Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,313cataloged exploits
34,834CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,797GitHub PoC 13,885VulnCheck XDB 8,484Nuclei 4,237Metasploit 3,467✓ verified onlyrecentpopularrisk
21,797 exploits
Referência✓ VexDay Proof
phpProfiles 3.1.2b - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in phpProfiles 3.1.2b and earlier allow remote attackers to execute a
23RISK
open ↗Referência✓ VexDay Proof
SCart 2.0 - 'page' Remote Code Execution
scart.cgi in SCart 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the page parame
23RISK
open ↗Referência✓ VexDay Proof
ViRC 2.0 - JOIN Response Remote Overwrite (SEH)
Stack-based buffer overflow in Visual IRC (ViRC) 2.0 allows remote IRC servers to execute arbitrary code via a long resp
23RISK
open ↗Referência✓ VexDay Proof
Web Wiz Rich Text Editor 4.0 - Multiple Vulnerabilities
Web Wiz RTE_file_browser.asp in, as used in Web Wiz Rich Text Editor 4.0, Web Wiz Forums 9.07, and Web Wiz Newspad 1.02,
23RISK
open ↗Referência✓ VexDay Proof
FAQ Manager 1.2 - 'header.php' Remote File Inclusion
PHP remote file inclusion vulnerability in include/header.php in Werner Hilversum FAQ Manager 1.2, when register_globals
23RISK
open ↗Referência
CVE-2016-9566
base/logging.c in Nagios Core before 4.2.4 allows local users with access to an account in the nagios group to gain root
23RISK
open ↗Referência
CVE-2018-7704
SecurEnvoy SecurMail before 9.2.501 allows remote authenticated users to read arbitrary e-mail messages via the option1
23RISK
open ↗Referência
CVE-2026-18645
danpros HTMLy Admin Content Endpoint admin.php add_content path traversal
30RISK
open ↗Referência
CVE-2026-18644
danpros HTMLy Delete Username Endpoint htmly.php unlink path traversal
30RISK
open ↗Referência
CVE-2026-18641
Sangfor Operation and Maintenance Security Management System Login Endpoint portal_login com.sbr.fort.foreignDP.DpLoginController os command injection
30RISK
open ↗Referência
CVE-2026-18632
langgenius dify Jinja2 jinja2_transformer.py jinja2.Template special elements used in a template engine
30RISK
open ↗Referência
CVE-2026-18631
jeequan jeepay PreAuthorize SysLogController.java WebSecurityConfig authorization
30RISK
open ↗Referência
CVE-2026-67599
ClearOS 7.9 OS Command Injection via Log Viewer filter parameter
38RISK
open ↗Referência
CVE-2026-18616
GL-iNet GL-MT3000 wg-server.so Native Plugin glc server.set_peer command injection
45RISK
open ↗Referência
CVE-2011-5148
Multiple incomplete blacklist vulnerabilities in the Simple File Upload (mod_simplefileuploadv1.3) module before 1.3.5 f
23RISK
open ↗Referência
CVE-2018-9128
DVD X Player Standard 5.5.3.9 has a Buffer Overflow via a crafted .plf file, a related issue to CVE-2007-3068.
23RISK
open ↗Referência
CVE-2018-9128
DVD X Player Standard 5.5.3.9 has a Buffer Overflow via a crafted .plf file, a related issue to CVE-2007-3068.
23RISK
open ↗Referência
CVE-2018-9128
DVD X Player Standard 5.5.3.9 has a Buffer Overflow via a crafted .plf file, a related issue to CVE-2007-3068.
23RISK
open ↗Referência
CVE-2009-3213
Stack-based buffer overflow in broid 1.0 Beta 3a allows remote attackers to cause a denial of service (application crash
23RISK
open ↗Referência
CVE-2013-2577
Buffer overflow in XnView before 2.04 allows remote attackers to execute arbitrary code via a crafted PCT file.
28RISK
open ↗Referência
CVE-2010-3591
Unspecified vulnerability in the Oracle Document Capture component in Oracle Fusion Middleware 10.1.3.4 and 10.1.3.5 all
28RISK
open ↗Referência
CVE-2019-8925
An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. An Absolute Path Traversal vulnerabi
28RISK
open ↗Referência
CVE-2019-8925
An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. An Absolute Path Traversal vulnerabi
28RISK
open ↗Referência✓ VexDay Proof
Mambo Component com_loudmouth 4.0j - Remote File Inclusion
PHP remote file inclusion vulnerability in includes/abbc/abbc.class.php in the LoudMouth Component for Mambo 4.0j, and p
23RISK
open ↗Referência
eBrigade ERP 4.5 - Arbitrary File Download
eBrigade through 4.5 allows Arbitrary File Download via ../ directory traversal in the showfile.php file parameter, as d
23RISK
open ↗Referência
CVE-2020-28413
In MantisBT 2.24.3, SQL Injection can occur in the parameter "access" of the mc_project_get_users function through the A
33RISK
open ↗Referência
CVE-2022-31325
There is a SQL Injection vulnerability in ChurchCRM 4.4.5 via the 'PersonID' field in /churchcrm/WhyCameEditor.php.
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.