Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,465Referência 23,022GitHub PoC 15,031VulnCheck XDB 8,860Nuclei 4,361Metasploit 3,491✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
Ace Image Hosting Script - 'id' SQL Injection
SQL injection vulnerability in albums.php in Ace Image Hosting Script allows remote authenticated users to execute arbit
23RISK
open ↗Referência✓ VexDay Proof
Flat PHP Board 1.2 - Multiple Vulnerabilities
Flat PHP Board 1.2 and earlier stores sensitive information under the web root with insufficient access control, which a
23RISK
open ↗Referência✓ VexDay Proof
Flat PHP Board 1.2 - Multiple Vulnerabilities
index.php in Flat PHP Board 1.2 and earlier allows remote authenticated users to obtain the password for the current use
23RISK
open ↗Referência✓ VexDay Proof
Adult Script 1.6 - Unauthorized Administrative Access
admin/administrator.php in Adult Script 1.6 and earlier sends a redirect to the web browser but does not exit, which all
23RISK
open ↗Referência✓ VexDay Proof
Anon Proxy Server 0.1000 - Remote Command Execution
Anon Proxy Server 0.100, and probably 0.101, allows remote attackers to execute arbitrary commands via shell metacharact
23RISK
open ↗Referência✓ VexDay Proof
Form Tools 1.5.0b - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Form tools 1.5.0b allow remote attackers to execute arbitrary PHP
23RISK
open ↗Referência✓ VexDay Proof
FreeWebShop 2.2.1 - Blind SQL Injection
Multiple SQL injection vulnerabilities in index.php in FreeWebshop 2.2.1 allow remote attackers to execute arbitrary SQL
23RISK
open ↗Referência✓ VexDay Proof
RunCMS 1.6 - Get Admin Cookie Blind SQL Injection
Multiple SQL injection vulnerabilities in RunCMS before 1.6.1 allow remote attackers to execute arbitrary SQL commands v
23RISK
open ↗Referência✓ VexDay Proof
TeamCalPro 3.1.000 - Multiple Local/Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in TeamCal Pro 3.1.000 and earlier allow remote attackers to execute
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component mosDirectory 2.3.2 - Remote File Inclusion
PHP remote file inclusion vulnerability in modules/mod_pxt_latest.php in the mosDirectory (com_directory) 2.3.2 componen
23RISK
open ↗Referência✓ VexDay Proof
zBlog 1.2 - SQL Injection
Multiple SQL injection vulnerabilities in index.php in zBlog 1.2 allow remote attackers to execute arbitrary SQL command
23RISK
open ↗Referência✓ VexDay Proof
PHP ZLink 0.3 - 'go.php' SQL Injection
SQL injection vulnerability in go.php in PHP ZLink 0.3 allows remote attackers to execute arbitrary SQL commands via the
23RISK
open ↗Referência✓ VexDay Proof
Wallpaper Site 1.0.09 - 'category.php' SQL Injection
Multiple SQL injection vulnerabilities in Wallpaper Site 1.0.09 allow remote attackers to execute arbitrary SQL commands
23RISK
open ↗Referência✓ VexDay Proof
1024 CMS 1.3.1 - Local File Inclusion / SQL Injection
Multiple directory traversal vulnerabilities in 1024 CMS 1.3.1 allow remote attackers to include and execute arbitrary l
23RISK
open ↗Referência✓ VexDay Proof
NmnNewsletter 1.0.7 - 'output' Remote File Inclusion
PHP remote file inclusion vulnerability in confirmUnsubscription.php in NmnNewsletter 1.0.7 allows remote attackers to e
23RISK
open ↗Referência✓ VexDay Proof
SkyFex Client 1.0 - ActiveX 'Start()' Method Remote Stack Overflow
Buffer overflow in a certain ActiveX control in SkyFexClient.ocx 1.0.2.77 in SkyFex Client 1.0 allows remote attackers t
23RISK
open ↗Referência✓ VexDay Proof
Haberx 1.02 < 1.1 - 'tr' SQL Injection
SQL injection vulnerability in kategorix.asp in Haberx 1.02 through 1.1 allows remote attackers to execute arbitrary SQL
23RISK
open ↗Referência✓ VexDay Proof
LulieBlog 1.02 - SQL Injection
SQL injection vulnerability in voircom.php in LulieBlog 1.02 allows remote attackers to execute arbitrary SQL commands v
23RISK
open ↗Referência✓ VexDay Proof
Exponent CMS 0.96.3 - 'view' Remote Command Execution
Directory traversal vulnerability in index.php in Exponent CMS 0.96.3 allows remote attackers to read and execute arbitr
23RISK
open ↗Referência✓ VexDay Proof
PHP-Nuke Module books SQL - 'cid' SQL Injection
SQL injection vulnerability in the Books module of PHP-Nuke allows remote attackers to execute arbitrary SQL commands vi
23RISK
open ↗Referência✓ VexDay Proof
SanyBee Gallery 0.1.1 - 'p' Local File Inclusion
Directory traversal vulnerability in index.php in SanyBee Gallery 0.1.0 and 0.1.1 allows remote attackers to include and
23RISK
open ↗Referência✓ VexDay Proof
matpo bilder galerie 1.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in includes/tumbnail.php in MatPo Bilder Galerie 1.1 allows remote attackers to
23RISK
open ↗Referência✓ VexDay Proof
Bitweaver R2 CMS - Arbitrary File Upload / Disclosure
Unrestricted file upload vulnerability in fisheye/upload.php in Bitweaver R2 CMS allows remote attackers to upload arbit
23RISK
open ↗Referência✓ VexDay Proof
Bitweaver R2 CMS - Arbitrary File Upload / Disclosure
Directory traversal vulnerability in wiki/edit.php in Bitweaver R2 CMS allows remote attackers to obtain sensitive infor
23RISK
open ↗Referência✓ VexDay Proof
XCMS 1.83 - Remote Command Execution
cpie.php in XCMS 1.83 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers t
23RISK
open ↗Referência✓ VexDay Proof
Mihalism Multi Host 2.0.7 - 'download.php' Remote File Disclosure
Directory traversal vulnerability in download.php in Mihalism Multi Host 2.0.7 allows remote attackers to read arbitrary
23RISK
open ↗Referência✓ VexDay Proof
Bitweaver 2.8.1 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Bitweaver 2.8.1 and earlier allow remote attackers to inject arbi
23RISK
open ↗Referência✓ VexDay Proof
Web//News 1.4 - 'parser.php' Remote File Inclusion (1)
PHP remote file inclusion vulnerability in parse/parser.php in WEB//NEWS (aka webnews) 1.4 and earlier allows remote att
23RISK
open ↗Referência✓ VexDay Proof
Site@School 2.4.10 - Blind SQL Injection
SQL injection vulnerability in starnet/addons/slideshow_full.php in Site@School 2.3.10 and earlier allows remote attacke
23RISK
open ↗Referência✓ VexDay Proof
Tribisur 2.0 - SQL Injection
Multiple SQL injection vulnerabilities in Tribisur 2.1 and earlier allow remote attackers to execute arbitrary SQL comma
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.