Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,465Referência 23,022GitHub PoC 15,031VulnCheck XDB 8,860Nuclei 4,361Metasploit 3,491✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
Flatnuke 3 - Remote Cookie Manipulation / Privilege Escalation
Flatnuke 3 (aka FlatnuX) allows remote attackers to obtain administrative access via a myforum%00 cookie.
23RISK
open ↗Referência✓ VexDay Proof
Flatnuke 3 - Remote Command Execution / Privilege Escalation
Cross-site request forgery (CSRF) vulnerability in index.php in the File Manager module in Flatnuke 3 allows remote atta
23RISK
open ↗Referência✓ VexDay Proof
project alumni 1.0.9 - Cross-Site Scripting / SQL Injection
Multiple cross-site scripting (XSS) vulnerabilities in project alumni 1.0.9 and earlier allow remote attackers to inject
23RISK
open ↗Referência✓ VexDay Proof
WorkingOnWeb 2.0.1400 - 'events.php' SQL Injection
SQL injection vulnerability in events.php in WorkingOnWeb 2.0.1400 allows remote attackers to execute arbitrary SQL comm
23RISK
open ↗Referência✓ VexDay Proof
Content Injector 1.52 - 'index.php?cat' SQL Injection
SQL injection vulnerability in news.php in Content Injector 1.52 allows remote attackers to execute arbitrary SQL comman
23RISK
open ↗Referência✓ VexDay Proof
Plogger 3.0 - SQL Injection
Multiple SQL injection vulnerabilities in Plogger 3.0 and earlier allow remote attackers to execute arbitrary SQL comman
23RISK
open ↗Referência✓ VexDay Proof
CCProxy 6.2 - 'ping' Remote Buffer Overflow
Buffer overflow in YoungZSoft CCProxy 6.2 and earlier allows remote attackers to execute arbitrary code via a long addre
28RISK
open ↗Referência✓ VexDay Proof
CCProxy 6.2 - Telnet Proxy Ping Overflow (Metasploit)
Buffer overflow in YoungZSoft CCProxy 6.2 and earlier allows remote attackers to execute arbitrary code via a long addre
28RISK
open ↗Referência✓ VexDay Proof
WordPress Plugin PictPress 0.91 - Remote File Disclosure
Multiple directory traversal vulnerabilities in resize.php in the PictPress 0.91 and earlier plugin for WordPress allow
23RISK
open ↗Referência✓ VexDay Proof
Active Photo Gallery 6.2 - Authentication Bypass
SQL injection vulnerability in account.asp in Active Photo Gallery 6.2 allows remote attackers to execute arbitrary SQL
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component com_books - 'book_id' SQL Injection
SQL injection vulnerability in the Books (com_books) component for Joomla! allows remote attackers to execute arbitrary
23RISK
open ↗Referência✓ VexDay Proof
falcon CMS 1.4.3 - Remote File Inclusion / Cross-Site Scripting
Cross-site request forgery (CSRF) vulnerability in Falcon Series One CMS 1.4.3 allows remote attackers to change a passw
23RISK
open ↗Referência✓ VexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote attackers to register arbitrary users via a request to host
23RISK
open ↗Referência✓ VexDay Proof
DELTAScripts PHP Shop 1.0 - Authentication Bypass
SQL injection vulnerability in admin/login.php in DeltaScripts PHP Shop 1.0 allows remote attackers to execute arbitrary
23RISK
open ↗Referência✓ VexDay Proof
WinFTP Server 2.3.0 - 'PASV Mode' Remote Denial of Service
WinFTP FTP Server 2.3.0, when passive (aka PASV) mode is used, allows remote authenticated users to cause a denial of se
43RISK
open ↗Referência✓ VexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
Hosting Controller 6.1 Hot fix 3.3 and earlier (1) allows remote attackers to change arbitrary user profiles via a reque
23RISK
open ↗Referência✓ VexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
Multiple unspecified vulnerabilities in Hosting Controller 6.1 Hot fix 3.3 and earlier allow remote authenticated users
23RISK
open ↗Referência✓ VexDay Proof
WordPress Plugin Page Flip Image Gallery 0.2.2 - Remote File Disclosure
Directory traversal vulnerability in getConfig.php in the Page Flip Image Gallery plugin 0.2.2 and earlier for WordPress
23RISK
open ↗Referência✓ VexDay Proof
BulletProof FTP Client 2.63 - Local Heap Overflow (PoC)
Stack-based buffer overflow in BulletProof FTP Client 2.63 and 2010 allows user-assisted attackers to execute arbitrary
23RISK
open ↗Referência✓ VexDay Proof
TUTOS 1.3 - 'cmd.php' Remote Command Execution
TUTOS 1.3 allows remote attackers to read system information via a direct request to php/admin/phpinfo.php, which calls
23RISK
open ↗Referência✓ VexDay Proof
FlexBB 0.6.3 - Cookies SQL Injection
SQL injection vulnerability in FlexBB 0.6.3 and earlier allows remote attackers to execute arbitrary SQL commands via th
23RISK
open ↗Referência✓ VexDay Proof
Gateway Weblaunch - ActiveX Control Insecure Method
Multiple stack-based buffer overflows in the WebLaunch.WeblaunchCtl.1 (aka CWebLaunchCtl) ActiveX control in weblaunch.o
28RISK
open ↗Referência✓ VexDay Proof
Gateway WebLaunch - ActiveX Remote Buffer Overflow
Multiple stack-based buffer overflows in the WebLaunch.WeblaunchCtl.1 (aka CWebLaunchCtl) ActiveX control in weblaunch.o
28RISK
open ↗Referência✓ VexDay Proof
osData 2.08 Modules Php121 - Local File Inclusion
PHP remote file inclusion vulnerability in php121db.php in osDate 2.0.8 and possibly earlier versions allows remote atta
23RISK
open ↗Referência✓ VexDay Proof
ZeroCMS 1.0 Alpha - Arbitrary File Upload / SQL Injection
Multiple SQL injection vulnerabilities in Zero CMS 1.0 Alpha allow remote attackers to execute arbitrary SQL commands vi
23RISK
open ↗Referência✓ VexDay Proof
Agares phpAutoVideo 2.21 - 'articlecat' SQL Injection (2)
SQL injection vulnerability in includes/articleblock.php in Agares PhpAutoVideo 2.21 allows remote attackers to execute
23RISK
open ↗Referência✓ VexDay Proof
ImageAlbum 2.0.0b2 - 'id' SQL Injection
Multiple SQL injection vulnerabilities in ImageAlbum 2.0.0b2 allow remote attackers to execute arbitrary SQL commands vi
23RISK
open ↗Referência✓ VexDay Proof
SCO UnixWare < 7.1.4 p534589 - 'pkgadd' Local Privilege Escalation
Directory traversal vulnerability in pkgadd in SCO UnixWare 7.1.4 before p534589 allows local users to create or append
23RISK
open ↗Referência✓ VexDay Proof
Aria 0.99-6 - 'page' Local File Inclusion
Directory traversal vulnerability in arias/help/effect.php in aria 0.99-6 allows remote attackers to include and execute
23RISK
open ↗Referência✓ VexDay Proof
PHPEcho CMS 2.0 - 'id' SQL Injection
SQL injection vulnerability in index.php in the forum module in PHPEcho CMS, probably 2.0-rc3 and earlier, allows remote
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.