Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,465Referência 23,022GitHub PoC 15,031VulnCheck XDB 8,860Nuclei 4,361Metasploit 3,491✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
CS-Cart 1.3.3 - 'classes_dir' Remote File Inclusion
PHP remote file inclusion vulnerability in class.cs_phpmailer.php in CS-Cart 1.3.3 allows remote attackers to execute ar
23RISK
open ↗Referência✓ VexDay Proof
OpenEMR 2.8.1 - 'fileroot' Remote File Inclusion
PHP remote file inclusion vulnerability in contrib/forms/evaluation/C_FormEvaluation.class.php in OpenEMR 2.8.1 and earl
23RISK
open ↗Referência✓ VexDay Proof
Spaminator 1.7 - 'page' Remote File Inclusion
PHP remote file inclusion vulnerability in Login.php in Spaminator 1.7 and earlier allows remote attackers to execute ar
23RISK
open ↗Referência✓ VexDay Proof
Mambo Component Peoplebook 1.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in param.peoplebook.php in the Peoplebook Component for Mambo (com_peoplebook) 1
23RISK
open ↗Referência✓ VexDay Proof
Wheatblog 1.1 - 'session.php' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/session.php in Wheatblog (wB) 1.1 and earlier, when register_globals
23RISK
open ↗Referência✓ VexDay Proof
Spidey Blog Script 1.5 - 'proje_goster.asp' SQL Injection (1)
SQL injection vulnerability in proje_goster.php in Spidey Blog Script 1.5 and earlier allows remote attackers to execute
23RISK
open ↗Referência✓ VexDay Proof
WEBInsta MM 1.3e - 'cabsolute_path' Remote File Inclusion
PHP remote file inclusion vulnerability in install3.php in WEBInsta Mailing List Manager 1.3e allows remote attackers to
23RISK
open ↗Referência✓ VexDay Proof
Thatware 0.4.6 - 'ROOT_PATH' Remote File Inclusion
PHP remote file inclusion vulnerability in config.php in David Kent Norman Thatware 0.4.6 and possibly earlier allows re
23RISK
open ↗Referência✓ VexDay Proof
MiniBill 1.22b - config[plugin_dir] Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in MiniBill 2006-07-14 (1.2.2) allow remote attackers to execute arbi
28RISK
open ↗Referência✓ VexDay Proof
C-News 1.0.1 - 'path' Remote File Inclusion
PHP remote file inclusion vulnerability in affichage/commentaires.php in C-News.fr C-News 1.0.1 and earlier allows remot
23RISK
open ↗Referência✓ VexDay Proof
MySpeach 3.0.2 - 'my_ms[root]' Remote File Inclusion
PHP remote file inclusion vulnerability in jscript.php in Sky GUNNING MySpeach 3.0.2 and earlier, when register_globals
23RISK
open ↗Referência✓ VexDay Proof
SoftBB 0.1 - 'cmd' Remote Command Execution
index.php in SoftBB 0.1, and possibly earlier, allows remote attackers to obtain the installation path via a null or inv
23RISK
open ↗Referência✓ VexDay Proof
GeekLog 1.4.0sr3 - '_CONF[path]' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in GeekLog 1.4 allow remote attackers to execute arbitrary code via a
23RISK
open ↗Referência✓ VexDay Proof
Woltlab Burning Board Lite 1.0.2 - 'decode_cookie()' SQL Injection
SQL injection vulnerability in the decode_cookie function in thread.php in Woltlab Burning Board Lite 1.0.2 allows remot
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component ChronoForms 2.3.5 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in ChronoEngine ChronoForms (com_chronocontact) 2.3.5 component for J
35RISK
open ↗Referência✓ VexDay Proof
Downstat 1.8 - 'art' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Vmist Downstat 1.8 and earlier allow remote attackers to execute a
23RISK
open ↗Referência✓ VexDay Proof
Mindmeld 1.2.0.10 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Mindmeld 1.2.0.10 allow remote attackers to execute arbitrary PHP
28RISK
open ↗Referência✓ VexDay Proof
SafeNet 10.4.0.12 - 'IPSecDrv.sys' Local kernel Ring0 SYSTEM
IPSecDrv.sys 10.4.0.12 in SafeNET HighAssurance Remote and SoftRemote allows local users to gain privileges via a crafte
23RISK
open ↗Referência✓ VexDay Proof
Libxine 1.14 - MPEG Stream Buffer Overflow (PoC)
Buffer overflow in xine_list_delete_current in libxine 1.14 and earlier, as distributed in xine-lib 1.1.1 and earlier, a
28RISK
open ↗Referência✓ VexDay Proof
Crafty Syntax Image Gallery 3.1g - Remote Code Execution
SQL injection vulnerability in slides.php in Eric Gerdes Crafty Syntax Image Gallery (CSIG) (aka PHP thumbnail Photo Gal
23RISK
open ↗Referência✓ VexDay Proof
PhotoKorn Gallery 1.543 - 'pic' SQL Injection
SQL injection vulnerability in index.php in Photokorn Gallery 1.543 allows remote attackers to execute arbitrary SQL com
23RISK
open ↗Referência✓ VexDay Proof
NERO Media Player 1.4.0.35b - '.m3u' File Buffer Overflow (PoC)
Buffer overflow in NeroMediaPlayer.exe in Nero Media Player 1.4.0.35 and earlier allows remote attackers to execute arbi
28RISK
open ↗Referência✓ VexDay Proof
GNUTURK 2G - 't_id' SQL Injection
SQL injection vulnerability in mods.php in GNUTurk 2G and earlier allows remote attackers to execute arbitrary SQL comma
23RISK
open ↗Referência✓ VexDay Proof
PHP-Update 2.7 - '/admin/uploads.php' Remote Code Execution
Unrestricted file upload vulnerability in admin/uploads.php in PHP-Update 2.7 and earlier allows remote authenticated us
23RISK
open ↗Referência✓ VexDay Proof
PHP-Update 2.7 - Multiple Vulnerabilities
Unrestricted file upload vulnerability in admin/uploads.php in PHP-Update 2.7 and earlier allows remote authenticated us
23RISK
open ↗Referência✓ VexDay Proof
ProgSys 0.156 - 'RR.php' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/pear/Net/DNS/RR.php in ProgSys 0.151 and earlier allows remote attac
23RISK
open ↗Referência✓ VexDay Proof
Digital WebShop 1.128 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Cardway (aka Frederic Boudaud) DigitalWebShop 1.128 and earlier al
23RISK
open ↗Referência✓ VexDay Proof
BCWB 0.99 - 'ROOT_PATH' Remote File Inclusion
PHP remote file inclusion vulnerability in include/startup.inc.php in CMSDevelopment Business Card Web Builder (BCWB) 0.
23RISK
open ↗Referência✓ VexDay Proof
Web-News 1.6.3 - 'template.php' Remote File Inclusion
PHP remote file inclusion vulnerability in webnews/template.php in Web-News 1.6.3 and earlier allows remote attackers to
23RISK
open ↗Referência✓ VexDay Proof
PBLang 4.66z - 'temppath' Remote File Inclusion
PHP remote file inclusion vulnerability in templates/pb/language/lang_nl.php in PBLang (PBL) 4.66z and earlier allows re
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.