Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,465Referência 23,022GitHub PoC 15,031VulnCheck XDB 8,860Nuclei 4,361Metasploit 3,491✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
Natterchat 1.1 - Remote Authentication Bypass
NatterChat 1.1 allows remote attackers to bypass authentication and gain administrator privileges to read or delete room
23RISK
open ↗Referência✓ VexDay Proof
pragmaMX Module Landkarten 2.1 (Windows) - Local File Inclusion
Directory traversal vulnerability in inc/map.func.php in pragmaMX Landkarten 2.1 module allows remote attackers to inclu
23RISK
open ↗Referência✓ VexDay Proof
addalink 4 Beta - Write Approved Links
Addalink 1.0 beta 4 and earlier allows remote attackers to (1) approve web-site additions via a modified approved field
23RISK
open ↗Referência✓ VexDay Proof
WordPress Plugin fMoblog 2.1 - 'id' SQL Injection
SQL injection vulnerability in fmoblog.php in the fMoblog plugin 2.1 for WordPress allows remote attackers to execute ar
23RISK
open ↗Referência✓ VexDay Proof
Gretech GOM Encoder 1.0.0.11 - '.Subtitle' Buffer Overflow (PoC)
Heap-based buffer overflow in the Preview/ Set Segment function in Gretech GOMlab GOM Encoder 1.0.0.11 and earlier allow
23RISK
open ↗Referência✓ VexDay Proof
iziContents rc6 - Local/Remote File Inclusion
Directory traversal vulnerability in tiny_mce_gzip.php in TinyMCE Compressor PHP before 1.06 allows remote attackers to
23RISK
open ↗Referência✓ VexDay Proof
KnowledgeBuilder 2.2 - 'visEdit_root' Remote File Inclusion
PHP remote file inclusion vulnerability in admin/e_data/visEdit_control.class.php in ActiveCampaign KnowledgeBuilder 2.2
23RISK
open ↗Referência✓ VexDay Proof
webid 0.5.4 - Multiple Vulnerabilities
eledicss.php in WeBid auction script 0.5.4 allows remote attackers to modify arbitrary cascading style sheets (CSS) file
23RISK
open ↗Referência✓ VexDay Proof
Kim Websites 1.0 - Authentication Bypass
Multiple SQL injection vulnerabilities in login.php in Kim Websites 1.0 allow remote attackers to execute arbitrary SQL
23RISK
open ↗Referência✓ VexDay Proof
eZip Wizard 3.0 - Local Stack Buffer Overflow (PoC) (SEH)
Stack-based buffer overflow in ediSys eZip Wizard 3.0 allows remote attackers to execute arbitrary code via a crafted .z
50RISK
open ↗Referência✓ VexDay Proof
EasyNews 40tr - SQL Injection / Cross-Site Scripting / Local File Inclusion
Directory traversal vulnerability in admin/login.php in EasyNews 4.0 allows remote attackers to include and execute arbi
23RISK
open ↗Referência✓ VexDay Proof
gapicms 9.0.2 - 'dirDepth' Remote File Inclusion
PHP remote file inclusion vulnerability in ktmlpro/includes/ktedit/toolbar.php in gapicms 9.0.2 allows remote attackers
23RISK
open ↗Referência✓ VexDay Proof
DBGuestbook 1.1 - 'dbs_base_path' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in DBGuestbook 1.1 allow remote attackers to execute arbitrary PHP co
23RISK
open ↗Referência✓ VexDay Proof
HIOX Random Ad 1.3 - Remote File Inclusion
PHP remote file inclusion vulnerability in hioxRandomAd.php in HIOX Random Ad (HRA) 1.3 allows remote attackers to execu
23RISK
open ↗Referência✓ VexDay Proof
phpTrafficA 1.4.2 - 'pageid' SQL Injection
Directory traversal vulnerability in index.php in phpTrafficA 1.4.2 and earlier allows remote attackers to include arbit
23RISK
open ↗Referência✓ VexDay Proof
Hotel Reservation System - 'city.asp' Blind SQL Injection
SQL injection vulnerability in city.asp in SoftAcid Hotel Reservation System (HRS) allows remote attackers to execute ar
23RISK
open ↗Referência✓ VexDay Proof
YAP 1.1.1 - Blind SQL Injection / SQL Injection
Multiple SQL injection vulnerabilities in YAP Blog 1.1.1 allow remote attackers to execute arbitrary SQL commands via th
23RISK
open ↗Referência✓ VexDay Proof
WebCalendar 1.0.4 - 'includedir' Remote File Inclusion
PHP remote file inclusion vulnerability in send_reminders.php in WebCalendar 1.0.4 allows remote attackers to execute ar
23RISK
open ↗Referência✓ VexDay Proof
BitsCast 0.13.0 - invalid string Remote Denial of Service
BitsCast 0.13.0 allows remote attackers to cause a denial of service (application crash) via an RSS 2.0 feed item with c
23RISK
open ↗Referência✓ VexDay Proof
eZip Wizard 3.0 - Local Stack Buffer Overflow (PoC) (SEH)
Stack-based buffer overflow in ZipGenius might allow remote attackers to execute arbitrary code via a crafted .zip file
23RISK
open ↗Referência✓ VexDay Proof
mUnky 0.0.1 - 'zone' Local File Inclusion
Directory traversal vulnerability in index.php in mUnky 0.0.1 allows remote attackers to include and execute arbitrary l
23RISK
open ↗Referência✓ VexDay Proof
eZip Wizard 3.0 - Local Stack Buffer Overflow (PoC) (SEH)
Stack-based buffer overflow in Trident PowerZip 7.2 might allow remote attackers to execute arbitrary code via a crafted
23RISK
open ↗Referência✓ VexDay Proof
eXeScope 6.50 - Local Buffer Overflow
Buffer overflow in eXeScope 6.50 allows user-assisted remote attackers to execute arbitrary code via a crafted executabl
23RISK
open ↗Referência✓ VexDay Proof
ExBB 0.22 - Local/Remote File Inclusion
ExBB Italia 0.22 and earlier only checks GET requests that use the QUERY_STRING for certain path manipulations, which al
23RISK
open ↗Referência✓ VexDay Proof
Mantis Bug Tracker 1.1.1 - Code Execution / Cross-Site Scripting / Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in manage_user_create.php in Mantis 1.1.1 allows remote attackers to cre
23RISK
open ↗Referência✓ VexDay Proof
Observer 0.3.2.1 - Multiple Remote Command Execution Vulnerabilities
Observer 0.3.2.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the query
28RISK
open ↗Referência✓ VexDay Proof
BS.Player 2.34 - '.bsl' Universal Overwrite (SEH)
Stack-based buffer overflow in BS.Player (bsplayer) 2.32 Build 975 Free and 2.34 Build 980 PRO and earlier allows remote
28RISK
open ↗Referência✓ VexDay Proof
BS.Player 2.34 Build 980 - '.bsl' Local Buffer Overflow (SEH)
Stack-based buffer overflow in BS.Player (bsplayer) 2.32 Build 975 Free and 2.34 Build 980 PRO and earlier allows remote
28RISK
open ↗Referência✓ VexDay Proof
Icarus 2.0 - '.pgn' Local Stack Overflow (SEH)
Stack-based buffer overflow in Icarus 2.0 allows remote attackers to cause a denial of service (application crash) or ex
23RISK
open ↗Referência✓ VexDay Proof
CenterIM 4.22.3 - Remote Command Execution
CenterIM 4.22.3 and earlier allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.