Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,465Referência 23,022GitHub PoC 15,031VulnCheck XDB 8,860Nuclei 4,361Metasploit 3,491✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
DL PayCart 1.01 - 'viewitem.php?ItemID' Blind SQL Injection
SQL injection vulnerability in viewitem.php in DL PayCart 1.01 allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗Referência✓ VexDay Proof
PHPNuke-Clan 4.2.0 - 'mvcw_conver.php' Remote File Inclusion
PHP remote file inclusion vulnerability in convert/mvcw_conver.php in the Virtual War (VWar) module for PHPNuke-Clan (PN
23RISK
open ↗Referência✓ VexDay Proof
phpBB Links MOD 1.2.2 - SQL Injection
SQL injection vulnerability in links.php in the Links MOD 1.2.2 and earlier for phpBB 2.0.22 and earlier allows remote a
23RISK
open ↗Referência✓ VexDay Proof
eNetman 20050830 - 'index.php' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in eNetman 1 allows remote attackers to execute arbitrary PHP code
35RISK
open ↗Referência✓ VexDay Proof
Move Networks Quantum Streaming Player - Remote Overflow (SEH)
Multiple stack-based buffer overflows in the Quantum Streaming Internet Explorer Player ActiveX control in qsp2ie0705100
28RISK
open ↗Referência✓ VexDay Proof
OtsTurntables 1.00 - '.m3u' Local Buffer Overflow
Buffer overflow in Ots Labs OTSTurntables 1.00 allows user-assisted remote attackers to execute arbitrary code via a lon
23RISK
open ↗Referência✓ VexDay Proof
X-Cart - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in X-Cart allow remote attackers to execute arbitrary PHP code via a
23RISK
open ↗Referência✓ VexDay Proof
JetCast Server 2.0.0.4308 - Remote Denial of Service
JSMP3OGGWt.dll in JetCast Server 2.0.0.4308 allows remote attackers to cause a denial of service (daemon crash) via a lo
23RISK
open ↗Referência✓ VexDay Proof
JBlog 1.0 - 'index.php?id' SQL Injection
Multiple SQL injection vulnerabilities in JBlog 1.0 allow (1) remote attackers to execute arbitrary SQL commands via the
23RISK
open ↗Referência✓ VexDay Proof
PHP Webquest 2.5 - 'id_actividad' SQL Injection
SQL injection vulnerability in soporte_derecha_w.php in PHP Webquest 2.5 and earlier allows remote attackers to execute
23RISK
open ↗Referência✓ VexDay Proof
Streamline PHP Media Server 1.0-beta4 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Streamline PHP Media Server 1.0-beta4 allow remote attackers to ex
35RISK
open ↗Referência✓ VexDay Proof
OneCMS 2.4 - 'abc' SQL Injection
SQL injection vulnerability in userreviews.php in OneCMS 2.4 allows remote attackers to execute arbitrary SQL commands v
23RISK
open ↗Referência✓ VexDay Proof
Airsensor M520 - HTTPd Remote Denial of Service / Buffer Overflow (PoC)
Multiple buffer overflows in the AirDefense Airsensor M520 with firmware 4.3.1.1 and 4.4.1.4 allow remote authenticated
23RISK
open ↗Referência✓ VexDay Proof
neuron news 1.0 - 'index.php?q' Local File Inclusion
Directory traversal vulnerability in index.php in Neuron News 1.0 allows remote attackers to include and execute arbitra
23RISK
open ↗Referência✓ VexDay Proof
ActiveKB KnowledgeBase 2.x - 'catId' SQL Injection
SQL injection vulnerability in index.php in Interspire ActiveKB NX 2.x allows remote attackers to execute arbitrary SQL
23RISK
open ↗Referência✓ VexDay Proof
ImageStation - 'SonyISUpload.cab 1.0.0.38' ActiveX Buffer Overflow (PoC)
Buffer overflow in the Sony AxRUploadServer.AxRUploadControl.1 ActiveX control in AxRUploadServer.dll 1.0.0.38 in SonyIS
28RISK
open ↗Referência✓ VexDay Proof
phpArcadeScript 3.0RC2 - 'userid' SQL Injection
SQL injection vulnerability in index.php in phpArcadeScript 1.0 through 3.0 RC2 allows remote attackers to execute arbit
23RISK
open ↗Referência✓ VexDay Proof
1024 CMS 1.4.2 - Local File Inclusion / Blind SQL Injection
SQL injection vulnerability in includes/system.php in 1024 CMS 1.4.2 beta and earlier, when magic_quotes_gpc is disabled
23RISK
open ↗Referência✓ VexDay Proof
Dream4 Koobi Pro 6.25 Poll - 'poll_id' SQL Injection
SQL injection vulnerability in index.php in dream4 Koobi Pro 6.25 allows remote attackers to execute arbitrary SQL comma
23RISK
open ↗Referência✓ VexDay Proof
Smeego 1.0 - 'Cookie lang' Local File Inclusion
Directory traversal vulnerability in index.php in Smeego 1.0, when magic_quotes_gpc is disabled, allows remote attackers
23RISK
open ↗Referência✓ VexDay Proof
Archangel Weblog 0.90.02 - 'post_id' SQL Injection
SQL injection vulnerability in index.php in Archangel Weblog 0.90.02 and earlier allows remote attackers to execute arbi
23RISK
open ↗Referência✓ VexDay Proof
Flatnuke 3 - Remote Cookie Manipulation / Privilege Escalation
Flatnuke 3 (aka FlatnuX) allows remote attackers to obtain administrative access via a myforum%00 cookie.
23RISK
open ↗Referência✓ VexDay Proof
Flatnuke 3 - Remote Command Execution / Privilege Escalation
Cross-site request forgery (CSRF) vulnerability in index.php in the File Manager module in Flatnuke 3 allows remote atta
23RISK
open ↗Referência✓ VexDay Proof
project alumni 1.0.9 - Cross-Site Scripting / SQL Injection
Multiple cross-site scripting (XSS) vulnerabilities in project alumni 1.0.9 and earlier allow remote attackers to inject
23RISK
open ↗Referência✓ VexDay Proof
WorkingOnWeb 2.0.1400 - 'events.php' SQL Injection
SQL injection vulnerability in events.php in WorkingOnWeb 2.0.1400 allows remote attackers to execute arbitrary SQL comm
23RISK
open ↗Referência✓ VexDay Proof
Content Injector 1.52 - 'index.php?cat' SQL Injection
SQL injection vulnerability in news.php in Content Injector 1.52 allows remote attackers to execute arbitrary SQL comman
23RISK
open ↗Referência✓ VexDay Proof
Plogger 3.0 - SQL Injection
Multiple SQL injection vulnerabilities in Plogger 3.0 and earlier allow remote attackers to execute arbitrary SQL comman
23RISK
open ↗Referência✓ VexDay Proof
CCProxy 6.2 - 'ping' Remote Buffer Overflow
Buffer overflow in YoungZSoft CCProxy 6.2 and earlier allows remote attackers to execute arbitrary code via a long addre
28RISK
open ↗Referência✓ VexDay Proof
CCProxy 6.2 - Telnet Proxy Ping Overflow (Metasploit)
Buffer overflow in YoungZSoft CCProxy 6.2 and earlier allows remote attackers to execute arbitrary code via a long addre
28RISK
open ↗Referência✓ VexDay Proof
WordPress Plugin PictPress 0.91 - Remote File Disclosure
Multiple directory traversal vulnerabilities in resize.php in the PictPress 0.91 and earlier plugin for WordPress allow
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.