Bypass
U&M Software Signup 1.0 and 1.1 does not require administrative authentication for all scripts in the admin/ directory,
23RISK
open ↗Referência✓ VexDay Proof
U&M Software Event Lister 1.0 - Authentication Bypass
U&M Software Event Lister (aka JustListIt) 1.0 does not require administrative authentication for all scripts in the adm
23RISK
open ↗Referência✓ VexDay Proof
Durian Web Application Server 3.02 - Denial of Service
Buffer overflow in Durian Web Application Server 3.02 freeware on Windows allows remote attackers to execute arbitrary c
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component rekry 1.0.0 - 'op_id' SQL Injection
SQL injection vulnerability in the Matti Kiviharju rekry (aka com_rekry or rekry!Joom) 1.0.0 component for Joomla! allow
23RISK
open ↗Referência✓ VexDay Proof
DELTAScripts PHP Links 1.3 - Authentication Bypass
SQL injection vulnerability in admin/adm_login.php in DeltaScripts PHP Links 1.3 and earlier allows remote attackers to
23RISK
open ↗Referência✓ VexDay Proof
AJ Article 1.0 - Authentication Bypass
SQL injection vulnerability in index.php in AJ Square AJ Article allows remote attackers to execute arbitrary SQL comman
23RISK
open ↗Referência✓ VexDay Proof
TurnkeyForms Entertainment Portal 2.0 - Insecure Cookie Handling
TurnkeyForms Entertainment Portal 2.0 allows remote attackers to bypass authentication and gain administrative access by
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.