Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,465Referência 23,022GitHub PoC 15,031VulnCheck XDB 8,860Nuclei 4,361Metasploit 3,491✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
WholeHogSoftware Password Protect - Insecure Cookie Handling
Whole Hog Password Protect: Enhanced 1.x allows remote attackers to bypass authentication and obtain administrative acce
23RISK
open ↗Referência✓ VexDay Proof
ClickCart 6.0 - Authentication Bypass
Multiple SQL injection vulnerabilities in customer_login_check.asp in ClickTech ClickCart 6.0 allow remote attackers to
23RISK
open ↗Referência✓ VexDay Proof
Axiom Photo/News Gallery 0.8.6 - Remote File Inclusion
PHP remote file inclusion vulnerability in template.php in Geoffrey Golliher Axiom Photo/News Gallery (axiompng) 0.8.6 a
23RISK
open ↗Referência✓ VexDay Proof
GLLCTS2 - 'sort' Blind SQL Injection
SQL injection vulnerability in listing.php in Gryphon gllcTS2 4.2.4 allows remote attackers to execute arbitrary SQL com
23RISK
open ↗Referência✓ VexDay Proof
Profense Web Application Firewall 2.6.2 - Cross-Site Request Forgery / Cross-Site Scripting
Multiple cross-site request forgery (CSRF) vulnerabilities in ajax.html in Profense Web Application Firewall 2.6.2 and 2
23RISK
open ↗Referência✓ VexDay Proof
AgerMenu 0.01 - 'top.inc.php?rootdir' Remote File Inclusion
PHP remote file inclusion vulnerability in examples/inc/top.inc.php in AgerMenu 0.03 and earlier allows remote attackers
23RISK
open ↗Referência✓ VexDay Proof
NUNE News Script 2.0pre2 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in NUNE News Script 2.0pre2 allow remote attackers to execute arbitra
23RISK
open ↗Referência✓ VexDay Proof
minb 0.1.0 - Remote Code Execution
include/modules/top/1-random_quote.php in Minb Is Not a Blog (minb) 0.1.0 allows remote attackers to execute arbitrary P
23RISK
open ↗Referência✓ VexDay Proof
eFiction 3.1.1 - 'path_to_smf' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in eFiction 3.1.1 and earlier allow remote attackers to execute arbit
23RISK
open ↗Referência✓ VexDay Proof
Expert Advisior - 'index.php?id' SQL Injection
SQL injection vulnerability in index.php in Expert Advisor allows remote attackers to execute arbitrary SQL commands via
23RISK
open ↗Referência✓ VexDay Proof
Pluck CMS 4.5.3 - 'g_pcltar_lib_dir' Local File Inclusion
Directory traversal vulnerability in data/inc/lib/pcltar.lib.php in Pluck 4.5.3, when register_globals is enabled, allow
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component Portfol 1.2 - 'vcatid' SQL Injection
SQL injection vulnerability in the Portfol (com_portfol) 1.2 component for Joomla! allows remote attackers to execute ar
23RISK
open ↗Referência✓ VexDay Proof
Demo4 CMS - 'id' SQL Injection
SQL injection vulnerability in index.php in Demo4 CMS 01 Beta allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗Referência✓ VexDay Proof
phpProfiles 3.1.2b - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in phpProfiles 3.1.2b and earlier allow remote attackers to execute a
23RISK
open ↗Referência✓ VexDay Proof
ViRC 2.0 - JOIN Response Remote Overwrite (SEH)
Stack-based buffer overflow in Visual IRC (ViRC) 2.0 allows remote IRC servers to execute arbitrary code via a long resp
23RISK
open ↗Referência✓ VexDay Proof
Virtual Guestbook 2.1 - Remote Database Disclosure
Virtual GuestBook (vgbook) 2.1 stores sensitive information under the web root with insufficient access control, which a
23RISK
open ↗Referência✓ VexDay Proof
Web Wiz Rich Text Editor 4.0 - Multiple Vulnerabilities
Web Wiz RTE_file_browser.asp in, as used in Web Wiz Rich Text Editor 4.0, Web Wiz Forums 9.07, and Web Wiz Newspad 1.02,
23RISK
open ↗Referência✓ VexDay Proof
Mambo Component com_loudmouth 4.0j - Remote File Inclusion
PHP remote file inclusion vulnerability in includes/abbc/abbc.class.php in the LoudMouth Component for Mambo 4.0j, and p
23RISK
open ↗Referência✓ VexDay Proof
SnippetMaster Webpage Editor 2.2.2 - Remote File Inclusion / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in SnippetMaster Webpage Editor 2.2.2 allows remote attackers to i
23RISK
open ↗Referência✓ VexDay Proof
SnippetMaster Webpage Editor 2.2.2 - Remote File Inclusion / Cross-Site Scripting
Multiple PHP remote file inclusion vulnerabilities in SnippetMaster 2.2.2, when register_globals is enabled, allow remot
23RISK
open ↗Referência✓ VexDay Proof
A Better Member-Based ASP Photo Gallery - 'entry' SQL Injection
SQL injection vulnerability in gallery/view.asp in A Better Member-Based ASP Photo Gallery before 1.2 allows remote atta
23RISK
open ↗Referência✓ VexDay Proof
Move Networks Quantum Streaming Player Control - Remote Buffer Overflow
Stack-based buffer overflow in the Quantum Streaming Player (Quantum Streaming IE Player) ActiveX control (aka QSP2IE.QS
23RISK
open ↗Referência✓ VexDay Proof
Panda Security ActiveScan 2.0 (Update) - Remote Buffer Overflow
Stack-based buffer overflow in the ActiveX control (as2guiie.dll) in Panda ActiveScan before 1.02.00 allows remote attac
23RISK
open ↗Referência✓ VexDay Proof
WebXell Editor 0.1.3 - Arbitrary File Upload
Unrestricted file upload vulnerability in upload_pictures.php in WebXell Editor 0.1.3 allows remote attackers to execute
23RISK
open ↗Referência✓ VexDay Proof
CafeEngine - 'catid' SQL Injection
SQL injection vulnerability in index.php in Easy CafeEngine allows remote attackers to execute arbitrary SQL commands vi
23RISK
open ↗Referência✓ VexDay Proof
Winamp 5.21 - '.Midi' File Header Handling Buffer Overflow (PoC)
Buffer overflow in in_midi.dll for WinAmp 2.90 up to 5.23, including 5.21, allows remote attackers to execute arbitrary
28RISK
open ↗Referência✓ VexDay Proof
PHP 5.x COM - Safe Mode / disable_functions Bypass
The Component Object Model (COM) functions in PHP 5.x on Windows do not follow safe_mode and disable_functions restricti
23RISK
open ↗Referência✓ VexDay Proof
dBpowerAMP Audio Player 2 - '.m3u' Buffer Overflow (PoC)
Buffer overflow in dBpowerAMP Audio Player Release 2 allows remote attackers to execute arbitrary code via a .M3U file w
23RISK
open ↗Referência✓ VexDay Proof
FlashBlog 0.31b - Arbitrary File Upload
Unrestricted file upload vulnerability in admin/Editor/imgupload.php in FlashBlog 0.31 beta allows remote attackers to e
23RISK
open ↗Referência✓ VexDay Proof
Magic CMS 4.2.747 - 'mysave.php' Remote File Inclusion
PHP remote file inclusion vulnerability in mysave.php in Magic CMS 4.2.747 allows remote attackers to execute arbitrary
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.