Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,465Referência 23,022GitHub PoC 15,031VulnCheck XDB 8,860Nuclei 4,361Metasploit 3,491✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
STWC-Counter 3.4.0 - 'downloadcounter.php' Remote File Inclusion
PHP remote file inclusion vulnerability in downloadcounter.php in STWC-Counter 3.4.0.0 and earlier allows remote attacke
23RISK
open ↗Referência✓ VexDay Proof
Connectix Boards 0.7 - 'p_skin' Multiple Vulnerabilities
Unrestricted file upload vulnerability in admin.bbcode.php in Connectix Boards 0.7 and earlier allows remote authenticat
23RISK
open ↗Referência✓ VexDay Proof
WebMod 0.48 - Content-Length Remote Buffer Overflow
Stack-based buffer overflow in the connectHandle function in server.cpp in WebMod 0.48 allows remote attackers to execut
23RISK
open ↗Referência✓ VexDay Proof
SonicMailer Pro 3.2.3 - 'index.php' SQL Injection
SQL injection vulnerability in index.php in Triexa SonicMailer Pro 3.2.3 and earlier allows remote attackers to execute
23RISK
open ↗Referência✓ VexDay Proof
AssetMan 2.4a - 'download_pdf.php' Remote File Disclosure
Directory traversal vulnerability in download_pdf.php in AssetMan 2.4a and earlier allows remote attackers to read arbit
23RISK
open ↗Referência✓ VexDay Proof
creative Guestbook 1.0 - Multiple Vulnerabilities
Creative Guestbook 1.0 allows remote attackers to add an administrative account via a direct request to createadmin.php
23RISK
open ↗Referência✓ VexDay Proof
wbblog - Cross-Site Scripting / SQL Injection
SQL injection vulnerability in index.php in WBBlog allows remote attackers to execute arbitrary SQL commands via the e_i
23RISK
open ↗Referência✓ VexDay Proof
wbblog - Cross-Site Scripting / SQL Injection
Cross-site scripting (XSS) vulnerability in index.php in WBBlog allows remote attackers to inject arbitrary web script o
23RISK
open ↗Referência✓ VexDay Proof
WebLog - 'index.php' Remote File Disclosure
Directory traversal vulnerability in index.php in Sascha Schroeder (aka CyberTeddy or Cyber-inside) WebLog allows remote
23RISK
open ↗Referência✓ VexDay Proof
Avant Browser 11.0 build 26 - Remote Stack Overflow Crash
Stack-based buffer overflow in Avant Browser 11.0 build 26 allows remote attackers to cause a denial of service (crash)
23RISK
open ↗Referência✓ VexDay Proof
osTicket 1.11 - Cross-Site Scripting / Local File Inclusion
In osTicket before 1.12, XSS exists via /upload/file.php, /upload/scp/users.php?do=import-users, and /upload/scp/ajax.ph
23RISK
open ↗Referência✓ VexDay Proof
pNews 1.1.0 - 'nbs' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/global.php in Joshua Wilson pNews System 1.1.0 (aka PowerNews) allow
23RISK
open ↗Referência✓ VexDay Proof
ApowerManager 3.1.7 - Phone Manager Remote Denial of Service (PoC)
The ApowerManager application through 3.1.7 for Android allows remote attackers to cause a denial of service via many si
23RISK
open ↗Referência✓ VexDay Proof
Active Link Engine - 'default.asp?catid' SQL Injection
SQL injection vulnerability in default.asp in ActiveWebSoftwares Active Link Engine allows remote attackers to execute a
23RISK
open ↗Referência✓ VexDay Proof
ClassWeb 2.0.3 - 'BASE' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in ClassWeb 2.03 and earlier allow remote attackers to execute arbitr
23RISK
open ↗Referência✓ VexDay Proof
PortailPhp 2.0 - 'idnews' SQL Injection
SQL injection vulnerability in index.php in PortailPHP 2.0 allows remote attackers to execute arbitrary SQL commands via
23RISK
open ↗Referência✓ VexDay Proof
Active NewsLetter 4.3 - 'ViewNewspapers.asp' SQL Injection
SQL injection vulnerability in ViewNewspapers.asp in Active Newsletter 4.3 and earlier allows remote attackers to execut
23RISK
open ↗Referência✓ VexDay Proof
Philex 0.2.3 - Remote File Inclusion / File Disclosure
download.php in Philex 0.2.3 and earlier allows remote attackers to read arbitrary files and source code, and obtain sen
23RISK
open ↗Referência✓ VexDay Proof
Mambo Module Flatmenu 1.07 - Remote File Inclusion
PHP remote file inclusion vulnerability in mod_flatmenu.php in the Flatmenu 1.07 and earlier Mambo module allows remote
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component RWCards 2.4.3 - SQL Injection
SQL injection vulnerability in index.php in the RWCards (com_rwcards) 2.4.3 and earlier component for Joomla! allows rem
23RISK
open ↗Referência✓ VexDay Proof
Active Trade 2 - 'catid' SQL Injection
SQL injection vulnerability in default.asp in Active Trade 2 allows remote attackers to execute arbitrary SQL commands v
23RISK
open ↗Referência✓ VexDay Proof
eWebquiz 8 - 'eWebQuiz.asp' SQL Injection
SQL injection vulnerability in eWebQuiz.asp in eWebQuiz 8 allows remote attackers to execute arbitrary SQL commands via
23RISK
open ↗Referência✓ VexDay Proof
ttCMS 4 - 'ez_sql.php?lib_path' Remote File Inclusion
PHP remote file inclusion vulnerability in lib/db/ez_sql.php in ttCMS 4 and earlier allows remote attackers to execute a
23RISK
open ↗Referência✓ VexDay Proof
Corel WordPerfect X3 13.0.0.565 - '.prs' Local Buffer Overflow
Stack-based buffer overflow in Corel WordPerfect Office X3 (13.0.0.565) allows user-assisted remote attackers to execute
23RISK
open ↗Referência✓ VexDay Proof
HIOX GUEST BOOK (HGB) 4.0 - Remote Code Execution
Direct static code injection vulnerability in HIOX Guest Book (HGB) 4.0 allows remote attackers to inject arbitrary PHP
23RISK
open ↗Referência✓ VexDay Proof
gtcatalog 0.9.1 - 'index.php' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in Chris Mac gtcatalog (aka GimeScripts Shopping Catalog) 0.9.1 and
23RISK
open ↗Referência✓ VexDay Proof
Scorp Book 1.0 - 'smilies.php?config' Remote File Inclusion
PHP remote file inclusion vulnerability in smilies.php in Scorp Book 1.0 allows remote attackers to execute arbitrary PH
23RISK
open ↗Referência✓ VexDay Proof
XOOPS Module Rha7 Downloads 1.0 - 'visit.php' SQL Injection
SQL injection vulnerability in visit.php in the Rha7 Downloads (rha7downloads) 1.0 module for XOOPS, and possibly other
23RISK
open ↗Referência✓ VexDay Proof
MyBulletinBoard (MyBB) 1.2.3 - Remote Code Execution
SQL injection vulnerability in the create_session function in class_session.php in MyBB (aka MyBulletinBoard) 1.2.3 and
23RISK
open ↗Referência✓ VexDay Proof
XOOPS Module WF-Section 1.01 - 'articleId' SQL Injection
SQL injection vulnerability in the getArticle function in class/wfsarticle.php in WF-Section (aka WF-Sections) 1.0.1, as
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.