Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,464Referência 22,936GitHub PoC 15,010VulnCheck XDB 8,846Nuclei 4,361Metasploit 3,490✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
FreeCMS.us 0.2 - 'index.php' SQL Injection
SQL injection vulnerability in index.php in FreeCMS 0.2 allows remote attackers to execute arbitrary SQL commands via th
23RISK
open ↗Referência✓ VexDay Proof
mystats - 'hits.php' Multiple Vulnerabilities
hits.php in myWebland myStats allows remote attackers to bypass IP address restrictions via a modified X-Forwarded-For H
23RISK
open ↗Referência✓ VexDay Proof
Yerba SACphp 6.3 - Multiple Vulnerabilities
Yerba SACphp 6.3 and earlier allows remote attackers to bypass authentication and gain administrative access via a galle
23RISK
open ↗Referência✓ VexDay Proof
ravennuke 2.3.0 - Multiple Vulnerabilities
Eval injection vulnerability in the Custom Fields feature in the Your Account module in Raven Web Services RavenNuke 2.3
23RISK
open ↗Referência✓ VexDay Proof
Oxygen 2.0 - 'repquote' SQL Injection
SQL injection vulnerability in post.php in Oxygen (aka O2PHP Bulletin Board) 2.0 allows remote attackers to execute arbi
23RISK
open ↗Referência✓ VexDay Proof
BASE 1.2.4 - melissa Snort Frontend Remote File Inclusion
PHP remote file inclusion vulnerability in Basic Analysis and Security Engine (BASE) 1.2.4 and earlier, with register_gl
50RISK
open ↗Referência✓ VexDay Proof
CCleague Pro 1.0.1RC1 - 'cookie' Remote Code Execution
Directory traversal vulnerability in admin.php in CCleague Pro Sports CMS 1.0.1 RC1 allows remote attackers to read and
23RISK
open ↗Referência✓ VexDay Proof
SlimCMS 1.0.0 - 'redirect.php' Privilege Escalation
redirect.php in SlimCMS 1.0.0 does not require authentication, which allows remote attackers to create administrative us
23RISK
open ↗Referência✓ VexDay Proof
GL-SH Deaf Forum 6.4.4 - Local File Inclusion
Multiple directory traversal vulnerabilities in GL-SH Deaf Forum 6.4.4 and earlier allow remote attackers to include and
23RISK
open ↗Referência✓ VexDay Proof
RPortal 1.1 - 'file_op' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in RPortal 1.1 and earlier allows remote attackers to execute arbit
23RISK
open ↗Referência✓ VexDay Proof
Scribe 0.2 - PHP Remote Code Execution
Directory traversal vulnerability in forum.php in Ben Ng Scribe 0.2 and earlier allows remote attackers to create or ove
23RISK
open ↗Referência✓ VexDay Proof
Easy-Clanpage 3.0b1 - 'section' Local File Inclusion
Directory traversal vulnerability in Easy-Clanpage 3.0 b1 allows remote attackers to include and execute arbitrary local
23RISK
open ↗Referência✓ VexDay Proof
registroTL - 'main.php' Remote File Inclusion
registroTL stores sensitive information under the web root with insufficient access control, which allows remote attacke
23RISK
open ↗Referência✓ VexDay Proof
DodosMail 2.0.1 - 'dodosmail.php' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in dodosmail.php in DodosMail 2.0.1 and earlier, and possibly 2.1, al
23RISK
open ↗Referência✓ VexDay Proof
Web Wiz Rich Text Editor 4.0 - Multiple Vulnerabilities
RTE_popup_save_file.asp in Web Wiz Rich Text Editor 4.0 allows remote attackers to upload (1) .html and (2) .htm files v
23RISK
open ↗Referência✓ VexDay Proof
Noticeware Email Server 4.6.1.0 - Denial of Service
MailServer.exe in NoticeWare Email Server 4.6.1.0 allows remote attackers to cause a denial of service (application cras
23RISK
open ↗Referência✓ VexDay Proof
Scientific Image DataBase 0.41 - Blind SQL Injection
SQL injection vulnerability in projects.php in Scientific Image DataBase 0.41 allows remote attackers to execute arbitra
23RISK
open ↗Referência✓ VexDay Proof
Online Grades 3.2.4 - Authentication Bypass
Online Grades 3.2.4 allows remote attackers to obtain configuration information via a direct request to phpinfo.php, whi
23RISK
open ↗Referência✓ VexDay Proof
DMXReady Registration Manager 1.1 - Database Disclosure
DMXReady Registration Manager 1.1 stores sensitive information under the web root with insufficient access control, whic
23RISK
open ↗Referência✓ VexDay Proof
Blog PixelMotion - 'sauvBase.php' Arbitrary Database Backup
admin/sauvBase.php in Blog Pixel Motion (aka Blog PixelMotion) does not require authentication, which allows remote atta
23RISK
open ↗Referência✓ VexDay Proof
SimpleBlog 2.0 - 'comments.asp' SQL Injection (1)
SQL injection vulnerability in comments.asp in SimpleBlog 2.0 and earlier allows remote attackers to execute arbitrary S
23RISK
open ↗Referência✓ VexDay Proof
Barman 0.0.1r3 - 'Interface.php' Remote File Inclusion
PHP remote file inclusion vulnerability in interface.php in Barman 0.0.1r3 allows remote attackers to execute arbitrary
23RISK
open ↗Referência✓ VexDay Proof
realm CMS 2.3 - Multiple Vulnerabilities
Realm CMS 2.3 and earlier allows remote attackers to obtain sensitive information via a direct request to _db/compact.as
23RISK
open ↗Referência✓ VexDay Proof
Thickbox Gallery 2.0 - 'Admins.php' Admin Data Disclosure
Davlin Thickbox Gallery 2 allows remote attackers to obtain the administrative username and MD5 password hash via a dire
23RISK
open ↗Referência✓ VexDay Proof
nightfall personal diary 1.0 - Cross-Site Scripting / File Disclosure
Nightfall Personal Diary 1.0 stores sensitive information under the web root with insufficient access control, which all
23RISK
open ↗Referência✓ VexDay Proof
PHP Site Lock 2.0 - Insecure Cookie Handling
index.php in PHP Site Lock 2.0 allows remote attackers to bypass authentication and obtain administrative access by sett
23RISK
open ↗Referência✓ VexDay Proof
DM FileManager 3.9.2 - Insecure Cookie Handling
admin/login.php in DM FileManager 3.9.2 allows remote attackers to bypass authentication and gain administrative access
23RISK
open ↗Referência✓ VexDay Proof
OwnRS blog beta3 - SQL Injection / Cross-Site Scripting
SQL injection vulnerability in clanek.php in OwnRS Beta 3 allows remote attackers to execute arbitrary SQL commands via
23RISK
open ↗Referência✓ VexDay Proof
Techno Dreams Articles & Papers 2.0 - SQL Injection
SQL injection vulnerability in ArticlesTableview.asp in Techno Dreams Articles & Papers Package 2.0 and earlier allows r
23RISK
open ↗Referência✓ VexDay Proof
Flatnuke 3 - Remote Command Execution / Privilege Escalation
index.php in the File Manager module in Flatnuke 3 allows remote attackers to obtain sensitive information via an invali
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.