Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,465Referência 23,022GitHub PoC 15,031VulnCheck XDB 8,860Nuclei 4,361Metasploit 3,491✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
BXCP 0.3.0.4 - 'where' SQL Injection
SQL injection vulnerability in the files mod in index.php in BXCP 0.3.0.4 allows remote attackers to execute arbitrary S
23RISK
open ↗Referência✓ VexDay Proof
Quake 3 Engine Client - 'CG_ServerCommand()' Remote Overflow
Stack-based buffer overflow in the CG_ServerCommand function in Quake 3 Engine as used by Soldier of Fortune 2 (SOF2MP)
23RISK
open ↗Referência✓ VexDay Proof
WonderEdit Pro CMS (template_path) - Remote File Inclusion
PHP remote file inclusion vulnerability in WonderEdit Pro CMS allows remote attackers to execute arbitrary PHP code via
23RISK
open ↗Referência✓ VexDay Proof
PAPOO 3_RC3 - SQL Injection / Admin Credentials Disclosure
SQL injection vulnerability in forumthread.php in Papoo 3 RC3 and earlier allows remote attackers to execute arbitrary S
23RISK
open ↗Referência✓ VexDay Proof
Winlpd 1.2 Build 1076 - Remote Buffer Overflow
Stack-based buffer overflow in Winlpd 1.26 allows remote attackers to execute arbitrary code via a long string in a requ
23RISK
open ↗Referência✓ VexDay Proof
Mambo Component Sitemap 2.0.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in sitemap.xml.php in Sitemap component (com_sitemap) 2.0.0 for Mambo 4.5.1 CMS,
23RISK
open ↗Referência✓ VexDay Proof
Mambo Component com_hashcash 1.2.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in server.php in the Hashcash Component (com_hashcash) 1.2.1 for Joomla! allows
23RISK
open ↗Referência✓ VexDay Proof
FlushCMS 1.0.0-pre2 - 'class.rich.php' Remote File Inclusion
PHP remote file inclusion vulnerability in Include/editor/rich_files/class.rich.php in FlushCMS 1.0.0-pre2 and earlier a
23RISK
open ↗Referência✓ VexDay Proof
iManage CMS 4.0.12 - 'absolute_path' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in component.php in iManage CMS 4.0.12 and earlier allow remote attac
28RISK
open ↗Referência✓ VexDay Proof
Mambo Component Mam-Moodle alpha - Remote File Inclusion
PHP remote file inclusion vulnerability in moodle.php in Mam-moodle alpha component (com_moodle) for Mambo allows remote
23RISK
open ↗Referência✓ VexDay Proof
WinRAR 3.60 Beta 6 (French) - SFX Path Local Stack Overflow
Stack-based buffer overflow in the SFX module in WinRAR before 3.60 beta 8 has unspecified vectors and impact.
23RISK
open ↗Referência✓ VexDay Proof
WinRAR 3.60 Beta 6 - SFX Path Local Stack Overflow
Stack-based buffer overflow in the SFX module in WinRAR before 3.60 beta 8 has unspecified vectors and impact.
23RISK
open ↗Referência✓ VexDay Proof
PHP Forge 3 Beta 2 - 'cfg_racine' Remote File Inclusion
PHP remote file inclusion vulnerability in inc/gabarits.php in R. Corson PHP Forge 3 beta 2 and earlier allows remote at
23RISK
open ↗Referência✓ VexDay Proof
Portail PHP 1.7 - 'chemin' Remote File Inclusion
PHP remote file inclusion vulnerability in mod_membre/inscription.php in PortailPHP 1.7 allows remote attackers to execu
23RISK
open ↗Referência✓ VexDay Proof
WMNews 0.2a - 'base_datapath' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in WMNews 0.2a and earlier allows remote attackers to execute arbit
23RISK
open ↗Referência✓ VexDay Proof
Mambo Component mambatStaff 3.1b - Remote File Inclusion
PHP remote file inclusion vulnerability in components/com_mambatstaff/mambatstaff.php in the Mambatstaff 3.1b and earlie
23RISK
open ↗Referência✓ VexDay Proof
MyNewsGroups 0.6b - 'myng_root' Remote Inclusion
PHP remote file inclusion vulnerability in /lib/tree/layersmenu.inc.php in the PHP Layers Menu 2.3.5 package for MyNewsG
23RISK
open ↗Referência✓ VexDay Proof
XMB 1.9.6 - 'mq=off' 'u2uid' SQL Injection
SQL injection vulnerability in the u2u_send_recp function in u2u.inc.php in XMB (aka extreme message board) 1.9.6 Alpha
23RISK
open ↗Referência✓ VexDay Proof
MyBloggie 2.1.4 - 'trackback.php' Multiple SQL Injections
Multiple SQL injection vulnerabilities in trackback.php in myWebland myBloggie 2.1.4 and earlier allow remote attackers
23RISK
open ↗Referência✓ VexDay Proof
Torbstoff News 4 - 'pfad' Remote File Inclusion
PHP remote file inclusion vulnerability in news.php in Torbstoff News 4 allows remote attackers to execute arbitrary PHP
23RISK
open ↗Referência✓ VexDay Proof
Open Cubic Player 2.6.0pre6/0.1.10_rc5 - Multiple Local Buffer Overflows
Multiple stack-based buffer overflows in Open Cubic Player 2.6.0pre6 and earlier for Windows, and 0.1.10_rc5 and earlier
28RISK
open ↗Referência✓ VexDay Proof
Microsoft Windows Explorer - '.WMF' CreateBrushIndirect Denial of Service
Sign extension vulnerability in the createBrushIndirect function in the GDI library (gdi32.dll) in Microsoft Windows XP,
28RISK
open ↗Referência✓ VexDay Proof
NES Game and NES System c108122 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in NES Game and NES System c108122 and earlier allow remote attackers
28RISK
open ↗Referência✓ VexDay Proof
PHlyMail Lite 3.4.4 - 'mod.listmail.php' Remote File Inclusion
PHP remote file inclusion vulnerability in handlers/email/mod.listmail.php in PHlyMail Lite 3.4.4 and earlier (Build 3.0
23RISK
open ↗Referência✓ VexDay Proof
Mambo Component cropimage 1.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in admin.cropcanvas.php in the CropImage component (com_cropimage) 1.0 for Mambo
23RISK
open ↗Referência✓ VexDay Proof
VistaBB 2.x - 'functions_mod_user.php' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in VistaBB 2.0.33 and earlier allow remote attackers to execute arbit
23RISK
open ↗Referência✓ VexDay Proof
SL_Site 1.0 - 'spaw_root' Remote File Inclusion
PHP remote file inclusion vulnerability in admin/editeur/spaw_control.class.php in Web Provence SL_Site 1.0 and earlier
28RISK
open ↗Referência✓ VexDay Proof
Somery 0.4.6 - 'skin_dir' Remote File Inclusion
PHP remote file inclusion vulnerability in admin/system/include.php in Somery 0.4.6 and earlier, when register_globals i
23RISK
open ↗Referência✓ VexDay Proof
PhotoKorn Gallery 1.52 - 'dir_path' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in PhotoKorn Gallery 1.52 and earlier allow remote attackers to execu
28RISK
open ↗Referência✓ VexDay Proof
SIPS 0.3.1 - 'box.inc.php' Remote File Inclusion
PHP remote file inclusion vulnerability in sipssys/code/box.inc.php in Haakon Nilsen simple, integrated publishing syste
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.