Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,465Referência 23,022GitHub PoC 15,031VulnCheck XDB 8,860Nuclei 4,361Metasploit 3,491✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
DodosMail 2.0.1 - 'dodosmail.php' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in dodosmail.php in DodosMail 2.0.1 and earlier, and possibly 2.1, al
23RISK
open ↗Referência✓ VexDay Proof
PHPEasyNews 1.13 RC2 - 'POST' SQL Injection
SQL injection vulnerability in newsarchive.php in PHPeasyblog (formerly phpeasynews) 1.13 RC2 and earlier allows remote
23RISK
open ↗Referência✓ VexDay Proof
gCards 1.45 - Multiple Vulnerabilities
SQL injection vulnerability in loginfunction.php in Greg Neustaetter gCards 1.45 and earlier allows remote attackers to
23RISK
open ↗Referência✓ VexDay Proof
APC ActionApps CMS 2.8.1 - Remote File Inclusion
PHP remote file inclusion vulnerabilities in ActionApps 2.8.1 allow remote attackers to execute arbitrary PHP code via a
28RISK
open ↗Referência✓ VexDay Proof
Socketwiz BookMarks 2.0 - 'root_dir' Remote File Inclusion
PHP remote file inclusion vulnerability in smarty_config.php in Socketwiz Bookmarks 2.0 and earlier allows remote attack
23RISK
open ↗Referência✓ VexDay Proof
NetProxy 4.03 - Web Filter Evasion / Bypass Logging
Grok Developments NetProxy 4.03 allows remote attackers to bypass URL filtering via a request that omits "http://" from
23RISK
open ↗Referência✓ VexDay Proof
Web Wiz Rich Text Editor 4.0 - Multiple Vulnerabilities
RTE_popup_save_file.asp in Web Wiz Rich Text Editor 4.0 allows remote attackers to upload (1) .html and (2) .htm files v
23RISK
open ↗Referência✓ VexDay Proof
Noticeware Email Server 4.6.1.0 - Denial of Service
MailServer.exe in NoticeWare Email Server 4.6.1.0 allows remote attackers to cause a denial of service (application cras
23RISK
open ↗Referência✓ VexDay Proof
Scientific Image DataBase 0.41 - Blind SQL Injection
SQL injection vulnerability in projects.php in Scientific Image DataBase 0.41 allows remote attackers to execute arbitra
23RISK
open ↗Referência✓ VexDay Proof
Online Grades 3.2.4 - Authentication Bypass
Online Grades 3.2.4 allows remote attackers to obtain configuration information via a direct request to phpinfo.php, whi
23RISK
open ↗Referência✓ VexDay Proof
DMXReady Registration Manager 1.1 - Database Disclosure
DMXReady Registration Manager 1.1 stores sensitive information under the web root with insufficient access control, whic
23RISK
open ↗Referência✓ VexDay Proof
Blog PixelMotion - 'sauvBase.php' Arbitrary Database Backup
admin/sauvBase.php in Blog Pixel Motion (aka Blog PixelMotion) does not require authentication, which allows remote atta
23RISK
open ↗Referência✓ VexDay Proof
SimpleBlog 2.0 - 'comments.asp' SQL Injection (1)
SQL injection vulnerability in comments.asp in SimpleBlog 2.0 and earlier allows remote attackers to execute arbitrary S
23RISK
open ↗Referência✓ VexDay Proof
Barman 0.0.1r3 - 'Interface.php' Remote File Inclusion
PHP remote file inclusion vulnerability in interface.php in Barman 0.0.1r3 allows remote attackers to execute arbitrary
23RISK
open ↗Referência✓ VexDay Proof
realm CMS 2.3 - Multiple Vulnerabilities
Realm CMS 2.3 and earlier allows remote attackers to obtain sensitive information via a direct request to _db/compact.as
23RISK
open ↗Referência✓ VexDay Proof
Thickbox Gallery 2.0 - 'Admins.php' Admin Data Disclosure
Davlin Thickbox Gallery 2 allows remote attackers to obtain the administrative username and MD5 password hash via a dire
23RISK
open ↗Referência✓ VexDay Proof
nightfall personal diary 1.0 - Cross-Site Scripting / File Disclosure
Nightfall Personal Diary 1.0 stores sensitive information under the web root with insufficient access control, which all
23RISK
open ↗Referência✓ VexDay Proof
PHP Site Lock 2.0 - Insecure Cookie Handling
index.php in PHP Site Lock 2.0 allows remote attackers to bypass authentication and obtain administrative access by sett
23RISK
open ↗Referência✓ VexDay Proof
DM FileManager 3.9.2 - Insecure Cookie Handling
admin/login.php in DM FileManager 3.9.2 allows remote attackers to bypass authentication and gain administrative access
23RISK
open ↗Referência✓ VexDay Proof
OwnRS blog beta3 - SQL Injection / Cross-Site Scripting
SQL injection vulnerability in clanek.php in OwnRS Beta 3 allows remote attackers to execute arbitrary SQL commands via
23RISK
open ↗Referência✓ VexDay Proof
Techno Dreams Articles & Papers 2.0 - SQL Injection
SQL injection vulnerability in ArticlesTableview.asp in Techno Dreams Articles & Papers Package 2.0 and earlier allows r
23RISK
open ↗Referência✓ VexDay Proof
Flatnuke 3 - Remote Command Execution / Privilege Escalation
index.php in the File Manager module in Flatnuke 3 allows remote attackers to obtain sensitive information via an invali
23RISK
open ↗Referência✓ VexDay Proof
PHP Webquest 2.6 - Get Database Credentials
PHP Webquest 2.6 allows remote attackers to retrieve database credentials via a direct request to admin/backup_phpwebque
23RISK
open ↗Referência✓ VexDay Proof
eLineStudio Site Composer (ESC) 2.6 - Multiple Vulnerabilities
Multiple absolute path traversal vulnerabilities in eLineStudio Site Composer (ESC) 2.6 allow remote attackers to create
23RISK
open ↗Referência✓ VexDay Proof
Talkback 2.3.6 - Multiple Local File Inclusion / PHPInfo Disclosure Vulnerabilities
TalkBack 2.3.6 allows remote attackers to obtain configuration information via a direct request to install/info.php, whi
23RISK
open ↗Referência✓ VexDay Proof
Nukedit 4.9.8 - Remote Database Disclosure
Nukedit 4.9.8 stores sensitive information under the web root with insufficient access control, which allows remote atta
23RISK
open ↗Referência✓ VexDay Proof
Joovili 3.1.4 - Insecure Cookie Handling
Joovili 3.1.4 allows remote attackers to bypass authentication and gain privileges as other users, including the adminis
23RISK
open ↗Referência✓ VexDay Proof
Free PHP VX Guestbook 1.06 - Insecure Cookie Handling
Free PHP VX Guestbook 1.06 allows remote attackers to bypass authentication and gain administrative access by setting th
23RISK
open ↗Referência✓ VexDay Proof
IceBB 1.0-rc5 - Remote Code Execution
Unrestricted file upload vulnerability in index.php in IceBB 1.0-rc5 allows remote authenticated users to upload arbitra
23RISK
open ↗Referência✓ VexDay Proof
Crux Gallery 1.32 - Insecure Cookie Handling
main.php in Crux Gallery 1.32 and earlier allows remote attackers to gain administrative access by setting the name para
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.