Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,460Referência 22,910GitHub PoC 14,997VulnCheck XDB 8,843Nuclei 4,358Metasploit 3,489✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
Barracuda Web Application Firewall - Authentication Bypass
Barracuda Web Application Firewall (WAF) 7.8.1.013 allows remote attackers to bypass authentication by leveraging a perm
28RISK
open ↗Referência✓ VexDay Proof
QuickTicket 1.5 - 'qti_usr.php' SQL Injection
Multiple SQL injection vulnerabilities in QuickTicket 1.2 build:20070621 and QuickTalk Forum 1.3 allow remote attackers
23RISK
open ↗Referência✓ VexDay Proof
Microsoft Visual 6 - 'VDT70.dll NotSafe' Remote Stack Overflow
Stack-based buffer overflow in a certain ActiveX control in VDT70.DLL in Microsoft Visual Database Tools Database Design
28RISK
open ↗Referência✓ VexDay Proof
CMS Made Simple 1.2.4 Module FileManager - Arbitrary File Upload
Incomplete blacklist vulnerability in javaUpload.php in Postlet in the FileManager module in CMS Made Simple 1.2.4 and e
23RISK
open ↗Referência✓ VexDay Proof
mxCamArchive 2.2 - Bypass Configuration Download
Static code injection vulnerability in admin/admin.php in mxCamArchive 2.2 allows remote authenticated administrators to
23RISK
open ↗Referência✓ VexDay Proof
dBpowerAMP Audio Player 2 - '.m3u' Remote Buffer Overflow
Buffer overflow in dBpowerAMP Audio Player Release 2 allows remote attackers to execute arbitrary code via a .M3U file w
23RISK
open ↗Referência✓ VexDay Proof
PNPHPBB2 < 1.2i - 'ModName' Multiple Local File Inclusions
Multiple directory traversal vulnerabilities in PNphpBB2 1.2i and earlier allow remote attackers to include and execute
28RISK
open ↗Referência✓ VexDay Proof
phpskelsite 1.4 - Local File Inclusion / Remote File Inclusion / Cross-Site Scripting
Directory traversal vulnerability in skysilver/login.tpl.php in phpSkelSite 1.4, when register_globals is enabled, allow
23RISK
open ↗Referência✓ VexDay Proof
w3blabor CMS 3.3.0 - Authentication Bypass
SQL injection vulnerability in admin/index.php in w3b>cms (aka w3blabor CMS) before 3.4.0, when magic_quotes_gpc is disa
23RISK
open ↗Referência✓ VexDay Proof
FlashBlog 0.31b - Arbitrary File Upload
Unrestricted file upload vulnerability in admin/Editor/imgupload.php in FlashBlog 0.31 beta allows remote attackers to e
23RISK
open ↗Referência✓ VexDay Proof
Magic CMS 4.2.747 - 'mysave.php' Remote File Inclusion
PHP remote file inclusion vulnerability in mysave.php in Magic CMS 4.2.747 allows remote attackers to execute arbitrary
23RISK
open ↗Referência✓ VexDay Proof
NUVICO DVR NVDV4 / PdvrAtl Module 'PdvrAtl.DLL 1.0.1.25' - Remote Buffer Overflow
Heap-based buffer overflow in the PdvrAtl.PdvrOcx.1 ActiveX control (pdvratl.dll) in DVRHOST Web CMS OCX 1.0.1.25 allows
28RISK
open ↗Referência✓ VexDay Proof
PHPMesFilms 1.0 - 'index.php?id' SQL Injection
SQL injection vulnerability in index.php in PhpMesFilms 1.0 and 1.8 allows remote attackers to execute arbitrary SQL com
23RISK
open ↗Referência✓ VexDay Proof
Amber Script 1.0 - 'show_content.php?id' Local File Inclusion
Directory traversal vulnerability in scripts/include/show_content.php in Amber Script 1.0 allows remote attackers to inc
23RISK
open ↗Referência✓ VexDay Proof
XOOPS mod_gallery Zend_Hash_key + Extract - Remote File Inclusion
PHP remote file inclusion vulnerability in xoopsgallery/init_basic.php in the mod_gallery module for XOOPS, when registe
23RISK
open ↗Referência✓ VexDay Proof
Omegaboard 1.0beta4 - 'functions.php' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/functions.php in Omegaboard 1.0beta4 and earlier allows remote attac
23RISK
open ↗Referência✓ VexDay Proof
Scripteen Free Image Hosting Script 1.2 - 'cookie' Pass Grabber
Scripteen Free Image Hosting Script 1.2 and 1.2.1 allows remote attackers to bypass authentication and gain administrati
23RISK
open ↗Referência✓ VexDay Proof
Jaws 0.8.8 - Multiple Local File Inclusions
Directory traversal vulnerability in index.php in Jaws 0.8.8 allows remote authenticated users to read arbitrary files v
23RISK
open ↗Referência✓ VexDay Proof
4Site CMS 2.6 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in 4Site CMS 2.6 and earlier allow remote attackers to execute arbitrary SQL comm
23RISK
open ↗Referência✓ VexDay Proof
Nokia N95-8 browser - 'setAttributeNode' Method Crash
The web browser in Symbian OS on the Nokia N95 cell phone allows remote attackers to cause a denial of service (crash) v
23RISK
open ↗Referência✓ VexDay Proof
Nessus Vulnerability Scanner 3.0.6 - ActiveX Command Execution
Directory traversal vulnerability in a certain ActiveX control in Nessus Vulnerability Scanner 3.0.6 allows remote attac
28RISK
open ↗Referência✓ VexDay Proof
Microsoft DirectX SAMI File Parsing - Remote Stack Overflow
Stack-based buffer overflow in the DirectShow Synchronized Accessible Media Interchange (SAMI) parser in quartz.dll for
50RISK
open ↗Referência✓ VexDay Proof
Joomla! Component Expose RC35 - Arbitrary File Upload
uploadimg.php in the Expose RC35 and earlier (com_expose) component for Joomla! sends an error message but does not exit
23RISK
open ↗Referência✓ VexDay Proof
Electronics Workbench - '.ewb' Local Stack Overflow (PoC)
Stack-based buffer overflow in National Instruments Electronics Workbench allows user-assisted attackers to cause a deni
23RISK
open ↗Referência✓ VexDay Proof
ravennuke 2.3.0 - Multiple Vulnerabilities
SQL injection vulnerability in the Resend_Email module in Raven Web Services RavenNuke 2.30 allows remote authenticated
23RISK
open ↗Referência✓ VexDay Proof
Morovia Barcode ActiveX Professional 3.3.1304 - Arbitrary File Overwrite
A certain ActiveX control in Morovia Barcode ActiveX Professional 3.3.1304 allows remote attackers to overwrite arbitrar
23RISK
open ↗Referência✓ VexDay Proof
A-shop 0.70 - Remote File Deletion
Multiple SQL injection vulnerabilities in A-shop 0.70 and earlier allow remote attackers to execute arbitrary SQL comman
23RISK
open ↗Referência✓ VexDay Proof
eCentrex VOIP Client module - 'uacomx.ocx 2.0.1' Remote Buffer Overflow
Buffer overflow in the IUAComFormX ActiveX control in uacomx.ocx 2.0.1 in the eCentrex VOIP Client module allows remote
23RISK
open ↗Referência✓ VexDay Proof
dotCMS 1.6 - 'id' Local File Inclusion
Multiple directory traversal vulnerabilities in dotCMS 1.6.0.9 allow remote attackers to read arbitrary files via a .. (
23RISK
open ↗Referência✓ VexDay Proof
Advanced Electron Forum 1.0.6 - Remote Code Execution
Electron Inc. Advanced Electron Forum before 1.0.7 allows remote attackers to execute arbitrary PHP code via PHP code em
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.