Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,460Referência 22,910GitHub PoC 14,997VulnCheck XDB 8,843Nuclei 4,358Metasploit 3,489✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
Solaris 9 (UltraSPARC) - 'sadmind' Remote Code Execution
Stack-based buffer overflow in the adm_build_path function in sadmind in Sun Solstice AdminSuite on Solaris 8 and 9 allo
50RISK
open ↗Referência✓ VexDay Proof
Opera 9.64 - 7400 nested elements XML Parsing Remote Crash
Opera 9.64 allows remote attackers to cause a denial of service (application crash) via an XML document containing a lon
23RISK
open ↗Referência✓ VexDay Proof
Apple Mac OSX xnu 1228.x - 'hfs-fcntl' Kernel Privilege Escalation
XNU 1228.9.59 and earlier on Apple Mac OS X 10.5.6 and earlier does not properly restrict interaction between user space
23RISK
open ↗Referência✓ VexDay Proof
Real Estate Scripts 2008 - 'cat' SQL Injection
SQL injection vulnerability in index.php in Real Estate Classifieds allows remote attackers to execute arbitrary SQL com
23RISK
open ↗Referência✓ VexDay Proof
Valdersoft Shopping Cart 3.0 - Remote Command Execution
PHP remote file include vulnerability in (1) include/templates/categories/default.php and (2) certain other include/temp
23RISK
open ↗Referência✓ VexDay Proof
Ez Ringtone Manager - Multiple Remote File Disclosure Vulnerabilities
Multiple directory traversal vulnerabilities in Ez Ringtone Manager allow remote attackers to read arbitrary files via a
23RISK
open ↗Referência✓ VexDay Proof
open NewsLetter 2.5 - Multiple Vulnerabilities (2)
Open Newsletter 2.5 and earlier allows remote authenticated administrators to execute arbitrary PHP code by inserting th
23RISK
open ↗Referência✓ VexDay Proof
Apple Mac OSX xnu 1228.3.13 - 'macfsstat' Local Kernel Memory Leak/Denial of Service
Multiple memory leaks in XNU 1228.3.13 and earlier on Apple Mac OS X 10.5.6 and earlier allow local users to cause a den
23RISK
open ↗Referência✓ VexDay Proof
Apple Mac OSX xnu 1228.3.13 - 'Profil' Kernel Memory Leak/Denial of Service (PoC)
Multiple memory leaks in XNU 1228.3.13 and earlier on Apple Mac OS X 10.5.6 and earlier allow local users to cause a den
23RISK
open ↗Referência✓ VexDay Proof
PHPFootball 1.6 - Remote Database Disclosure
show.php in Vlad Alexa Mancini PHPFootball 1.6 allows remote attackers to obtain sensitive information (database content
23RISK
open ↗Referência✓ VexDay Proof
Eserv 3.x - FTP Server (ABOR) Remote Stack Overflow (PoC)
Stack-based buffer overflow in the FTP server in Etype Eserv 3.x, possibly 3.26, allows remote attackers to cause a deni
23RISK
open ↗Referência✓ VexDay Proof
Stash 1.0.3 - SQL Injection User Credentials Disclosure
Multiple SQL injection vulnerabilities in Stash 1.0.3 allow remote attackers to execute arbitrary SQL commands via (1) t
23RISK
open ↗Referência✓ VexDay Proof
Cartweaver 2.16.11 - 'ProdID' SQL Injection
Multiple SQL injection vulnerabilities in Application Dynamics Cartweaver ColdFusion 2.16.11 and earlier allow remote at
23RISK
open ↗Referência✓ VexDay Proof
FlexCMS Calendar - 'itemID' Blind SQL Injection
SQL injection vulnerability in FlexCMS 2.5 allows remote attackers to execute arbitrary SQL commands via the ItemId para
23RISK
open ↗Referência✓ VexDay Proof
OPENi-CMS 1.0.1beta - 'config' Remote File Inclusion
PHP remote file inclusion vulnerability in openi-admin/base/fileloader.php in OPENi-CMS 1.0.1, and possibly earlier, all
23RISK
open ↗Referência✓ VexDay Proof
KGB 1.9 - 'sesskglogadmin.php' Local File Inclusion
Directory traversal vulnerability in sesskglogadmin.php in KGB 1.9 and earlier allows remote attackers to include and ex
23RISK
open ↗Referência✓ VexDay Proof
Campsite 3.3.0 RC1 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Campsite 3.3.0 RC1 allow remote attackers to execute arbitrary PHP
23RISK
open ↗Referência✓ VexDay Proof
Aktueldownload Haber scripti - 'id' SQL Injection
SQL injection vulnerability in HaberDetay.asp in Aktueldownload Haber script allows remote attackers to execute arbitrar
23RISK
open ↗Referência✓ VexDay Proof
PHP-Nuke Module AddressBook 1.2 - Local File Inclusion
Directory traversal vulnerability in addressbook.php in the Addressbook 1.2 module for PHP-Nuke allows remote attackers
23RISK
open ↗Referência✓ VexDay Proof
public media manager 1.3 - Remote File Inclusion
PHP remote file inclusion vulnerability in NewsCMS/news/newstopic_inc.php in North Country Public Radio Public Media Man
23RISK
open ↗Referência✓ VexDay Proof
Simplog 0.9.2 - 's' Remote Command Execution
Dynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb for PHP before 4.70, as used in multiple
28RISK
open ↗Referência✓ VexDay Proof
ClamAV < 0.94.2 - JPEG Parsing Recursive Stack Overflow (PoC)
Stack consumption vulnerability in libclamav/special.c in ClamAV before 0.94.2 allows remote attackers to cause a denial
23RISK
open ↗Referência✓ VexDay Proof
Arab Portal 2.1 (Windows) - Remote File Disclosure
Directory traversal vulnerability in mod.php in Arab Portal 2.1 on Windows allows remote attackers to read arbitrary fil
23RISK
open ↗Referência✓ VexDay Proof
UltraISO 9.3.3.2685 - CCD/IMG Universal Buffer Overflow
Heap-based buffer overflow in Magic ISO Maker 5.5 build 0274 allows remote attackers to cause a denial of service (crash
28RISK
open ↗Referência✓ VexDay Proof
AdaptBB 1.0 - 'topic_id' SQL Injection / Credentials Disclosure
SQL injection vulnerability in inc/bb/topic.php in Insane Visions AdaptBB 1.0, when magic_quotes_gpc is disabled, allows
23RISK
open ↗Referência✓ VexDay Proof
PowerPHPBoard 1.00b - Multiple Local File Inclusions
Multiple directory traversal vulnerabilities in PowerPHPBoard 1.00b allow remote attackers to include and execute arbitr
23RISK
open ↗Referência✓ VexDay Proof
ITechBids 7.0 gold - Cross-Site Scripting / SQL Injection
Cross-site scripting (XSS) vulnerability in forward_to_friend.php in ITechBids 7.0 Gold allows remote attackers to injec
23RISK
open ↗Referência✓ VexDay Proof
Link Request Contact Form 3.4 - Remote Code Execution
Unrestricted file upload vulnerability in Link Request Contact Form 3.4 allows remote attackers to execute arbitrary PHP
23RISK
open ↗Referência✓ VexDay Proof
Simple Machines Forum (SMF) 1.1.3 - Blind SQL Injection
SQL injection vulnerability in Sources/Search.php in Simple Machines Forum (SMF) 1.1.3, when MySQL 5 is used, allows rem
23RISK
open ↗Referência✓ VexDay Proof
easysite 2.3 - Multiple Vulnerabilities
Multiple directory traversal vulnerabilities in EasySite 2.3 allow remote attackers to read arbitrary files or list dire
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.