Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
75,652cataloged exploits
34,545CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,581GitHub PoC 13,708VulnCheck XDB 8,225Nuclei 4,228Metasploit 3,467✓ verified onlyrecentpopularrisk
21,554 exploits
Referência✓ VexDay Proof
OPT Max 1.2.0 - 'CRM_inc' Remote File Inclusion
PHP remote file inclusion vulnerability in include/urights.php in Outreach Project Tool (OPT) Max 1.2.6 and earlier allo
23RISK
open ↗Referência
CVE-2021-36520
A SQL injection vulnerability in I-Tech Trainsmart r1044 exists via a evaluation/assign-evaluation?id= URI.
41RISK
open ↗Referência✓ VexDay Proof
phpFullAnnu 5.1 - 'repmod' Remote File Inclusion
PHP remote file inclusion vulnerability in modules/home.module.php in phpFullAnnu 5.1 and earlier allows remote attacker
23RISK
open ↗Referência
CVE-2018-8584
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (A
23RISK
open ↗Referência✓ VexDay Proof
Star FTP Server 1.10 - 'RETR' Remote Denial of Service
Fightersoft Multimedia Star FTP server 1.10 allows remote attackers to cause a denial of service (crash) via multiple RE
23RISK
open ↗Referência
CVE-2023-0902
SourceCodester Simple Food Ordering System process_order.php cross site scripting
28RISK
open ↗Referência✓ VexDay Proof
photokron 1.7 - Remote Database Disclosure
PhotoKorn allows remote attackers to obtain database credentials via a direct request to update/update3.php, which inclu
23RISK
open ↗Referência✓ VexDay Proof
BolinOS 4.6.1 - Local File Inclusion / Cross-Site Scripting
BolinOS 4.6.1 allows remote attackers to obtain sensitive information via a direct request to system/actionspages/_b/con
23RISK
open ↗Referência✓ VexDay Proof
FREEze Greetings 1.0 - Remote Password Retrieve
ScriptsEz FREEze Greetings 1.0 stores pwd.txt under the web root with insufficient access control, which allows remote a
23RISK
open ↗Referência✓ VexDay Proof
Noticeware E-mail Server 5.1.2.2 - 'POP3' Denial of Service
NoticeWare Email Server NG 5.1.2.2 allows remote attackers to cause a denial of service (crash) via multiple POP3 reques
23RISK
open ↗Referência
CVE-2010-2340
SQL injection vulnerability in members.php in Arab Portal 2.2, when magic_quotes_gpc is disabled, allows remote attacker
23RISK
open ↗Referência
CVE-2010-2505
Soft SaschArt SasCAM Webcam Server 2.6.5, 2.7, and earlier allows remote attackers to cause a denial of service (crash)
23RISK
open ↗Referência
CVE-2010-2342
SQL injection vulnerability in onlinenotebookmanager.asp in DMXReady Online Notebook Manager 1.0 allows remote attackers
23RISK
open ↗Referência
CVE-2019-1364
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle o
23RISK
open ↗Referência
CVE-2009-3366
Directory traversal vulnerability in navigation.php in An image gallery 1.0 allows remote attackers to list arbitrary di
23RISK
open ↗Referência✓ VexDay Proof
WoW Roster 1.5.1 - 'subdir' Remote File Inclusion
PHP remote file inclusion vulnerability in conf.php in WoWRoster (aka World of Warcraft Roster) 1.5.1 and earlier allows
23RISK
open ↗Referência
CVE-2011-2944
SQL injection vulnerability in login.php in MegaLab The Uploader before 2.0.5 allows remote attackers to execute arbitra
23RISK
open ↗Referência
CVE-2011-2944
SQL injection vulnerability in login.php in MegaLab The Uploader before 2.0.5 allows remote attackers to execute arbitra
23RISK
open ↗Referência
CVE-2007-3529
videos.php in PHPDirector 0.21 and earlier allows remote attackers to obtain sensitive information via an empty value of
23RISK
open ↗Referência
CVE-2018-12912
An issue wan discovered in admin\controllers\database.php in HongCMS 3.0.0. There is a SQL Injection vulnerability via a
23RISK
open ↗Referência✓ VexDay Proof
WTools 0.0.1a - 'INCLUDE_PATH' Remote File Inclusion
PHP remote file inclusion vulnerability in common.php in Thomas LETE WTools 0.0.1-ALPH allows remote attackers to execut
23RISK
open ↗Referência✓ VexDay Proof
HLStats 1.34 - 'hlstats.php' SQL Injection
HLstats 1.20 through 1.34 allows remote attackers to obtain sensitive information via playinfo mode, with certain values
23RISK
open ↗Referência✓ VexDay Proof
Poplar Gedcom Viewer 2.0 - 'common.php' Remote File Inclusion
PHP remote file inclusion vulnerability in include/common.php in Poplar Gedcom Viewer 2.0 and earlier allows remote atta
23RISK
open ↗Referência✓ VexDay Proof
Sinapis 2.2 Gastebuch - 'sinagb.php?fuss' Remote File Inclusion
PHP remote file inclusion vulnerability in sinagb.php in Sinapis Gastebuch 2.2 allows remote attackers to execute arbitr
23RISK
open ↗Referência✓ VexDay Proof
Pharmacy System 2.0 - 'index.php?ID' SQL Injection
index.php in Pharmacy System 2 and earlier allows remote attackers to obtain sensitive information via a ' (quote) chara
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.