Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,107cataloged exploits
34,679CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,692GitHub PoC 13,812VulnCheck XDB 8,460Nuclei 4,233Metasploit 3,467✓ verified onlyrecentpopularrisk
21,692 exploits
Referência
CVE-2009-4989
Cross-site scripting (XSS) vulnerability in index.php in AJ Auction Pro OOPD 3.0 allows remote attackers to inject arbit
23RISK
open ↗Referência✓ VexDay Proof
WordPress Plugin myflash 1.00 - 'wppath' Remote File Inclusion
PHP remote file inclusion vulnerability in myflash-button.php in the myflash 1.00 and earlier plugin for WordPress allow
35RISK
open ↗Referência✓ VexDay Proof
PostNuke Module v4bJournal - SQL Injection
SQL injection vulnerability in index.php in the v4bJournal module for PostNuke allows remote authenticated users to exec
23RISK
open ↗Referência✓ VexDay Proof
Excel Viewer OCX 3.1.0.6 - Multiple Denial of Service Vulnerabilities
Multiple stack-based buffer overflows in the ExcelOCX ActiveX control in ExcelViewer.ocx 3.1.0.6 allow remote attackers
23RISK
open ↗Referência✓ VexDay Proof
1024 CMS 0.7 - 'download.php' Remote File Disclosure
Directory traversal vulnerability in includes/download.php in Treble Designs 1024 CMS 0.7 allows remote attackers to rea
23RISK
open ↗Referência✓ VexDay Proof
Berylium2 2003-08-18 - 'beryliumroot' Remote File Inclusion
PHP remote file inclusion vulnerability in berylium-classes.php in Berylium2 2003-08-18 allows remote attackers to execu
23RISK
open ↗Referência✓ VexDay Proof
workbench 0.11 - 'header.php?path' Remote File Inclusion
PHP remote file inclusion vulnerability in header.php in workbench survival guide 0.11 allows remote attackers to execut
23RISK
open ↗Referência✓ VexDay Proof
PHP TopTree BBS 2.0.1a - 'right_file' Remote File Inclusion
PHP remote file inclusion vulnerability in templates/default/tpl_message.php in PHP TopTree BBS 2.0.1a and earlier allow
23RISK
open ↗Referência
CVE-2007-2583
The in_decimal::set function in item_cmpfunc.cc in MySQL before 5.0.40, and 5.1 before 5.1.18-beta, allows context-depen
28RISK
open ↗Referência
CVE-2010-1952
Directory traversal vulnerability in the BeeHeard (com_beeheard) and BeeHeard Lite (com_beeheardlite) component 1.0 for
43RISK
open ↗Referência✓ VexDay Proof
aForum 1.32 - 'CommonAbsDir' Remote File Inclusion
PHP remote file inclusion vulnerability in common/func.php in aForum 1.32 and earlier allows remote attackers to execute
23RISK
open ↗Referência✓ VexDay Proof
telltarget 1.3.3 - 'tt_docroot' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in telltarget CMS 1.3.3 allow remote attackers to execute arbitrary P
28RISK
open ↗Referência✓ VexDay Proof
TutorialCMS 1.00 - 'search.php?search' SQL Injection
Multiple SQL injection vulnerabilities in TutorialCMS (aka Photoshop Tutorials) 1.00 and earlier allow remote attackers
23RISK
open ↗Referência✓ VexDay Proof
TutorialCMS 1.00 - 'search.php?search' SQL Injection
Multiple cross-site scripting (XSS) vulnerabilities in TutorialCMS (aka Photoshop Tutorials) 1.00 and earlier allow remo
23RISK
open ↗Referência✓ VexDay Proof
Miplex2 - 'SmartyFU.class.php' Remote File Inclusion
PHP remote file inclusion vulnerability in lib/smarty/SmartyFU.class.php in Miplex2 Alpha 1 allows remote attackers to e
23RISK
open ↗Referência✓ VexDay Proof
PHPLojaFacil 0.1.5 - 'path_local' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Crie seu PHPLojaFacil 0.1.5 allow remote attackers to execute arbi
23RISK
open ↗Referência
CVE-2009-5093
Directory traversal vulnerability in gastbuch.php in Gästebuch (Gastebuch) 1.6 allows remote attackers to read arbitrary
23RISK
open ↗Referência✓ VexDay Proof
Original 0.11 - 'config.inc.php?x[1]' Remote File Inclusion
PHP remote file inclusion vulnerability in inc/config.inc.php in Jakub Steiner (aka jimmac) original 0.11 allows remote
23RISK
open ↗Referência✓ VexDay Proof
NagiosQL 2005 2.00 - 'prepend_adm.php' Remote File Inclusion
PHP remote file inclusion vulnerability in functions/prepend_adm.php in NagiosQL 2005 2.00 allows remote attackers to ex
23RISK
open ↗Referência✓ VexDay Proof
Snaps! Gallery 1.4.4 - Remote User Pass Change
Admin/users.php in Snaps! Gallery 1.4.4 allows remote attackers to change arbitrary usernames and passwords via the (1)
28RISK
open ↗Referência✓ VexDay Proof
XOOPS Module resmanager 1.21 - Blind SQL Injection
SQL injection vulnerability in edit_day.php in the ResManager 1.2.1 and earlier module for Xoops allows remote attackers
23RISK
open ↗Referência✓ VexDay Proof
Achievo 1.1.0 - 'config_atkroot' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in Achievo 1.1.0 allows remote attackers to execute arbitrary PHP c
23RISK
open ↗Referência✓ VexDay Proof
FAQEngine 4.16.03 - 'question.php?questionref' SQL Injection
SQL injection vulnerability in question.php in FAQEngine 4.16.03 and earlier allows remote attackers to execute arbitrar
23RISK
open ↗Referência✓ VexDay Proof
PHPGlossar 0.8 - 'format_menue' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in PHPGlossar 0.8 allow remote attackers to execute arbitrary PHP cod
23RISK
open ↗Referência✓ VexDay Proof
CA BrightStor Backup 11.5.2.0 - 'caloggderd.exe' Denial of Service
(1) caloggerd.exe (camt70.dll) and (2) mediasvr.exe (catirpc.dll and rwxdr.dll) in CA BrightStor Backup 11.5.2.0 SP2 all
28RISK
open ↗Referência✓ VexDay Proof
CA BrightStor Backup 11.5.2.0 - 'Mediasvr.exe' Denial of Service
(1) caloggerd.exe (camt70.dll) and (2) mediasvr.exe (catirpc.dll and rwxdr.dll) in CA BrightStor Backup 11.5.2.0 SP2 all
28RISK
open ↗Referência✓ VexDay Proof
Alstrasoft Live Support 1.21 - Admin Credential Retrieve
AlstraSoft Live Support 1.21 sends a redirect to the web browser but does not exit when administrative credentials are m
23RISK
open ↗Referência✓ VexDay Proof
Alstrasoft Template Seller Pro 3.25 - Remote Code Execution
Unrestricted file upload vulnerability in admin/addsptemplate.php in AlstraSoft Template Seller Pro 3.25 and earlier all
23RISK
open ↗Referência✓ VexDay Proof
Libstats 1.0.3 - 'template_csv.php' Remote File Inclusion
PHP remote file inclusion vulnerability in template_csv.php in Libstats 1.0.3 and earlier allows remote attackers to exe
23RISK
open ↗Referência✓ VexDay Proof
LeadTools Thumbnail Browser Control - 'lttmb14E.ocx' Remote Buffer Overflow
Stack-based buffer overflow in the BrowseDir function in the (1) lttmb14E.ocx or (2) LTRTM14e.DLL ActiveX control in Lea
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.