Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,465Referência 23,022GitHub PoC 15,031VulnCheck XDB 8,860Nuclei 4,361Metasploit 3,491✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
ComicShout 2.8 - 'news_id' SQL Injection
SQL injection vulnerability in news.php in ComicShout 2.8 allows remote attackers to execute arbitrary SQL commands via
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component NeoGallery 1.1 - SQL Injection
SQL injection vulnerability in index.php in the Neogallery (com_neogallery) 1.1 component for Joomla! allows remote atta
23RISK
open ↗Referência✓ VexDay Proof
HiveMaker Directory 1.0.2 - 'cid' SQL Injection
SQL injection vulnerability in index.php in Hivemaker Professional 1.0.2 and earlier, when magic_quotes_gpc is disabled,
23RISK
open ↗Referência✓ VexDay Proof
VUPlayer 2.49 - '.pls' Universal Buffer Overflow
Buffer overflow in VUPlayer 2.49 and earlier allows user-assisted attackers to execute arbitrary code via a long URL in
50RISK
open ↗Referência✓ VexDay Proof
AIMP 2.51 build 330 - ID3v1/ID3v2 Tag Remote Stack Buffer Overflow (PoC) (SEH)
Stack-based buffer overflow in AIMP 2.51 build 330 allows remote attackers to execute arbitrary code via an MP3 file wit
28RISK
open ↗Referência✓ VexDay Proof
RhinoSoft Serv-U FTP Server 7.3 - (Authenticated) 'stou con:1' Denial of Service
Serv-U 7.0.0.1 through 7.3, including 7.2.0.1, allows remote authenticated users to cause a denial of service (CPU consu
28RISK
open ↗Referência✓ VexDay Proof
jPORTAL 2 - 'humor.php' SQL Injection
SQL injection vulnerability in humor.php in jPORTAL 2 allows remote attackers to execute arbitrary SQL commands via the
23RISK
open ↗Referência✓ VexDay Proof
Winamp 5.34 - '.mp4' Code Execution
libmp4v2.dll in Winamp 5.02 through 5.34 allows user-assisted remote attackers to execute arbitrary code via a certain .
28RISK
open ↗Referência✓ VexDay Proof
Oceandir 2.9 - 'show_vote.php' SQL Injection
SQL injection vulnerability in show_vote.php in Oceandir 2.9 and earlier allows remote attackers to execute arbitrary SQ
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component pcchess 0.8 - SQL Injection
SQL injection vulnerability in index.php in the Prince Clan Chess Club (com_pcchess) 0.8 and earlier component for Jooml
23RISK
open ↗Referência✓ VexDay Proof
Diesel Pay Script - 'area' SQL Injection
SQL injection vulnerability in index.php in Diesel Pay allows remote attackers to execute arbitrary SQL commands via the
23RISK
open ↗Referência✓ VexDay Proof
easyLink 1.1.0 - 'detail.php' SQL Injection
SQL injection vulnerability in detail.php in MountainGrafix easyLink 1.1.0 allows remote attackers to execute arbitrary
23RISK
open ↗Referência✓ VexDay Proof
Mumbo Jumbo Media OP4 - Blind SQL Injection
SQL injection vulnerability in Mumbo Jumbo Media OP4 allows remote attackers to execute arbitrary SQL commands via the i
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component versioning 1.0.2 - 'id' SQL Injection
SQL injection vulnerability in the Versioning component (com_versioning) 1.0.2 in Joomla! and Mambo allows remote attack
23RISK
open ↗Referência✓ VexDay Proof
Microsoft Internet Explorer 6 / Provideo Camimage - 'ISSCamControl.dll 1.0.1.5' Remote Buffer Overflow
Buffer overflow in the Provideo Camimage ActiveX control in ISSCamControl.dll 1.0.1.5, when Internet Explorer 6 is used
35RISK
open ↗Referência✓ VexDay Proof
Openfire Server 3.6.0a - Authentication Bypass / SQL Injection / Cross-Site Scripting
Directory traversal vulnerability in the AuthCheck filter in the Admin Console in Openfire 3.6.0a and earlier allows rem
60RISK
open ↗Referência✓ VexDay Proof
Openfire Server 3.6.0a - Authentication Bypass / SQL Injection / Cross-Site Scripting
Open redirect vulnerability in login.jsp in Openfire 3.6.0a and earlier allows remote attackers to redirect users to arb
23RISK
open ↗Referência✓ VexDay Proof
NCTAudioEditor2 ActiveX DLL 'NCTWMAFile2.dll 2.6.2.157' - File Write
The NCTAudioEditor2 ActiveX control in NCTWMAFile2.dll 2.6.2.157, as distributed in NCTAudioEditor and NCTAudioStudio 2.
23RISK
open ↗Referência✓ VexDay Proof
Andy's PHP KnowledgeBase 0.92.9 - Arbitrary File Upload
Unrestricted file upload vulnerability in saa.php in Andy's PHP Knowledgebase (aphpkb) 0.92.9 allows remote attackers to
23RISK
open ↗Referência✓ VexDay Proof
b1gbb 2.24.0 - 'footer.inc.php?tfooter' Remote File Inclusion
PHP remote file inclusion vulnerability in footer.inc.php in B1G b1gBB 2.24 allows remote attackers to execute arbitrary
45RISK
open ↗Referência✓ VexDay Proof
VidiScript (Avatar) - Arbitrary File Upload
Unrestricted file upload vulnerability in the profile feature in VidiScript allows registered remote authenticated users
23RISK
open ↗Referência✓ VexDay Proof
Really Simple PHP and Ajax (RSPA) 2007-03-23 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Really Simple PHP and Ajax (RSPA) 2007-03-23 and earlier allow rem
23RISK
open ↗Referência✓ VexDay Proof
OpenInvoice 0.9 - Arbitrary Change User Password
auth.php in openInvoice 0.90 beta and earlier allows remote attackers to bypass authentication and gain privileges by se
23RISK
open ↗Referência✓ VexDay Proof
NetRisk 1.9.7 - Local/Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in NetRisk 1.9.7 and earlier allows remote attackers to execute arb
35RISK
open ↗Referência✓ VexDay Proof
GoodTech SSH - 'SSH_FXP_OPEN' Remote Buffer Overflow
Stack-based buffer overflow in the SFTP subsystem in GoodTech SSH 6.4 allows remote authenticated users to execute arbit
35RISK
open ↗Referência✓ VexDay Proof
WiClear 0.10 - 'path' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in WiClear 0.10 allow remote attackers to execute arbitrary PHP code
28RISK
open ↗Referência✓ VexDay Proof
PHPProfiles 4.5.2 Beta - 'body_comm.inc.php' Remote File Inclusion
PHP remote file inclusion vulnerability in include/body_comm.inc.php in phpProfiles 4.5.2 BETA allows remote attackers t
28RISK
open ↗Referência✓ VexDay Proof
PayPal eStore - Admin Password Change
admin/settings.php in PayPal eStores allows remote attackers to bypass intended access restrictions and change the admin
23RISK
open ↗Referência✓ VexDay Proof
Destar 0.2.2-5 - Arbitrary Add New User
DeStar 0.2.2-5 allows remote attackers to add arbitrary users via a direct request to config/add/CfgOptUser.
23RISK
open ↗Referência✓ VexDay Proof
WordPress Plugin Sniplets 1.1.2 - Remote File Inclusion / Cross-Site Scripting / Remote Code Execution
Multiple cross-site scripting (XSS) vulnerabilities in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allow remote at
38RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.