Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,607cataloged exploits
34,986CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,899GitHub PoC 13,974VulnCheck XDB 8,571Nuclei 4,248Metasploit 3,472✓ verified onlyrecentpopularrisk
21,899 exploits
Referência✓ VexDay Proof
VideoLAN VLC Media Player 0.8.6e - Subtitle Parsing Local Buffer Overflow
Stack-based buffer overflow in the ParseSSA function (modules/demux/subtitle.c) in VLC 0.8.6e allows remote attackers to
28RISK
open ↗Referência✓ VexDay Proof
CDNetworks Nefficient Download - 'NeffyLauncher.dll' Code Execution
Directory traversal vulnerability in the NeffyLauncher 1.0.5 ActiveX control (NeffyLauncher.dll) in CDNetworks Nefficien
23RISK
open ↗Referência✓ VexDay Proof
XplodPHP AutoTutorials 2.1 - 'id' SQL Injection
SQL injection vulnerability in viewcat.php in XplodPHP AutoTutorials 2.1 and earlier, when magic_quotes_gpc is disabled,
23RISK
open ↗Referência✓ VexDay Proof
DivX Player 6.7.0 - '.srt' File Buffer Overflow (PoC)
Stack-based buffer overflow in DivX Player 6.7 build 6.7.0.22 and earlier allows user-assisted remote attackers to cause
28RISK
open ↗Referência✓ VexDay Proof
LaserNet CMS 1.5 - SQL Injection
SQL injection vulnerability in index.php in Lasernet CMS 1.5 and 1.11, when magic_quotes_gpc is disabled, allows remote
23RISK
open ↗Referência✓ VexDay Proof
BigAnt Server 2.2 - Remote Overflow (SEH)
Stack-based buffer overflow in the AntServer module (AntServer.exe) in BigAnt IM Server in BigAnt Messenger 2.2 allows r
60RISK
open ↗Referência✓ VexDay Proof
BlogWorx 1.0 - 'id' SQL Injection
SQL injection vulnerability in view.asp in DevWorx BlogWorx 1.0 allows remote attackers to execute arbitrary SQL command
23RISK
open ↗Referência✓ VexDay Proof
PHP-Fusion 7.0.2 - Blind SQL Injection
SQL injection vulnerability in submit.php in PHP-Fusion 6.01.14 and 6.00.307, when magic_quotes_gpc is disabled and the
23RISK
open ↗Referência✓ VexDay Proof
5th Avenue Shopping Cart - 'category_id' SQL Injection
SQL injection vulnerability in store_pages/category_list.php in 5th Avenue Shopping Cart 1.2 trial edition allows remote
23RISK
open ↗Referência✓ VexDay Proof
Crazy Goomba 1.2.1 - 'id' SQL Injection
SQL injection vulnerability in commentaires.php in Crazy Goomba 1.2.1 allows remote attackers to execute arbitrary SQL c
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component Filiale 1.0.4 - 'idFiliale' SQL Injection
SQL injection vulnerability in the Filiale 1.0.4 component for Joomla! allows remote attackers to execute arbitrary SQL
23RISK
open ↗Referência✓ VexDay Proof
Classifieds Caffe - 'cat_id' SQL Injection
SQL injection vulnerability in index.php in Classifieds Caffe allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗Referência✓ VexDay Proof
W1L3D4 philboard 1.0 - 'philboard_reply.asp' SQL Injection
Multiple SQL injection vulnerabilities in W1L3D4 Philboard 1.0 allow remote attackers to execute arbitrary SQL commands
23RISK
open ↗Referência✓ VexDay Proof
AllMyGuests 0.4.1 - 'AMG_id' SQL Injection
SQL injection vulnerability in index.php in Voice Of Web AllMyGuests 0.4.1 allows remote attackers to execute arbitrary
23RISK
open ↗Referência✓ VexDay Proof
E RESERV 2.1 - 'index.php' SQL Injection
SQL injection vulnerability in index.php in E-RESERV 2.1 allows remote attackers to execute arbitrary SQL commands via t
23RISK
open ↗Referência✓ VexDay Proof
Acidcat CMS 3.4.1 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in Acidcat CMS 3.4.1 allow remote attackers to execute arbitrary SQL commands via
23RISK
open ↗Referência✓ VexDay Proof
WonderWare SuiteLink 2.0 - Remote Denial of Service (Metasploit)
The SuiteLink Service (aka slssvc.exe) in WonderWare SuiteLink before 2.0 Patch 01, as used in WonderWare InTouch 8.0, a
28RISK
open ↗Referência
CVE-2014-6242
Multiple SQL injection vulnerabilities in the All In One WP Security & Firewall plugin before 3.8.3 for WordPress allow
23RISK
open ↗Referência
CVE-2014-6242
Multiple SQL injection vulnerabilities in the All In One WP Security & Firewall plugin before 3.8.3 for WordPress allow
23RISK
open ↗Referência
CVE-2022-0847
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open ↗Referência
CVE-2015-4066
Multiple SQL injection vulnerabilities in admin/handlers.php in the GigPress plugin before 2.3.9 for WordPress allow rem
23RISK
open ↗Referência
CVE-2015-4066
Multiple SQL injection vulnerabilities in admin/handlers.php in the GigPress plugin before 2.3.9 for WordPress allow rem
23RISK
open ↗Referência
CVE-2022-0847
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open ↗Referência
CVE-2016-6707
An elevation of privilege vulnerability in System Server in Android 6.x before 2016-11-01 and 7.0 before 2016-11-01 coul
23RISK
open ↗Referência
CVE-2026-13389
WebToffee Cookie Consent < 3.5.3 - Consent Log Disclosure/Deletion, Page Creation & License Deactivation via Unprotected REST Routes
33RISK
open ↗Referência
CVE-2014-2023
Multiple SQL injection vulnerabilities in the Tapatalk plugin 4.9.0 and earlier and 5.x through 5.2.1 for vBulletin allo
23RISK
open ↗Referência✓ VexDay Proof
Studio Lounge Address Book 2.5 - 'profile' Arbitrary File Upload
Unrestricted file upload vulnerability in upload-file.php in Adam Patterson Studio Lounge Address Book 2.5, as reachable
23RISK
open ↗Referência
CVE-2025-15675
Charitable < 1.8.5.3 - Admin+ Stored XSS via Photo Field ALT Text
33RISK
open ↗Referência
CVE-2016-7216
The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 mishandles permissi
23RISK
open ↗Referência
CVE-2019-0836
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), ak
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.