Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,460Referência 22,910GitHub PoC 14,997VulnCheck XDB 8,843Nuclei 4,358Metasploit 3,489✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
HIOX Random Ad 1.3 - Remote File Inclusion
PHP remote file inclusion vulnerability in hioxRandomAd.php in HIOX Random Ad (HRA) 1.3 allows remote attackers to execu
23RISK
open ↗Referência✓ VexDay Proof
phpTrafficA 1.4.2 - 'pageid' SQL Injection
Directory traversal vulnerability in index.php in phpTrafficA 1.4.2 and earlier allows remote attackers to include arbit
23RISK
open ↗Referência✓ VexDay Proof
Hotel Reservation System - 'city.asp' Blind SQL Injection
SQL injection vulnerability in city.asp in SoftAcid Hotel Reservation System (HRS) allows remote attackers to execute ar
23RISK
open ↗Referência✓ VexDay Proof
YAP 1.1.1 - Blind SQL Injection / SQL Injection
Multiple SQL injection vulnerabilities in YAP Blog 1.1.1 allow remote attackers to execute arbitrary SQL commands via th
23RISK
open ↗Referência✓ VexDay Proof
ExBB Italiano 0.2 - exbb[home_path] Remote File Inclusion
PHP remote file inclusion vulnerability in modules/userstop/userstop.php in ExBB Italia 0.2 and earlier, when register_g
23RISK
open ↗Referência✓ VexDay Proof
Stash 1.0.3 - Multiple SQL Injections
SQL injection vulnerability in Stash 1.0.3, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitr
23RISK
open ↗Referência✓ VexDay Proof
Scriptsez Easy Image Downloader - Local File Download
Directory traversal vulnerability in main.php in ScriptsEz Easy Image Downloader allows remote attackers to read arbitra
23RISK
open ↗Referência✓ VexDay Proof
FreeBSD 7.0/7.1 - 'ktimer' Local Privilege Escalation
The ktimer feature (sys/kern/kern_time.c) in FreeBSD 7.0, 7.1, and 7.2 allows local users to overwrite arbitrary kernel
23RISK
open ↗Referência✓ VexDay Proof
WFTPD Explorer Pro 1.0 - Remote Heap Overflow (PoC)
Heap-based buffer overflow in Texas Imperial Software WFTPD Pro Explorer 1.0 allows remote FTP servers to execute arbitr
23RISK
open ↗Referência✓ VexDay Proof
VideoLAN VLC Media Player 0.9.8a - Web UI 'input' Remote Denial of Service
requests/status.xml in VLC 0.9.8a allows remote attackers to cause a denial of service (stack consumption and crash) via
23RISK
open ↗Referência✓ VexDay Proof
WebCalendar 1.0.4 - 'includedir' Remote File Inclusion
PHP remote file inclusion vulnerability in send_reminders.php in WebCalendar 1.0.4 allows remote attackers to execute ar
23RISK
open ↗Referência✓ VexDay Proof
BitsCast 0.13.0 - invalid string Remote Denial of Service
BitsCast 0.13.0 allows remote attackers to cause a denial of service (application crash) via an RSS 2.0 feed item with c
23RISK
open ↗Referência✓ VexDay Proof
eZip Wizard 3.0 - Local Stack Buffer Overflow (PoC) (SEH)
Stack-based buffer overflow in ZipGenius might allow remote attackers to execute arbitrary code via a crafted .zip file
23RISK
open ↗Referência✓ VexDay Proof
mUnky 0.0.1 - 'zone' Local File Inclusion
Directory traversal vulnerability in index.php in mUnky 0.0.1 allows remote attackers to include and execute arbitrary l
23RISK
open ↗Referência✓ VexDay Proof
eZip Wizard 3.0 - Local Stack Buffer Overflow (PoC) (SEH)
Stack-based buffer overflow in Trident PowerZip 7.2 might allow remote attackers to execute arbitrary code via a crafted
23RISK
open ↗Referência✓ VexDay Proof
eXeScope 6.50 - Local Buffer Overflow
Buffer overflow in eXeScope 6.50 allows user-assisted remote attackers to execute arbitrary code via a crafted executabl
23RISK
open ↗Referência✓ VexDay Proof
ExBB 0.22 - Local/Remote File Inclusion
ExBB Italia 0.22 and earlier only checks GET requests that use the QUERY_STRING for certain path manipulations, which al
23RISK
open ↗Referência✓ VexDay Proof
Mantis Bug Tracker 1.1.1 - Code Execution / Cross-Site Scripting / Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in manage_user_create.php in Mantis 1.1.1 allows remote attackers to cre
23RISK
open ↗Referência✓ VexDay Proof
Observer 0.3.2.1 - Multiple Remote Command Execution Vulnerabilities
Observer 0.3.2.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the query
28RISK
open ↗Referência✓ VexDay Proof
BS.Player 2.34 - '.bsl' Universal Overwrite (SEH)
Stack-based buffer overflow in BS.Player (bsplayer) 2.32 Build 975 Free and 2.34 Build 980 PRO and earlier allows remote
28RISK
open ↗Referência✓ VexDay Proof
BS.Player 2.34 Build 980 - '.bsl' Local Buffer Overflow (SEH)
Stack-based buffer overflow in BS.Player (bsplayer) 2.32 Build 975 Free and 2.34 Build 980 PRO and earlier allows remote
28RISK
open ↗Referência✓ VexDay Proof
Icarus 2.0 - '.pgn' Local Stack Overflow (SEH)
Stack-based buffer overflow in Icarus 2.0 allows remote attackers to cause a denial of service (application crash) or ex
23RISK
open ↗Referência✓ VexDay Proof
IntelliTamper 2.07 - HTTP Header Remote Code Execution
Stack-based buffer overflow in IntelliTamper 2.07 allows remote web sites to execute arbitrary code via a long HTTP Serv
23RISK
open ↗Referência✓ VexDay Proof
GeoVision LiveAudio - ActiveX Remote Freed-Memory Access
Use-after-free vulnerability in the LIVEAUDIO.LiveAudioCtrl.1 ActiveX control in LIVEAU~1.OCX 7.0 for GeoVision DVR syst
23RISK
open ↗Referência✓ VexDay Proof
BBClone 0.31 - 'selectlang.php' Remote File Inclusion
PHP remote file inclusion vulnerability in lib/selectlang.php in BBClone 0.31 allows remote attackers to execute arbitra
23RISK
open ↗Referência✓ VexDay Proof
cPanel 11.x - 'Fantastico' Local File Inclusion
Directory traversal vulnerability in includes/xml.php in the Netenberg Fantastico De Luxe module before 2.10.4 r19 for c
23RISK
open ↗Referência✓ VexDay Proof
AT Contenator 1.0 - 'Root_To_Script' Remote File Inclusion
PHP remote file inclusion vulnerability in _admin/nav.php in AT Contenator 1.0 and earlier allows remote attackers to ex
23RISK
open ↗Referência✓ VexDay Proof
CenterIM 4.22.3 - Remote Command Execution
CenterIM 4.22.3 and earlier allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters
23RISK
open ↗Referência✓ VexDay Proof
phpBB Import Tools Mod 0.1.4 - Remote File Inclusion
PHP remote file inclusion vulnerability in includes/functions_mod_user.php in phpBB Import Tools Mod 0.1.4 and earlier a
23RISK
open ↗Referência✓ VexDay Proof
Hot Links SQL-PHP 3 - 'report.php' Multiple Vulnerabilities
SQL injection vulnerability in report.php in Mr. CGI Guy Hot Links SQL-PHP 3.0 and earlier allows remote attackers to ex
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.