Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,460Referência 22,910GitHub PoC 14,997VulnCheck XDB 8,843Nuclei 4,358Metasploit 3,489✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
TEC-IT TBarCode - OCX ActiveX Arbitrary File Overwrite
The TEC-IT TBarCode OCX ActiveX control (TBarCode7.ocx) 7.0.2.3524 allows remote attackers to overwrite arbitrary files
23RISK
open ↗Referência✓ VexDay Proof
Mozilla Firefox 3.0.6 - BODY onload Remote Crash
Mozilla Firefox 3.0.5 and earlier 3.0.x versions, when designMode is enabled, allows remote attackers to cause a denial
23RISK
open ↗Referência✓ VexDay Proof
Arcadem LE 2.04 - 'loadadminpage' Remote File Inclusion
PHP remote file inclusion vulnerability in admin/frontpage_right.php in Arcadem LE 2.04 and earlier allows remote attack
23RISK
open ↗Referência✓ VexDay Proof
Microsoft Internet Explorer 7 - Memory Corruption (PoC) (MS09-002)
Microsoft Internet Explorer 7 does not properly handle errors during attempted access to deleted objects, which allows r
60RISK
open ↗Referência✓ VexDay Proof
TYPSoft FTP Server 1.11 - 'ABORT' Remote Denial of Service
TYPSoft FTP Server 1.11 allows remote attackers to cause a denial of service (CPU consumption) by sending an ABOR (abort
23RISK
open ↗Referência✓ VexDay Proof
PHP Live Helper 2.0.1 - Multiple Vulnerabilities
Eval injection vulnerability in globalsoff.php in Turnkey PHP Live Helper 2.0.1 and earlier allows remote attackers to e
23RISK
open ↗Referência✓ VexDay Proof
PHPCollab 2.x / NetOffice 2.x - 'sendpassword.php' SQL Injection
SQL injection vulnerability in general/sendpassword.php in (1) PHPCollab 2.4 and 2.5.rc3, and (2) NetOffice 2.5.3-pl1 an
23RISK
open ↗Referência✓ VexDay Proof
mailwatch 1.0.4 - 'doc' Local File Inclusion
Directory traversal vulnerability in docs.php in MailWatch for MailScanner 1.0.4 and earlier allows remote attackers to
23RISK
open ↗Referência✓ VexDay Proof
PHP 4.4.6/5.2.1 - ext/gd Already Freed Resources Usage
The resource system in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allows context-dependent attackers to execute arb
23RISK
open ↗Referência✓ VexDay Proof
CUPS 1.3.7 - Cross-Site Request Forgery (Add RSS Subscription) Remote Crash
cupsd in CUPS 1.3.9 and earlier allows local users, and possibly remote attackers, to cause a denial of service (daemon
23RISK
open ↗Referência✓ VexDay Proof
WorkSimple 1.2.1 - Remote File Inclusion / Sensitive Data Disclosure
WorkSimple 1.2.1 stores sensitive information under the web root with insufficient access control, which allows remote a
23RISK
open ↗Referência✓ VexDay Proof
yourplace 1.0.2 - Multiple Vulnerabilities / Remote Code Execution
YourPlace 1.0.2 and earlier stores sensitive information under the web root with insufficient access control, which allo
23RISK
open ↗Referência✓ VexDay Proof
ASPThai.Net Forum 8.5 - Remote Database Disclosure
ASPThai.NET ASPThai Forums 8.5 stores sensitive information under the web root with insufficient access control, which a
23RISK
open ↗Referência✓ VexDay Proof
PlaySms 0.9.3 - Multiple Local/Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in playSMS 0.9.3 allow remote attackers to execute arbitrary PHP code
28RISK
open ↗Referência✓ VexDay Proof
Elecard MPEG Player 5.5 - '.m3u' Stack Buffer Overflow (PoC)
Stack-based buffer overflow in Elecard MPEG Player 5.5 build 15884.081218 allows remote attackers to execute arbitrary c
23RISK
open ↗Referência✓ VexDay Proof
Simple Website Software 0.99 - 'common.php' File Inclusion
PHP remote file inclusion vulnerability in common.php in Simple Website Software (SWS) 0.99 and earlier allows remote at
23RISK
open ↗Referência✓ VexDay Proof
EnjoySAP ActiveX rfcguisink.rfcguisink.1 - Remote Heap Overflow (PoC)
Multiple unspecified vulnerabilities in ActiveX controls in the EnjoySAP SAP GUI allow remote attackers to cause a denia
23RISK
open ↗Referência✓ VexDay Proof
EnjoySAP ActiveX kweditcontrol.kwedit.1 - Remote Stack Overflow (PoC)
Multiple unspecified vulnerabilities in ActiveX controls in the EnjoySAP SAP GUI allow remote attackers to create certai
23RISK
open ↗Referência✓ VexDay Proof
EnjoySAP ActiveX rfcguisink.rfcguisink.1 - Remote Heap Overflow (PoC)
Multiple unspecified vulnerabilities in ActiveX controls in the EnjoySAP SAP GUI allow remote attackers to create certai
23RISK
open ↗Referência✓ VexDay Proof
Asterisk 1.2.x - SIP channel driver / in pedantic mode Remote Crash
Asterisk Open Source 1.0.x and 1.2.x before 1.2.29 and Business Edition A.x.x and B.x.x before B.2.5.3, when pedantic pa
23RISK
open ↗Referência✓ VexDay Proof
ezpack 4.2b2 - Cross-Site Scripting / SQL Injection
Cross-site scripting (XSS) vulnerability in index.php in EZpack 4.2b2 allows remote attackers to inject arbitrary web sc
23RISK
open ↗Referência✓ VexDay Proof
FipsCMS 2.1 - 'print.asp' SQL Injection
SQL injection vulnerability in modules/print.asp in fipsASP fipsCMS allows remote attackers to execute arbitrary SQL com
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component xstandard editor 1.5.8 - Local Directory Traversal
Directory traversal vulnerability in attachmentlibrary.php in the XStandard component for Joomla! 1.5.8 and earlier allo
23RISK
open ↗Referência✓ VexDay Proof
PHPLibrary 1.5.3 - 'grid3.lib.php' Remote File Inclusion
PHP remote file inclusion vulnerability in example/lib/grid3.lib.php in Softerra PHP Developer Library 1.5.3 and earlier
23RISK
open ↗Referência✓ VexDay Proof
SubEdit Player build 4066 - subtitle Buffer Overflow (PoC)
Heap-based buffer overflow in SubEdit Player build 4056 and 4066 allows remote attackers to cause a denial of service (c
23RISK
open ↗Referência✓ VexDay Proof
Devalcms 1.4a - Cross-Site Scripting / Remote Code Execution
Cross-site scripting (XSS) vulnerability in index.php in devalcms 1.4a allows remote attackers to inject arbitrary web s
38RISK
open ↗Referência✓ VexDay Proof
AAA EasyGrid ActiveX 3.51 - Remote File Overwrite
Insecure method vulnerability in the EasyGrid.SGCtrl.32 ActiveX control in EasyGrid.ocx 1.0.0.1 in AAA EasyGrid ActiveX
23RISK
open ↗Referência✓ VexDay Proof
WinAsm Studio 5.1.5.0 - Local Heap Overflow (PoC)
Buffer overflow in WinAsm Studio 5.1.5.0 allows user-assisted remote attackers to execute arbitrary code via a crafted p
23RISK
open ↗Referência✓ VexDay Proof
e107 Plugin My_Gallery 2.3 - Arbitrary File Download
Absolute path traversal vulnerability in dload.php in the my_gallery 2.3 plugin for e107 allows remote attackers to obta
23RISK
open ↗Referência✓ VexDay Proof
VUPlayer 2.49 - '.asx' HREF Local Buffer Overflow (PoC)
Stack-based buffer overflow in VUPlayer 2.49 allows remote attackers to execute arbitrary code via a long .asf URI in th
28RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.