Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,460Referência 22,832GitHub PoC 14,991VulnCheck XDB 8,829Nuclei 4,357Metasploit 3,489✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
Symantec BackupExec Calendar Control - 'PVCalendar.ocx' Remote Buffer Overflow
Multiple stack-based buffer overflows in the PVATLCalendar.PVCalendar.1 ActiveX control in pvcalendar.ocx in the schedul
50RISK
open ↗Referência✓ VexDay Proof
Maran PHP Shop - 'prodshow.php' SQL Injection
SQL injection vulnerability in prodshow.php in Maran PHP Shop allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗Referência✓ VexDay Proof
YourFreeWorld Reminder Service - SQL Injection
SQL injection vulnerability in tr.php in YourFreeWorld Reminder Service Script allows remote attackers to execute arbitr
23RISK
open ↗Referência✓ VexDay Proof
YourFreeWorld Blog Blaster - 'tr.php' SQL Injection
SQL injection vulnerability in tr.php in YourFreeWorld Blog Blaster Script allows remote attackers to execute arbitrary
23RISK
open ↗Referência✓ VexDay Proof
miniBloggie 1.0 - 'del.php' Arbitrary Delete Post
del.php in miniBloggie 1.0 allows remote attackers to delete arbitrary posts via a direct request with a modified post_i
23RISK
open ↗Referência✓ VexDay Proof
FreeBSD 6/8 - ata Device Local Denial of Service
The IATA (ata) driver in FreeBSD 6.0 and 8.0, when read access to /dev is available, allows local users to cause a denia
23RISK
open ↗Referência✓ VexDay Proof
YourFreeWorld Classifieds Hosting - SQL Injection
SQL injection vulnerability in tr.php in YourFreeWorld Classifieds Hosting Script allows remote attackers to execute arb
23RISK
open ↗Referência✓ VexDay Proof
YourFreeWorld Scrolling Text Ads - SQL Injection
SQL injection vulnerability in tr1.php in YourFreeWorld Scrolling Text Ads Script allows remote attackers to execute arb
23RISK
open ↗Referência✓ VexDay Proof
NetRisk 2.0 - Cross-Site Scripting / SQL Injection
SQL injection vulnerability in index.php in NetRisk 2.0 and earlier allows remote attackers to execute arbitrary SQL com
23RISK
open ↗Referência✓ VexDay Proof
NetRisk 2.0 - Cross-Site Scripting / SQL Injection
Cross-site scripting (XSS) vulnerability in error.php in NetRisk 2.0 and earlier allows remote attackers to inject arbit
23RISK
open ↗Referência✓ VexDay Proof
YourFreeWorld Downline Builder - 'tr.php' SQL Injection
SQL injection vulnerability in tr.php in YourFreeWorld Downline Builder allows remote attackers to execute arbitrary SQL
23RISK
open ↗Referência✓ VexDay Proof
SAPID CMF Build 87 - 'last_module' Remote Code Execution
Eval injection vulnerability in adodb-perf-module.inc.php in ADOdb Lite 1.42 and earlier, as used in products including
28RISK
open ↗Referência✓ VexDay Proof
Logz podcast CMS 1.3.1 - 'art' SQL Injection
SQL injection vulnerability in fichiers/add_url.php in Logz podcast CMS 1.3.1, when magic_quotes_gpc is disabled, allows
23RISK
open ↗Referência✓ VexDay Proof
YourFreeWorld Classifieds Blaster - SQL Injection
SQL injection vulnerability in tr.php in YourFreeWorld Classifieds Blaster Script allows remote attackers to execute arb
23RISK
open ↗Referência✓ VexDay Proof
SFS EZ Gaming Directory - 'directory.php' SQL Injection
SQL injection vulnerability in directory.php in Sites for Scripts (SFS) Gaming Directory allows remote attackers to exec
23RISK
open ↗Referência✓ VexDay Proof
Article Publisher PRO 1.5 - Authentication Bypass
SQL injection vulnerability in admin/admin.php in Article Publisher Pro 1.5 allows remote attackers to execute arbitrary
23RISK
open ↗Referência✓ VexDay Proof
Xitami Web Server 2.5 - 'If-Modified-Since' Remote Buffer Overflow
Multiple buffer overflows in iMatix Xitami Web Server 2.5c2 allow remote attackers to execute arbitrary code via a long
60RISK
open ↗Referência✓ VexDay Proof
Article Publisher PRO - 'userid' SQL Injection
SQL injection vulnerability in contact_author.php in Article Publisher Pro 1.5 allows remote attackers to execute arbitr
23RISK
open ↗Referência✓ VexDay Proof
Bitweaver 2.6 - 'saveFeed()' Remote Code Execution
The smarty_function_math function in libs/plugins/function.math.php in Smarty 2.6.22 allows context-dependent attackers
28RISK
open ↗Referência✓ VexDay Proof
RX Maxsoft - 'fotoID' SQL Injection
SQL injection vulnerability in popup_img.php in the fotogalerie module in RS MAXSOFT allows remote attackers to execute
23RISK
open ↗Referência✓ VexDay Proof
Visagesoft eXPert PDF ViewerX - 'VSPDFViewerX.ocx' File Overwrite
Insecure method vulnerability in VISAGESOFT eXPert PDF Viewer X ActiveX control (VSPDFViewerX.ocx) 3.0.990.0 allows remo
23RISK
open ↗Referência✓ VexDay Proof
helplink 0.1.0 - 'show.php' Remote File Inclusion
PHP remote file inclusion vulnerability in show.php in David Watters Helplink 0.1.0 allows remote attackers to execute a
35RISK
open ↗Referência✓ VexDay Proof
MindDezign Photo Gallery 2.2 - Arbitrary Add Admin
SQL injection vulnerability in MindDezign Photo Gallery 2.2 allows remote attackers to execute arbitrary SQL commands vi
23RISK
open ↗Referência✓ VexDay Proof
DjVu - ActiveX Control 3.0 ImageURL Property Overflow
Buffer overflow in the DjVu ActiveX Control 3.0 for Microsoft Office (DjVu_ActiveX_MSOffice.dll) allows remote attackers
50RISK
open ↗Referência✓ VexDay Proof
MW6 Aztec - ActiveX 'Aztec.dll' Remote Insecure Method
Multiple insecure method vulnerabilities in MW6 Technologies Aztec ActiveX control (AZTECLib.MW6Aztec, Aztec.dll) 3.0.0.
23RISK
open ↗Referência✓ VexDay Proof
Softbiz Classifieds PLUS - 'id' SQL Injection
SQL injection vulnerability in store_info.php in SoftBiz Classifieds PLUS allows remote attackers to execute arbitrary S
23RISK
open ↗Referência✓ VexDay Proof
MW6 Barcode - ActiveX 'Barcode.dll' Insecure Method
Multiple insecure method vulnerabilities in MW6 Technologies 1D Barcode ActiveX control (BARCODELib.MW6Barcode, Barcode.
23RISK
open ↗Referência✓ VexDay Proof
MW6 PDF417 - ActiveX 'MW6PDF417.dll' Remote Insecure Method
Multiple insecure method vulnerabilities in MW6 Technologies PDF417 ActiveX control (MW6PDF417Lib.PDF417, MW6PDF417.dll)
23RISK
open ↗Referência✓ VexDay Proof
U-Mail Webmail 4.91 - 'edit.php' Arbitrary File Write
webmail/modules/filesystem/edit.php in U-Mail Webmail server 4.91 allows remote attackers to overwrite arbitrary files v
23RISK
open ↗Referência✓ VexDay Proof
PHPX 3.5.16 - 'news_id' SQL Injection
SQL injection vulnerability in admin/includes/news.inc.php in PHPX 3.5.16, when magic_quotes_gpc is disabled, allows rem
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.