Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,460Referência 22,910GitHub PoC 14,997VulnCheck XDB 8,843Nuclei 4,358Metasploit 3,489✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
Neat weblog 0.2 - 'articleId' SQL Injection
SQL injection vulnerability in index.php in Neat weblog 0.2 allows remote attackers to execute arbitrary SQL commands vi
23RISK
open ↗Referência✓ VexDay Proof
phpMyPortal 3.0.0 RC3 - GLOBALS[CHEMINMODULES] Remote File Inclusion
PHP remote file inclusion vulnerability in inc/articles.inc.php in phpMyPortal 3.0.0 RC3 allows remote attackers to exec
23RISK
open ↗Referência✓ VexDay Proof
Maian Links 3.1 - Insecure Cookie Handling
admin/index.php in Maian Links 3.1 and earlier allows remote attackers to bypass authentication and gain administrative
23RISK
open ↗Referência✓ VexDay Proof
PHP 'Perl' Extension - 'Safe_mode' Bypass
The perl extension in PHP does not follow safe_mode restrictions, which allows context-dependent attackers to execute ar
23RISK
open ↗Referência✓ VexDay Proof
yourplace 1.0.2 - Multiple Vulnerabilities / Remote Code Execution
YourPlace 1.0.2 and earlier allows remote attackers to obtain sensitive system information via a direct request via a di
23RISK
open ↗Referência✓ VexDay Proof
SFS EZ Affiliate - 'cat_id' SQL Injection
SQL injection vulnerability in directory.php in Scripts for Sites (SFS) SFS EZ Affiliate allows remote attackers to exec
23RISK
open ↗Referência✓ VexDay Proof
Charrays CMS 0.9.3 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Charray's CMS 0.9.3 allow remote attackers to execute arbitrary PH
23RISK
open ↗Referência✓ VexDay Proof
Woltlab Burning Board Addon JGS-Treffen 2.0.2 - SQL Injection
SQL injection vulnerability in jgs_treffen.php in the JGS-XA JGS-Treffen 2.0.2 and earlier addon for Woltlab Burning Boa
23RISK
open ↗Referência✓ VexDay Proof
SFS EZ Gaming Directory - 'cat_id' SQL Injection
SQL injection vulnerability in directory.php in Sites for Scripts (SFS) Gaming Directory allows remote attackers to exec
23RISK
open ↗Referência✓ VexDay Proof
Oracle 10g - MDSYS.SDO_TOPO_DROP_FTBL SQL Injection (Metasploit)
Unspecified vulnerability in the Oracle Spatial component in Oracle Database 10.1.0.5 and 10.2.0.2 allows remote authent
50RISK
open ↗Referência✓ VexDay Proof
SFS EZ Home Business Directory - 'cat_id' SQL Injection
SQL injection vulnerability in directory.php in Sites for Scripts (SFS) EZ Home Business Directory allows remote attacke
23RISK
open ↗Referência✓ VexDay Proof
Mini File Host 1.x - Arbitrary '.PHP' File Upload
Unrestricted file upload vulnerability in Mini File Host 1.5 allows remote attackers to execute arbitrary code by upload
23RISK
open ↗Referência✓ VexDay Proof
Lizardware CMS 0.6.0 - Blind SQL Injection
SQL injection vulnerability in administrator/index.php in Lizardware CMS 0.6.0 and earlier allows remote attackers to ex
23RISK
open ↗Referência✓ VexDay Proof
bugmall shopping cart 2.5 - SQL Injection / Cross-Site Scripting
BugMall Shopping Cart 2.5 and earlier has a default username "demo" and password "demo," which allows remote attackers t
23RISK
open ↗Referência✓ VexDay Proof
WordPress Plugin Wp-FileManager 1.2 - Arbitrary File Upload
Unrestricted file upload vulnerability in ajaxfilemanager.php in the Wp-FileManager 1.2 plugin for WordPress allows remo
23RISK
open ↗Referência✓ VexDay Proof
Titan FTP Server 6.03 - 'USER/PASS' Remote Heap Overflow (PoC)
Multiple heap-based buffer overflows in Titan FTP Server 6.03 and 6.0.5.549 allow remote attackers to cause a denial of
38RISK
open ↗Referência✓ VexDay Proof
MindDezign Photo Gallery 2.2 - SQL Injection
SQL injection vulnerability in MindDezign Photo Gallery 2.2, when magic_quotes_gpc is disabled, allows remote attackers
23RISK
open ↗Referência✓ VexDay Proof
PumpKIN TFTP Server 2.7.2.0 - Denial of Service (Metasploit)
PumpKIN TFTP Server 2.7.2.0 allows remote attackers to cause a denial of service via a write request with a long mode fi
23RISK
open ↗Referência✓ VexDay Proof
EnjoySAP ActiveX rfcguisink.rfcguisink.1 - Remote Heap Overflow (PoC)
Heap-based buffer overflow in the rfcguisink.rfcguisink.1 ActiveX control in the EnjoySAP SAP GUI, on systems using ASCI
23RISK
open ↗Referência✓ VexDay Proof
jspwiki 2.4.104/2.5.139 - Multiple Vulnerabilities
Directory traversal vulnerability in Edit.jsp in JSPWiki 2.4.104 and 2.5.139 allows remote attackers to include and exec
23RISK
open ↗Referência✓ VexDay Proof
AuraCMS 2.x - '/user.php' Security Code Bypass / Arbitrary Add Administrator
SQL injection vulnerability in content/user.php in AuraCMS 2.2.1 and earlier, when magic_quotes_gpc is disabled, allows
23RISK
open ↗Referência✓ VexDay Proof
Vibro-School-CMS - 'nID' SQL Injection
SQL injection vulnerability in view_news.php in nicLOR Vibro-School-CMS allows remote attackers to execute arbitrary SQL
23RISK
open ↗Referência✓ VexDay Proof
Pre Real Estate Listings - Authentication Bypass
SQL injection vulnerability in manager/login.php in Pre Projects Pre Real Estate Listings allows remote attackers to exe
23RISK
open ↗Referência✓ VexDay Proof
acronis pxe server 2.0.0.1076 - Directory Traversal / Null Pointer
The PXE Server (pxesrv.exe) in Acronis Snap Deploy 2.0.0.1076 and earlier allows remote attackers to cause a denial of s
23RISK
open ↗Referência✓ VexDay Proof
BuzzyWall 1.3.1 - 'id' Remote File Disclosure
Directory traversal vulnerability in download.php in BuzzyWall 1.3.1 allows remote attackers to read arbitrary local fil
23RISK
open ↗Referência✓ VexDay Proof
Pre Real Estate Listings - Arbitrary File Upload
Multiple SQL injection vulnerabilities in login.php in Pre Projects Pre Real Estate Listings allow remote attackers to e
23RISK
open ↗Referência✓ VexDay Proof
7Shop 1.1 - Arbitrary File Upload
Unrestricted file upload vulnerability in includes/imageupload.php in 7Shop 1.1 and earlier allows remote attackers to e
23RISK
open ↗Referência✓ VexDay Proof
Tumbleweed SecureTransport 4.6.1 FileTransfer - ActiveX Buffer Overflow
Stack-based buffer overflow in the IActiveXTransfer.FileTransfer method in the SecureTransport FileTransfer ActiveX cont
50RISK
open ↗Referência✓ VexDay Proof
Booking Centre 2.01 - 'HotelID' SQL Injection
SQL injection vulnerability in hotel_habitaciones.php in Venalsur Booking Centre Booking System for Hotels Group 2.01 al
23RISK
open ↗Referência✓ VexDay Proof
Booking Centre 2.01 - Authentication Bypass
Multiple SQL injection vulnerabilities in admin/checklogin.php in Venalsur Booking Centre Booking System for Hotels Grou
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.