Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,460Referência 22,910GitHub PoC 14,997VulnCheck XDB 8,843Nuclei 4,358Metasploit 3,489✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
adaptweb 0.9.2 - Local File Inclusion / SQL Injection
SQL injection vulnerability in a_index.php in AdaptWeb 0.9.2 allows remote attackers to execute arbitrary SQL commands v
23RISK
open ↗Referência✓ VexDay Proof
ScriptsFeed (SF) Recipes Listing Portal - Arbitrary File Upload
Unrestricted file upload vulnerability in ScriptsFeed Recipes Listing Portal allows remote authenticated users to execut
23RISK
open ↗Referência✓ VexDay Proof
AJ Article 1.0 - Remote Authentication Bypass
AJ Square AJ Article allows remote attackers to bypass authentication and access administrator functionality via a direc
23RISK
open ↗Referência✓ VexDay Proof
Pre Real Estate Listings - Arbitrary File Upload
Unrestricted file upload vulnerability in profile.php in Pre Projects Pre Real Estate Listings allows remote authenticat
23RISK
open ↗Referência✓ VexDay Proof
TorrentTrader Classic 1.09 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in TorrentTrader Classic 1.09 allow remote authenticated users to execute arbitra
23RISK
open ↗Referência✓ VexDay Proof
Kjtechforce mailman b1 - Delete Row 'code' SQL Injection
Multiple SQL injection vulnerabilities in Kjtechforce mailman beta1, when magic_quotes_gpc is disabled, allow remote att
23RISK
open ↗Referência✓ VexDay Proof
EgyPlus 7ml 1.0.1 - Authentication Bypass
cpanel/login.php in EgyPlus 7ammel (aka 7ml) 1.0.1 and earlier sends a redirect to the web browser but does not exit whe
53RISK
open ↗Referência✓ VexDay Proof
Carom3D 5.06 - Unicode Buffer Overrun/Denial of Service
The LAN game feature in Carom3D 5.06 allows remote authenticated users to cause a denial of service (application hang) v
23RISK
open ↗Referência✓ VexDay Proof
Fuzzylime CMS 3.03a - Local Inclusion / Arbitrary File Corruption
Multiple directory traversal vulnerabilities in fuzzylime (cms) 3.03a and earlier, when magic_quotes_gpc is disabled, al
23RISK
open ↗Referência✓ VexDay Proof
Nero ShowTime 5.0.15.0 - '.m3u' Playlist File Remote Buffer Overflow (PoC)
Buffer overflow in Nero ShowTime 5.0.15.0 allows remote attackers to cause a denial of service (crash) and possibly exec
23RISK
open ↗Referência✓ VexDay Proof
ReVou Twitter Clone - Authentication Bypass
Multiple SQL injection vulnerabilities in ReVou Micro Blogging Twitter clone allow remote attackers to execute arbitrary
23RISK
open ↗Referência✓ VexDay Proof
HockeySTATS Online 2.0 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in TheHockeyStop HockeySTATS Online 2.0 Basic and Advanced allow remote attackers
23RISK
open ↗Referência✓ VexDay Proof
Mercury/32 Mail SMTPD - Remote Stack Overrun (PoC)
Stack-based buffer overflow in the MercuryS SMTP server in Mercury Mail Transport System, possibly 4.51 and earlier, all
50RISK
open ↗Referência✓ VexDay Proof
IBM Domino Web Access Upload Module - 'dwa7w.dll' Remote Buffer Overflow
Multiple stack-based buffer overflows in the IBM Lotus Domino Web Access ActiveX control, as provided by inotes6.dll, in
50RISK
open ↗Referência✓ VexDay Proof
Mozilla Firefox 3.0.5 - Status Bar Obfuscation / Clickjacking
Mozilla Firefox 3.0.5 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action that
23RISK
open ↗Referência✓ VexDay Proof
Multiple Vendor - PF Null Pointer Dereference
The pf_test_rule function in OpenBSD Packet Filter (PF), as used in OpenBSD 4.2 through 4.5, NetBSD 5.0 before RC3, MirO
23RISK
open ↗Referência✓ VexDay Proof
OpenBSD 4.5 - IP datagrams Remote Denial of Service
The pf_test_rule function in OpenBSD Packet Filter (PF), as used in OpenBSD 4.2 through 4.5, NetBSD 5.0 before RC3, MirO
23RISK
open ↗Referência✓ VexDay Proof
phpBB Mod Ktauber.com StylesDemo - Blind SQL Injection
SQL injection vulnerability in index.php in the Ktauber.com StylesDemo mod for phpBB 2.0.xx allows remote attackers to e
23RISK
open ↗Referência✓ VexDay Proof
iziContents rc6 - Local/Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in iziContents 1 RC6 and earlier allow remote attackers to execute ar
35RISK
open ↗Referência✓ VexDay Proof
CMS Made Simple 1.2 - Remote Code Execution
Eval injection vulnerability in adodb-perf-module.inc.php in ADOdb Lite 1.42 and earlier, as used in products including
28RISK
open ↗Referência✓ VexDay Proof
Journalness 4.1 - 'last_module' Remote Code Execution
Eval injection vulnerability in adodb-perf-module.inc.php in ADOdb Lite 1.42 and earlier, as used in products including
28RISK
open ↗Referência✓ VexDay Proof
Zervit Web Server 0.02 - Remote Buffer Overflow (PoC)
Buffer overflow in the http_parse_hex function in libz/misc.c in Zervit Webserver 0.02 allows remote attackers to cause
23RISK
open ↗Referência✓ VexDay Proof
Elecard AVC HD Player - '.XPL' Stack Buffer Overflow (SEH) (PoC)
Stack-based buffer overflow in Elecard AVC HD Player allows remote attackers to execute arbitrary code via a long MP3 fi
23RISK
open ↗Referência✓ VexDay Proof
BaoFeng - ActiveX 'OnBeforeVideoDownload()' Remote Buffer Overflow
Stack-based buffer overflow in the MPS.StormPlayer.1 ActiveX control in mps.dll 3.9.4.27 in Baofeng Storm allows remote
50RISK
open ↗Referência✓ VexDay Proof
Easy Scripts Answer and Question Script - Multiple Vulnerabilities
myaccount.php in Easy Scripts Answer and Question Script does not verify the original password before changing passwords
23RISK
open ↗Referência✓ VexDay Proof
Soulseek 157 NS x/156.x - Remote Distributed Search Code Execution
Stack-based buffer overflow in Soulseek 156 and 157 NS allows remote attackers to execute arbitrary code via a long sear
23RISK
open ↗Referência✓ VexDay Proof
Winamp 5.55 - MAKI Script Universal Overwrite (SEH)
The Nullsoft Modern Skins Support module (gen_ff.dll) in Nullsoft Winamp before 5.552 allows remote attackers to execute
50RISK
open ↗Referência✓ VexDay Proof
phpBugTracker 1.0.3 - Authentication Bypass
SQL injection vulnerability in index.php in phpBugTracker 1.0.3 allows remote attackers to execute arbitrary SQL command
23RISK
open ↗Referência✓ VexDay Proof
OCS Inventory NG 1.02 - Remote File Disclosure
Absolute path traversal vulnerability in cvs.php in OCS Inventory NG before 1.02.1 on Unix allows remote attackers to re
23RISK
open ↗Referência✓ VexDay Proof
vBulletin Radio and TV Player AddOn - HTML Injection
Cross-site scripting (XSS) vulnerability in forum/radioandtv.php in the Radio and TV Player addon for vBulletin allows r
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.