Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,647cataloged exploits
34,986CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,899GitHub PoC 14,014VulnCheck XDB 8,571Nuclei 4,248Metasploit 3,472✓ verified onlyrecentpopularrisk
21,899 exploits
Referência✓ VexDay Proof
Hacks List phpBB Mod 1.21 - SQL Injection
SQL injection vulnerability in admin_hacks_list.php in the Nivisec Hacks List 1.21 and earlier phpBB module allows remot
23RISK
open ↗Referência✓ VexDay Proof
Recipes Complete Website 1.1.14 - SQL Injection
Multiple SQL injection vulnerabilities in Recipes Website (Recipes Complete Website) 1.1.14 allow remote attackers to ex
23RISK
open ↗Referência✓ VexDay Proof
GeekLog 1.4.0sr3 - '_CONF[path]' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in GeekLog 1.4 allow remote attackers to execute arbitrary code via a
23RISK
open ↗Referência✓ VexDay Proof
S9Y Serendipity 1.0.3 - 'comment.php' Local File Inclusion
Multiple directory traversal vulnerabilities in Serendipity 1.0.3 and earlier allow remote attackers to read or include
23RISK
open ↗Referência✓ VexDay Proof
Songbird Media Player 0.2 - Format String Denial of Service (PoC)
Format string vulnerability in Songbird Media Player 0.2 and earlier allows remote attackers to cause a denial of servic
23RISK
open ↗Referência✓ VexDay Proof
VUPlayer 2.44 - '.m3u' UNC Name Buffer Overflow (Metasploit)
Stack-based buffer overflow in VUPlayer 2.44 and earlier allows remote attackers to execute arbitrary code via a long st
50RISK
open ↗Referência✓ VexDay Proof
Quintessential Player 4.50.1.82 - Playlist Denial of Service (PoC)
Buffer overflow in Quintessential Player 4.50.1.82 and earlier allows remote attackers to cause a denial of service (cra
23RISK
open ↗Referência✓ VexDay Proof
CoolPlayer 2.17 - '.m3u' Local Stack Overflow
Multiple buffer overflows in Niek Albers CoolPlayer 216 and earlier allow remote attackers to execute arbitrary code via
23RISK
open ↗Referência✓ VexDay Proof
F-Prot AntiVirus 4.6.6 - CHM Heap Overflow (PoC)
Heap-based buffer overflow in FRISK Software F-Prot Antivirus before 4.6.7 allows user-assisted remote attackers to exec
28RISK
open ↗Referência✓ VexDay Proof
mxBB Module kb_mods 2.0.2 - Remote File Inclusion
Directory traversal vulnerability in includes/kb_constants.php in the Knowledge Base (mx_kb) 2.0.2 module for mxBB allow
23RISK
open ↗Referência
CVE-2009-4721
Multiple SQL injection vulnerabilities in Admin/index.asp in Andrews-Web (A-W) BannerAd 1.0 allow remote attackers to ex
23RISK
open ↗Referência✓ VexDay Proof
yaplap 0.6.1b - 'ldap.php' Remote File Inclusion
PHP remote file inclusion vulnerability in ldap.php in Brian Drawert Yet Another PHP LDAP Admin Project (yaplap) 0.6 and
23RISK
open ↗Referência
CVE-2006-6576
Heap-based buffer overflow in Golden FTP Server (goldenftpd) 1.92 allows remote attackers to cause a denial of service (
50RISK
open ↗Referência✓ VexDay Proof
vBlog / C12 0.1 - 'cfgProgDir' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Vortex Blog (vBlog, aka C12) a0.1_nonfunc allow remote attackers t
23RISK
open ↗Referência✓ VexDay Proof
AR Memberscript - 'usercp_menu.php' Remote File Inclusion
PHP remote file inclusion vulnerability in usercp_menu.php in AR Memberscript allows remote attackers to execute arbitra
23RISK
open ↗Referência✓ VexDay Proof
TorrentFlux 2.2 - 'downloaddetails.php' Local File Disclosure
Directory traversal vulnerability in downloaddetails.php in TorrentFlux 2.2 allows remote authenticated users to read ar
23RISK
open ↗Referência✓ VexDay Proof
PHPMyCMS 0.3 - 'basic.inc.php' Remote File Inclusion
PHP remote file inclusion vulnerability in basic.inc.php in PhpMyCms 0.3 allows remote attackers to execute arbitrary PH
23RISK
open ↗Referência
CVE-2009-4725
Directory traversal vulnerability in modules/aljazeera/admin/setup.php in Arab Portal 2.2 and earlier, when register_glo
23RISK
open ↗Referência✓ VexDay Proof
mxBB Module Activity Games 0.92 - Remote File Inclusion
PHP remote file inclusion vulnerability in includes/act_constants.php in the Activity Games (mx_act) 0.92 module for mxB
23RISK
open ↗Referência✓ VexDay Proof
Sambar FTP Server 6.4 - 'SIZE' Remote Denial of Service
The FTP Server in Sambar Server 6.4 allows remote authenticated users to cause a denial of service (application crash) v
23RISK
open ↗Referência✓ VexDay Proof
Genepi 1.6 - 'genepi.php' Remote File Inclusion
PHP remote file inclusion vulnerability in genepi.php in Genepi 1.6 and earlier allows remote attackers to execute arbit
23RISK
open ↗Referência✓ VexDay Proof
JumbaCMS 0.0.1 - '/includes/functions.php' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/functions.php in JumbaCMS 0.0.1 allows remote attackers to execute a
23RISK
open ↗Referência✓ VexDay Proof
mxBB Module Meeting 1.1.2 - Remote File Inclusion
PHP remote file inclusion vulnerability in pages/meeting_constants.php in the Meeting (mx_meeting) 1.1.2 and earlier mod
23RISK
open ↗Referência
CVE-2015-7297
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via un
60RISK
open ↗Referência
CVE-2020-0688
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open ↗Referência
CVE-2020-0688
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open ↗Referência
CVE-2026-9583
SourceCodester CET Automated Grading System with AI Predictive Analytics SQL index.php information exposure
33RISK
open ↗Referência
CVE-2026-9582
SourceCodester CET Automated Grading System with AI Predictive Analytics cross-site request forgery
33RISK
open ↗Referência
CVE-2026-9582
SourceCodester CET Automated Grading System with AI Predictive Analytics cross-site request forgery
33RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.