Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,465Referência 23,022GitHub PoC 15,031VulnCheck XDB 8,860Nuclei 4,361Metasploit 3,491✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
Free MP3 CD Ripper 2.6 - '.mp3' Buffer Overflow (SEH)
Stack-based buffer overflow in Free MP3 CD Ripper 2.6, when converting a file, allows user-assisted remote attackers to
23RISK
open ↗Referência✓ VexDay Proof
pl-PHP Beta 0.9 - Multiple Vulnerabilities
Directory traversal vulnerability in admin.php in pL-PHP beta 0.9 allows remote attackers to include and execute arbitra
23RISK
open ↗Referência✓ VexDay Proof
Free MP3 CD Ripper 2.6 - '.wma' Local Buffer Overflow (SEH)
Stack-based buffer overflow in Free MP3 CD Ripper 2.6, when converting a file, allows user-assisted remote attackers to
23RISK
open ↗Referência✓ VexDay Proof
Mambo Module Weather - 'absolute_path' Remote File Inclusion
PHP remote file inclusion vulnerability in mod_weather.php in the Antonis Ventouris Weather module for Mambo and Joomla!
23RISK
open ↗Referência✓ VexDay Proof
VCDGear 3.56 Build 050213 - 'FILE' Local Code Execution
Stack-based buffer overflow in VCDGear 3.55 and 3.56 BETA allows user-assisted remote attackers to execute arbitrary cod
23RISK
open ↗Referência✓ VexDay Proof
Web Slider 0.6 - 'path' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Marco Antonio Islas Cruz Web Slider (WebSlider) 0.6 allow remote a
23RISK
open ↗Referência✓ VexDay Proof
StoreFront for Gallery - 'GALLERY_BASEDIR' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in the StoreFront mods for Gallery allow remote attackers to execute
23RISK
open ↗Referência✓ VexDay Proof
openMairie 1.10 - '/scr/soustab.php' Local File Inclusion
Directory traversal vulnerability in scr/soustab.php in openMairie 1.11 and earlier allows remote attackers to include a
23RISK
open ↗Referência✓ VexDay Proof
SunShop Shopping Cart 3.5 - 'abs_path' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools SunShop Shopping Cart before 3.5.1 allow remote
23RISK
open ↗Referência✓ VexDay Proof
xoops module tsdisplay4xoops 0.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in blocks/tsdisplay4xoops_block2.php in tsdisplay4xoops (TSD4XOOPS, aka the Team
23RISK
open ↗Referência✓ VexDay Proof
ShoutPro 1.5.2 - 'shout.php' Remote Code Injection
Direct static code injection vulnerability in shoutbox.php in ShoutPro 1.5.2 allows remote attackers to inject arbitrary
35RISK
open ↗Referência✓ VexDay Proof
Joomla! Component Template Be2004-2 - 'index.php' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in the Be2004-2 template for Joomla! allows remote attackers to exe
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component JoomlaPack 1.0.4a2 RE - 'CAltInstaller.php' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/CAltInstaller.php in the JoomlaPack (com_jpack) 1.0.4a2 RE component
23RISK
open ↗Referência✓ VexDay Proof
Cabron Connector 1.1.0-Full - Remote File Inclusion
PHP remote file inclusion vulnerability in services/samples/inclusionService.php in Cabron Connector 1.1.0 allows remote
23RISK
open ↗Referência✓ VexDay Proof
Rezervi 0.9 - 'root' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Rezervi Generic 0.9 allow remote attackers to execute arbitrary PH
28RISK
open ↗Referência✓ VexDay Proof
Supasite 1.23b - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Supasite 1.23b allow remote attackers to execute arbitrary PHP cod
23RISK
open ↗Referência✓ VexDay Proof
PHPSiteBackup 0.1 - 'pcltar.lib.php' Remote File Inclusion
PHP remote file inclusion vulnerability in lib/pcltar.lib.php (aka pcltar.php) in the PclTar module 1.3 and 1.3.1 for Vi
35RISK
open ↗Referência✓ VexDay Proof
Post REvolution 0.7.0 RC 2 - 'dir' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Post Revolution 6.6 and 7.0 RC2 allow remote attackers to execute
23RISK
open ↗Referência✓ VexDay Proof
GPB Bulletin Board - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in GPL PHP Board (GPB) unstable-2001.11.14-1 allow remote attackers t
23RISK
open ↗← previouspage 188 / 188
We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.