Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,559cataloged exploits
34,978CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,899GitHub PoC 13,960VulnCheck XDB 8,542Nuclei 4,243Metasploit 3,472✓ verified onlyrecentpopularrisk
21,899 exploits
Referência✓ VexDay Proof
Microsoft Internet Explorer 6 - DirectX Media Remote Overflow Denial of Service
Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (crash) via a long Color attrib
35RISK
open ↗Referência✓ VexDay Proof
OpenSSL < 0.9.7l/0.9.8d - SSLv2 Client Crash
The get_server_hello function in the SSLv2 client code in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier
28RISK
open ↗Referência✓ VexDay Proof
Joomla! Component Kochsuite 0.9.4 - Remote File Inclusion
PHP remote file inclusion vulnerability in config.kochsuite.php in the Kochsuite (com_kochsuite) 0.9.4 component for Mam
23RISK
open ↗Referência
CVE-2009-4561
Multiple SQL injection vulnerabilities in Admin/index.php in WebLeague 2.2.0, when magic_quotes_gpc is disabled, allow r
23RISK
open ↗Referência✓ VexDay Proof
Empire CMS 3.7 - 'checklevel.php' Remote File Inclusion
PHP remote file inclusion vulnerability in e/class/CheckLevel.php in Phome Empire CMS 3.7 and earlier allows remote atta
23RISK
open ↗Referência✓ VexDay Proof
Integramod Portal 2.x - 'functions_portal.php' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/functions_portal.php in IntegraMOD Portal 2.x and earlier allows rem
23RISK
open ↗Referência✓ VexDay Proof
Integramod Portal 2.x - 'functions_portal.php' Remote File Inclusion
Absolute path traversal vulnerability in includes/functions_portal.php in IntegraMOD Portal 2.x and earlier, when magic_
23RISK
open ↗Referência✓ VexDay Proof
pSlash 0.7 - 'lvc_include_dir' Remote File Inclusion
PHP remote file inclusion vulnerability in modules/visitors2/include/config.inc.php in pSlash 0.70 allows remote attacke
23RISK
open ↗Referência✓ VexDay Proof
PHPCOIN 1.2.3 - 'session_set.php' Remote File Inclusion
PHP remote file inclusion vulnerability in coin_includes/constants.php in phpCOIN 1.2.3 allows remote attackers to execu
23RISK
open ↗Referência✓ VexDay Proof
eFiction < 2.0.7 - Remote Admin Authentication Bypass
index.php in eFiction before 2.0.7 allows remote attackers to bypass authentication and gain privileges by setting the (
23RISK
open ↗Referência✓ VexDay Proof
Ay System CMS 2.6 - 'main.php' Remote File Inclusion
PHP remote file inclusion vulnerability in main.php in Ay System Solutions CMS 2.6 and earlier allows remote attackers t
23RISK
open ↗Referência✓ VexDay Proof
Interact 2.2 - 'CONFIG[base_path]' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in interact 2.2, when register_globals is enabled, allow remote attac
23RISK
open ↗Referência✓ VexDay Proof
XChat 2.6.7 (Windows) - Remote Denial of Service
Unspecified vulnerability in Xchat 2.6.7 and earlier allows remote attackers to cause a denial of service (crash) via un
23RISK
open ↗Referência✓ VexDay Proof
openmovieeditor 0.0.20060901 - 'name' Local Buffer Overflow
Buffer overflow in Open Movie Editor 0.0.20060901 allows local users to cause a denial of service (system crash) or exec
23RISK
open ↗Referência
CVE-2009-4578
Cross-site scripting (XSS) vulnerability in the Facileforms (com_facileforms) component for Joomla! and Mambo allows rem
23RISK
open ↗Referência✓ VexDay Proof
TualBLOG 1.0 - 'icerikno' SQL Injection
Multiple SQL injection vulnerabilities in icerik.asp in TualBLOG 1.0 allow remote attackers to execute arbitrary SQL com
23RISK
open ↗Referência
CVE-2026-12183
Nefteprodukttekhnika BUK TS-G Gas Station Automation System Authentication Bypass via ajax-login.php Accepting Arbitrary Credentials
48RISK
open ↗Referência
CVE-2026-9062
Agile Store Locator < 1.6.9 - Admin+ Arbitrary File Read via Path Traversal
28RISK
open ↗Referência
CVE-2026-12066
PbootCMS Password MemberController.php retrieve password recovery
33RISK
open ↗Referência
CVE-2026-12065
Groww Stock, Mutual Fund, Gold App WebView URL improper authorization in handler for custom url scheme
28RISK
open ↗Referência
CVE-2026-12065
Groww Stock, Mutual Fund, Gold App WebView URL improper authorization in handler for custom url scheme
28RISK
open ↗Referência
CVE-2026-8589
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
41RISK
open ↗Referência
CVE-2026-20253
Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprise
100RISK
open ↗Referência
CVE-2026-25860
OpenClinic GA 5.351.19 Reflected XSS via DICOM Image Upload Handler
33RISK
open ↗Referência
CVE-2026-25860 POC git
OpenClinic GA 5.351.19 Reflected XSS via DICOM Image Upload Handler
33RISK
open ↗Referência
CVE-2026-34417
OSCAL-GUI Reflected XSS via project parameter in oscal-forms.php
33RISK
open ↗Referência
CVE-2025-55651
A NULL pointer dereference in the gf_isom_get_user_data_count function (isomedia/isom_read.c) of GPAC MP4Box v2.4 allows
33RISK
open ↗Referência
CVE-2026-11582
CodeAstro Student Attendance Management System index.php sql injection
33RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.