Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,465Referência 23,022GitHub PoC 15,031VulnCheck XDB 8,860Nuclei 4,361Metasploit 3,491✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
Microsoft Windows - 'NetrWkstaUserEnum()' Remote Denial of Service
The Workstation service in Microsoft Windows 2000 SP4 and XP SP2 allows remote attackers to cause a denial of service (m
35RISK
open ↗Referência✓ VexDay Proof
BolinTech DreamFTP Server 1.0.2 - 'PORT' Remote Denial of Service
BolinTech Dream FTP Server 1.02 allows remote authenticated users, including anonymous users, to cause a denial of servi
23RISK
open ↗Referência✓ VexDay Proof
cwmVote 1.0 - 'archive.php' Remote File Inclusion
PHP remote file inclusion vulnerability in archive.php in cwmVote 1.0 allows remote attackers to execute arbitrary PHP c
23RISK
open ↗Referência✓ VexDay Proof
Paristemi 0.8.3b - 'buycd.php' Remote File Inclusion
PHP remote file inclusion vulnerability in buycd.php in Paristemi 0.8.3 allows remote attackers to execute arbitrary PHP
23RISK
open ↗Referência✓ VexDay Proof
Ixprim CMS 1.2 - Blind SQL Injection
The code function in install.fct.php in Ixprim 1.2 produces a guessable value of the confidential IXP_CODE in mainfile.p
23RISK
open ↗Referência✓ VexDay Proof
cwmExplorer 1.0 - 'show_file' Source Code Disclosure
Directory traversal vulnerability in index.php in cwmExplorer 1.0 allows remote attackers to read arbitrary files and so
23RISK
open ↗Referência✓ VexDay Proof
Http explorer Web Server 1.02 - Directory Traversal
Directory traversal vulnerability in Http explorer 1.02 allows remote attackers to read arbitrary files via a .. (dot do
23RISK
open ↗Referência✓ VexDay Proof
Enthrallweb eCoupons 1.0 - 'myprofile.asp' Remote Pass Change
myprofile.asp in Enthrallweb eCoupons does not properly validate the MM_recordId parameter during profile updates, which
23RISK
open ↗Referência✓ VexDay Proof
Enthrallweb eNews 1.0 - Remote User Pass Change
myprofile.asp in Enthrallweb eNews does not properly validate the MM_recordId parameter during profile updates, which al
23RISK
open ↗Referência✓ VexDay Proof
Yrch 1.0 - 'plug.inc.phppath' Remote File Inclusion
PHP remote file inclusion vulnerability in plugins/metasearch/plug.inc.php in Yrch! 1.0 allows remote attackers to execu
23RISK
open ↗Referência✓ VexDay Proof
b2 Blog 0.5 - 'b2verifauth.php' Remote File Inclusion
PHP remote file inclusion vulnerability in b2verifauth.php in b2 Blog 0.5 and earlier allows remote attackers to execute
23RISK
open ↗Referência✓ VexDay Proof
aFAQ 1.0 - 'faqDsp.asp?catcode' SQL Injection
SQL injection vulnerability in faqDsp.asp in aFAQ 1.0 allows remote attackers to execute arbitrary SQL commands via the
23RISK
open ↗Referência✓ VexDay Proof
phpBB2 Plus 1.53 - Acronym Mod SQL Injection
SQL injection vulnerability in admin/admin_acronyms.php in the Acronym Mod 0.9.5 for phpBB2 Plus 1.53 allows remote atta
23RISK
open ↗Referência✓ VexDay Proof
wywo inout board 1.0 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in While You Were Out (WYWO) InOut Board 1.0 allow remote attackers to execute ar
23RISK
open ↗Referência✓ VexDay Proof
RealPlayer 10.5 'ierpplug.dll' Internet Explorer 7 - Denial of Service
An ActiveX control in ierpplug.dll for RealNetworks RealPlayer 10.5 allows remote attackers to cause a denial of service
23RISK
open ↗Referência✓ VexDay Proof
ASPTicker 1.0 - Authentication Bypass
SQL injection vulnerability in admin.asp in ASPTicker 1.0 allows remote attackers to execute arbitrary SQL commands via
23RISK
open ↗Referência✓ VexDay Proof
Shadowed Portal Module Character Roster - 'mod_root' Remote File Inclusion
PHP remote file inclusion vulnerability in include.php in the Roster Module (character_roster) in Shadowed Portal 5.7 al
23RISK
open ↗Referência✓ VexDay Proof
AIDeX Mini-WebServer 1.1 - Remote Crash (Denial of Service)
AIDeX Mini-WebServer 1.1 early release 3 allows remote attackers to cause a denial of service (daemon crash) via a flood
23RISK
open ↗Referência✓ VexDay Proof
WordPress Plugin Enigma 2 Bridge - 'boarddir' Remote File Inclusion
PHP remote file inclusion vulnerability in the Enigma2 plugin (Enigma2.php) in Enigma WordPress Bridge allows remote att
53RISK
open ↗Referência✓ VexDay Proof
SoftArtisans SAFileUp 5.0.14 - 'viewsrc.asp' Script Source Disclosure
Directory traversal vulnerability in SAFileUpSamples/util/viewsrc.asp in SoftArtisans FileUp (SAFileUp) 5.0.14 allows re
23RISK
open ↗Referência✓ VexDay Proof
eNdonesia 8.4 - '/mod.php/friend.php/admin.php' Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in eNdonesia 8.4 allow remote attackers to inject arbitrary web scri
23RISK
open ↗Referência✓ VexDay Proof
PHP-Update 2.7 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in code/guestadd.php in PHP-Update 2.7 and earlier allow remote attackers to exec
23RISK
open ↗Referência✓ VexDay Proof
Macromedia Shockwave 10 'SwDir.dll' Internet Explorer 7 - Denial of Service
An ActiveX control in SwDir.dll in Macromedia Shockwave 10 allows remote attackers to cause a denial of service (Interne
23RISK
open ↗Referência✓ VexDay Proof
Voodoo chat 1.0RC1b - 'users.dat' Password Disclosure
Voodoo chat 1.0RC1b stores sensitive information under the web root with insufficient access control, which allows remot
23RISK
open ↗Referência✓ VexDay Proof
Vz (Adp) Forum 2.0.3 - Remote Password Disclosure
Vz (Adp) Forum 2.0.3 stores sensitive information under the web root with insufficient access control, which allows remo
23RISK
open ↗Referência✓ VexDay Proof
Formbankserver 1.9 - 'Name' Remote Denial of Service
formbankcgi.exe in Fersch Formbankserver 1.9, when the PATH_INFO begins with Abfrage, allows remote attackers to cause a
23RISK
open ↗Referência✓ VexDay Proof
Quote&Ordering System 1.0 - 'ordernum' Multiple Vulnerabilities
SQL injection vulnerability in search.asp in Digitizing Quote And Ordering System 1.0 allows remote authenticated users
23RISK
open ↗Referência✓ VexDay Proof
CA BrightStor ARCserve - 'tapeeng.exe' Remote Buffer Overflow
Multiple buffer overflows in Computer Associates (CA) BrightStor ARCserve Backup R11.5 Server before SP2 allows remote a
28RISK
open ↗Referência✓ VexDay Proof
PHPGiggle 12.08 - 'CFG_PHPGIGGLE_ROOT' File Inclusion
PHP remote file inclusion vulnerability in kernel/system/startup.php in J. He PHPGiggle 12.08 and earlier, as distribute
23RISK
open ↗Referência✓ VexDay Proof
JAF CMS 4.0 RC2 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in JAF CMS 4.0 and 4.0 RC2 allow remote attackers to execute arbitrar
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.