Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,465Referência 23,022GitHub PoC 15,031VulnCheck XDB 8,860Nuclei 4,361Metasploit 3,491✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
Pollbooth 2.0 - 'pollID' SQL Injection
SQL injection vulnerability in pollBooth.php in osCommerce Poll Booth Add-On 2.0 allows remote attackers to execute arbi
23RISK
open ↗Referência✓ VexDay Proof
CyberBrau 0.9.4 - '/forum/track.php' Remote File Inclusion
PHP remote file inclusion vulnerability in forum/track.php in CyberBrau 0.9.4, when register_globals is enabled, allows
23RISK
open ↗Referência✓ VexDay Proof
MyCMS 0.9.8 - Remote Command Execution (1)
MyCMS 0.9.8 and earlier allows remote attackers to gain privileges via the admin cookie parameter, as demonstrated by a
23RISK
open ↗Referência✓ VexDay Proof
PHP-Stats 0.1.9.2 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in php-stats.recjs.php in Php-Stats 0.1.9.2 allow remote attackers to execute arb
23RISK
open ↗Referência✓ VexDay Proof
xeCMS 1.x - 'view.php' Remote File Disclosure
Directory traversal vulnerability in view.php in xeCMS 1.0 allows remote attackers to read arbitrary files via a ..%2F (
23RISK
open ↗Referência✓ VexDay Proof
vbPortal 3.0.2 < 3.6.0 b1 - 'cookie' Remote Code Execution
Directory traversal vulnerability in index.php in vbPortal 3.0.2 through 3.6.0 Beta 1, when magic_quotes_gpc is disabled
23RISK
open ↗Referência✓ VexDay Proof
D-Link MPEG4 SHM Audio Control - 'VAPGDecoder.dll 1.7.0.5' Remote Buffer Overflow
Stack-based buffer overflow in VATDecoder.VatCtrl.1 ActiveX control in (1) 4xem VatCtrl Class (VATDecoder.dll 1.0.0.27 a
23RISK
open ↗Referência✓ VexDay Proof
Avax Vector 'Avaxswf.dll' 1.0.0.1 - ActiveX Arbitrary Data Write
A certain ActiveX control in Avaxswf.dll 1.0.0.1 in Civitech Avax Vector 1.3 allows remote attackers to create or overwr
23RISK
open ↗Referência✓ VexDay Proof
osCommerce Addon Customer Testimonials 3.1 - SQL Injection
SQL injection vulnerability in customer_testimonials.php in the Customer Testimonials 3 and 3.1 Addon for osCommerce Onl
23RISK
open ↗Referência✓ VexDay Proof
TlAds 1.0 - Remote Insecure Cookie Handling
tlAds 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the tlAds_login coo
23RISK
open ↗Referência✓ VexDay Proof
QuoteBook - Remote Configuration File Disclosure
QuoteBook stores quotes.inc under the web root with insufficient access control, which allows remote attackers to obtain
23RISK
open ↗Referência✓ VexDay Proof
PHP-Nuke Module htmltonuke 2.0alpha - 'htmltonuke.php' Remote File Inclusion
PHP remote file inclusion vulnerability in htmltonuke.php in the htmltonuke 2.0 alpha, and possibly other versions, modu
23RISK
open ↗Referência✓ VexDay Proof
PortailPHP mod_phpalbum 2.1.5 - 'chemin' Remote File Inclusion
PHP remote file inclusion vulnerability in sommaire_admin.php in PhpAlbum (mod_phpalbum) 2.15 for PortailPHP allows remo
23RISK
open ↗Referência✓ VexDay Proof
Bloginator 1a - Cookie Bypass / SQL Injection
Bloginator 1A allows remote attackers to bypass authentication and gain administrative access by setting the identifyYou
23RISK
open ↗Referência✓ VexDay Proof
sBLOG 0.7.3 Beta - '/inc/lang.php' Local File Inclusion
Directory traversal vulnerability in inc/lang.php in sBLOG 0.7.3 Beta allows remote attackers to include and execute arb
23RISK
open ↗Referência✓ VexDay Proof
XOOPS Module Jobs 2.4 - 'cid' SQL Injection
SQL injection vulnerability in index.php in the John Mordo Jobs 2.4 and earlier module for XOOPS allows remote attackers
23RISK
open ↗Referência✓ VexDay Proof
Chilkat Zip ActiveX Component 12.4 - Multiple Insecure Methods
Absolute path traversal vulnerability in the Chilkat Software Chilkat Zip ActiveX control in ChilkatZip2.dll 12.4.2.0 al
23RISK
open ↗Referência✓ VexDay Proof
DevMass Shopping Cart 1.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in admin/kfm/initialise.php in DevMass Shopping Cart 1.0 and earlier allows remo
23RISK
open ↗Referência✓ VexDay Proof
CPCommerce 1.1.0 - Cross-Site Scripting / Local File Inclusion
Cross-site scripting (XSS) vulnerability in calendar.php in cpCommerce 1.1.0 allows remote attackers to inject arbitrary
23RISK
open ↗Referência✓ VexDay Proof
Falt4 CMS rc4 10.9.2007 - Multiple Vulnerabilities
SQL injection vulnerability in (1) index.php, and possibly (2) admin/index.php, in Falt4Extreme RC4 10.9.2007 allows rem
23RISK
open ↗Referência✓ VexDay Proof
aflog 1.01 - Multiple Insecure Cookie Handling Vulnerabilities
aflog 1.01 allows remote attackers to bypass authentication and gain administrative access by setting the aflog_auth_a c
23RISK
open ↗Referência✓ VexDay Proof
Microsoft Windows Media Player - '.mid' Integer Overflow (PoC)
Integer overflow in Microsoft Windows Media Player (WMP) 11.0.5721.5260 allows remote attackers to cause a denial of ser
28RISK
open ↗Referência✓ VexDay Proof
Rianxosencabos CMS 0.9 - Insecure Cookie Handling
Rianxosencabos CMS 0.9 allows remote attackers to bypass authentication and gain administrative access by setting the us
23RISK
open ↗Referência✓ VexDay Proof
Microsoft Internet Explorer (Windows Vista) - XML Parsing Buffer Overflow
Use-after-free vulnerability in the CRecordInstance::TransferToDestination function in mshtml.dll in Microsoft Internet
50RISK
open ↗Referência✓ VexDay Proof
Netref 4 - 'cat_for_aff.php' Source Code Disclosure
Directory traversal vulnerability in script/cat_for_aff.php in Netref 4 allows remote attackers to read arbitrary files
23RISK
open ↗Referência✓ VexDay Proof
MODx CMS 0.9.6.2 - Remote File Inclusion / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in MODx CMS 0.9.6.2 and earlier allows remote attackers to inject
23RISK
open ↗Referência✓ VexDay Proof
Hot or Not Clone by Jnshosts.com - Database Backup Dump
Hot or Not Clone has insufficient access control for producing and reading database backups, which allows remote attacke
23RISK
open ↗Referência✓ VexDay Proof
Apple Safari - 'ARGUMENTS' Array Integer Overflow HeapSpray (PoC)
Integer signedness error in Apple Safari allows remote attackers to read the contents of arbitrary memory locations, cau
23RISK
open ↗Referência✓ VexDay Proof
blogplus 1.0 - Multiple Local File Inclusions
Multiple directory traversal vulnerabilities in Blogplus 1.0 allow remote attackers to include and execute arbitrary loc
23RISK
open ↗Referência✓ VexDay Proof
CPCommerce 1.2.8 - 'id_document' Blind SQL Injection
SQL injection vulnerability in document.php in cpCommerce 1.2.8 allows remote attackers to execute arbitrary SQL command
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.