Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,465Referência 23,022GitHub PoC 15,031VulnCheck XDB 8,860Nuclei 4,361Metasploit 3,491✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
Motorola Timbuktu Pro 8.6.5 - File Deletion/Creation
Directory traversal vulnerability in the Notes (aka Flash Notes or instant messages) feature in tb2ftp.dll in Timbuktu P
50RISK
open ↗Referência✓ VexDay Proof
Motorola Timbuktu Pro 8.6.5/8.7 - Directory Traversal / Log Injection
Directory traversal vulnerability in the Notes (aka Flash Notes or instant messages) feature in tb2ftp.dll in Timbuktu P
50RISK
open ↗Referência✓ VexDay Proof
Barryvan Compo Manager 0.3 - Remote File Inclusion
PHP remote file inclusion vulnerability in main.php in Barryvan Compo Manager 0.3 allows remote attackers to execute arb
28RISK
open ↗Referência✓ VexDay Proof
Mambo Component garyscookbook 1.1.1 - SQL Injection
SQL injection vulnerability in the Garys Cookbook (com_garyscookbook) 1.1.1 and earlier component for Mambo and Joomla!
23RISK
open ↗Referência✓ VexDay Proof
DESlock+ < 3.2.6 - Local Kernel Ring0 link list zero SYSTEM
DESlock+ 3.2.6 and earlier, when DLMFENC.sys 1.0.0.26 and DLMFDISK.sys 1.2.0.27 are present, allows local users to gain
23RISK
open ↗Referência✓ VexDay Proof
Affiliate Market 0.1 Beta - Cross-Site Scripting / SQL Injection
SQL injection vulnerability in shop/detail.php in Affiliate Market (affmarket) 0.1 BETA allows remote attackers to execu
23RISK
open ↗Referência✓ VexDay Proof
WebSPELL 4.01.02 - 'picture.php' File Disclosure
Directory traversal vulnerability in picture.php in WebSPELL 4.01.02 and earlier, when PHP before 4.3.0 is used, allows
23RISK
open ↗Referência✓ VexDay Proof
phpMyNewsletter 0.8 (beta5) - Multiple Vulnerabilities
admin/index.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier provides access to configuration modification
23RISK
open ↗Referência✓ VexDay Proof
Internet Download Accelerator 5.2 - Remote Buffer Overflow (PoC)
Buffer overflow in the NotSafe function in the idaiehlp ActiveX control in idaiehlp.dll 1.9.1.74 in Internet Download Ac
23RISK
open ↗Referência✓ VexDay Proof
EDraw Office Viewer Component - Unsafe Method
A certain ActiveX control in the EDraw Office Viewer Component (edrawofficeviewer.ocx) 4.0.5.20, and other versions befo
23RISK
open ↗Referência✓ VexDay Proof
dagger Web engine 23jan2007 - Remote File Inclusion
PHP remote file inclusion vulnerability in cal.func.php in Valerio Capello Dagger - The Cutting Edge r23jan2007 allows r
45RISK
open ↗Referência✓ VexDay Proof
Pharmacy System 2.0 - 'index.php?ID' SQL Injection
SQL injection vulnerability in index.php in Pharmacy System 2 and earlier allows remote attackers to execute arbitrary S
23RISK
open ↗Referência✓ VexDay Proof
RKD Software BarCode ActiveX Control 'BarCodeAx.dll' 4.9 - Remote Overflow
Stack-based buffer overflow in the BeginPrint method in a certain ActiveX control in RKD Software (barcodetools.com) Bar
50RISK
open ↗Referência✓ VexDay Proof
Ripe Website Manager (CMS) 0.8.9 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Ripe Website Manager 0.8.9 and earlier allow remote attackers to e
35RISK
open ↗Referência✓ VexDay Proof
Buddy Zone 1.5 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in Buddy Zone 1.5 and earlier allow remote attackers to execute arbitrary SQL com
23RISK
open ↗Referência✓ VexDay Proof
Traffic Stats - 'referralUrl.php?offset' SQL Injection
SQL injection vulnerability in referralUrl.php in Traffic Stats allows remote attackers to execute arbitrary SQL command
23RISK
open ↗Referência✓ VexDay Proof
Microsoft Windows RSH daemon 1.7 - Remote Buffer Overflow
Stack-based buffer overflow in Mike Dubman Windows RSH daemon (rshd) 1.7 allows remote attackers to execute arbitrary co
28RISK
open ↗Referência✓ VexDay Proof
paBugs 2.0 Beta 3 - 'main.php?cid' SQL Injection
SQL injection vulnerability in main.php in paBugs 2.0 Beta 3 and earlier allows remote attackers to execute arbitrary SQ
23RISK
open ↗Referência✓ VexDay Proof
Microsoft Windows - DHCP Client Broadcast (MS06-036)
Buffer overflow in the DHCP Client service for Microsoft Windows 2000 SP4, Windows XP SP1 and SP2, and Server 2003 up to
45RISK
open ↗Referência✓ VexDay Proof
PHP 5.2.0 (Windows x86) - 'PHP_win32sti' Local Buffer Overflow
Buffer overflow in php_win32std.dll in the win32std extension for PHP 5.2.0 and earlier allows context-dependent attacke
23RISK
open ↗Referência✓ VexDay Proof
Remote Mouse GUI 3.008 - Local Privilege Escalation
Emote Interactive Remote Mouse 3.008 on Windows allows attackers to execute arbitrary programs as Administrator by using
23RISK
open ↗Referência✓ VexDay Proof
aForum 1.32 - 'CommonAbsDir' Remote File Inclusion
PHP remote file inclusion vulnerability in common/func.php in aForum 1.32 and earlier allows remote attackers to execute
23RISK
open ↗Referência✓ VexDay Proof
Monalbum 0.8.7 - Remote Code Execution
Static code injection vulnerability in admin/admin_configuration.php in Monalbum 0.8.7 allows remote authenticated users
23RISK
open ↗Referência✓ VexDay Proof
BlogMe 3.0 - 'archshow.asp?var' SQL Injection
SQL injection vulnerability in archshow.asp in BlogMe 3.0 allows remote attackers to execute arbitrary SQL commands via
23RISK
open ↗Referência✓ VexDay Proof
BitchX 1.1-final - 'EXEC' Remote Command Execution
hook.c in BitchX 1.1-final allows remote IRC servers to execute arbitrary commands by sending a client certain data cont
23RISK
open ↗Referência✓ VexDay Proof
SonicWALL SSL-VPN - 'NeLaunchCtrl' ActiveX Control Remote Command Execution
Stack-based buffer overflow in the SonicWall SSL-VPN NetExtender NELaunchCtrl ActiveX control before 2.1.0.51, and 2.5.x
50RISK
open ↗Referência✓ VexDay Proof
Sony CONNECT Player 4.x - '.m3u' Local Stack Overflow
Stack-based buffer overflow in Sony SonicStage CONNECT Player (CP) 4.3 allows remote attackers to execute arbitrary code
28RISK
open ↗Referência✓ VexDay Proof
ProfileCMS 1.0 - Arbitrary File Upload
Unrestricted file upload vulnerability in the profiles script in ProfileCMS 1.0 allows remote attackers to upload and ex
23RISK
open ↗Referência✓ VexDay Proof
Jakarta Slide 2.1 RC1 - Remote File Disclosure
Absolute path traversal vulnerability in Apache Jakarta Slide 2.1 and earlier allows remote authenticated users to read
23RISK
open ↗Referência✓ VexDay Proof
Surgemail 38k - 'Search' Remote Buffer Overflow
Stack-based buffer overflow in the IMAP service in SurgeMail 38k allows remote authenticated users to execute arbitrary
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.