Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,465Referência 23,022GitHub PoC 15,031VulnCheck XDB 8,860Nuclei 4,361Metasploit 3,491✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
Joomla! Component Kochsuite 0.9.4 - Remote File Inclusion
PHP remote file inclusion vulnerability in config.kochsuite.php in the Kochsuite (com_kochsuite) 0.9.4 component for Mam
23RISK
open ↗Referência✓ VexDay Proof
Apache Tomcat Connector jk2-2.0.2 mod_jk2 - Remote Overflow
Multiple stack-based buffer overflows in the legacy mod_jk2 2.0.3-DEV and earlier Apache module allow remote attackers t
35RISK
open ↗Referência✓ VexDay Proof
Apple Mac OSX 10.5.0 (Leopard) - vpnd Remote Denial of Service (PoC)
The accept_connections function in the virtual private network daemon (vpnd) in Apple Mac OS X 10.5 before 10.5.4 allows
23RISK
open ↗Referência✓ VexDay Proof
Falt4 CMS rc4 10.9.2007 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Falt4Extreme RC4 10.9.2007 allow remote attackers to inject arbit
23RISK
open ↗Referência✓ VexDay Proof
Interact 2.2 - 'CONFIG[base_path]' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in interact 2.2, when register_globals is enabled, allow remote attac
23RISK
open ↗Referência✓ VexDay Proof
xml2owl 0.1.1 - 'filedownload.php' Remote File Disclosure
Directory traversal vulnerability in filedownload.php in xml2owl 0.1.1 allows remote attackers to read arbitrary files v
23RISK
open ↗Referência✓ VexDay Proof
HP Compaq Notebooks - ActiveX Remote Code Execution
Absolute path traversal vulnerability in the HPInfoDLL.HPInfo.1 ActiveX control in HPInfoDLL.dll 1.0, as shipped with HP
35RISK
open ↗Referência✓ VexDay Proof
phpGroupWare 0.9.16.010 - 'GLOBALS[]' Remote Code Execution
Directory traversal vulnerability in calendar/inc/class.holidaycalc.inc.php in phpGroupWare 0.9.16.010 and earlier allow
23RISK
open ↗Referência✓ VexDay Proof
Linksys SPA941 - Remote Reboot (Denial of Service)
The Linksys SPA941 VoIP Phone allows remote attackers to cause a denial of service (device reboot) via a 0377 (0xff) cha
23RISK
open ↗Referência✓ VexDay Proof
USP FOSS Distribution 1.01 - 'dnld' Remote File Disclosure
Directory traversal vulnerability in Rajneel Lal TotaRam USP FOSS Distribution 1.01 allows remote attackers to read arbi
23RISK
open ↗Referência✓ VexDay Proof
SH-News 3.0 - 'comments.php' SQL Injection
SQL injection vulnerability in patch/comments.php in SH-News 3.0 allows remote attackers to execute arbitrary SQL comman
23RISK
open ↗Referência✓ VexDay Proof
TR Forum 2.0 - SQL Injection / Bypass Security Restriction
The admin panel in Tr Forum 2.0 accepts a username and password hash for authentication, which allows remote authenticat
23RISK
open ↗Referência✓ VexDay Proof
TikiWiki 1.9 Sirius - 'jhot.php' Remote Command Execution
Unrestricted file upload vulnerability in jhot.php in TikiWiki 1.9.4 Sirius and earlier allows remote attackers to execu
50RISK
open ↗Referência✓ VexDay Proof
Ace Image Hosting Script - 'id' SQL Injection
SQL injection vulnerability in albums.php in Ace Image Hosting Script allows remote authenticated users to execute arbit
23RISK
open ↗Referência✓ VexDay Proof
Flat PHP Board 1.2 - Multiple Vulnerabilities
Flat PHP Board 1.2 and earlier stores sensitive information under the web root with insufficient access control, which a
23RISK
open ↗Referência✓ VexDay Proof
Flat PHP Board 1.2 - Multiple Vulnerabilities
index.php in Flat PHP Board 1.2 and earlier allows remote authenticated users to obtain the password for the current use
23RISK
open ↗Referência✓ VexDay Proof
Adult Script 1.6 - Unauthorized Administrative Access
admin/administrator.php in Adult Script 1.6 and earlier sends a redirect to the web browser but does not exit, which all
23RISK
open ↗Referência✓ VexDay Proof
webSPELL 4.01.01 - Database Backup Download
src/index.php in WebSPELL 4.01.01 and earlier, when register_globals is enabled, allows remote attackers to bypass authe
23RISK
open ↗Referência✓ VexDay Proof
WebCalendar 1.2.4 - Remote Code Execution
install/index.php in WebCalendar before 1.2.5 allows remote attackers to execute arbitrary code via the form_single_user
60RISK
open ↗Referência✓ VexDay Proof
gf-3xplorer 2.4 - Cross-Site Scripting / Local File Inclusion
Multiple directory traversal vulnerabilities in GF-3XPLORER 2.4 allow remote attackers to include and execute arbitrary
23RISK
open ↗Referência✓ VexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
Unspecified vulnerability in IIS/iibind.asp in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticate
23RISK
open ↗Referência✓ VexDay Proof
HP Software Update Client 3.0.8.4 - Multiple Vulnerabilities
The HPRulesEngine.ContentCollection.1 ActiveX Control in RulesEngine.dll for HP Software Update 4.000.005.007 and earlie
28RISK
open ↗Referência✓ VexDay Proof
eSyndiCat Link Exchange Script 2005-2006 - SQL Injection
SQL injection vulnerability in suggest-link.php in eSyndiCat Link Exchange Script allows remote attackers to execute arb
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component mosDirectory 2.3.2 - Remote File Inclusion
PHP remote file inclusion vulnerability in modules/mod_pxt_latest.php in the mosDirectory (com_directory) 2.3.2 componen
23RISK
open ↗Referência✓ VexDay Proof
zBlog 1.2 - SQL Injection
Multiple SQL injection vulnerabilities in index.php in zBlog 1.2 allow remote attackers to execute arbitrary SQL command
23RISK
open ↗Referência✓ VexDay Proof
PHP ZLink 0.3 - 'go.php' SQL Injection
SQL injection vulnerability in go.php in PHP ZLink 0.3 allows remote attackers to execute arbitrary SQL commands via the
23RISK
open ↗Referência✓ VexDay Proof
Wallpaper Site 1.0.09 - 'category.php' SQL Injection
Multiple SQL injection vulnerabilities in Wallpaper Site 1.0.09 allow remote attackers to execute arbitrary SQL commands
23RISK
open ↗Referência✓ VexDay Proof
1024 CMS 1.3.1 - Local File Inclusion / SQL Injection
Multiple directory traversal vulnerabilities in 1024 CMS 1.3.1 allow remote attackers to include and execute arbitrary l
23RISK
open ↗Referência✓ VexDay Proof
NmnNewsletter 1.0.7 - 'output' Remote File Inclusion
PHP remote file inclusion vulnerability in confirmUnsubscription.php in NmnNewsletter 1.0.7 allows remote attackers to e
23RISK
open ↗Referência✓ VexDay Proof
SkyFex Client 1.0 - ActiveX 'Start()' Method Remote Stack Overflow
Buffer overflow in a certain ActiveX control in SkyFexClient.ocx 1.0.2.77 in SkyFex Client 1.0 allows remote attackers t
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.