Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,460Referência 22,910GitHub PoC 14,997VulnCheck XDB 8,843Nuclei 4,358Metasploit 3,489✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
Online Fantasy Football League (OFFL) 0.2.6 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Online Fantasy Football League (OFFL) 0.2.6 allow remote attackers
35RISK
open ↗Referência✓ VexDay Proof
Solaris 9 PortBind - XDR-DECODE 'taddr2uaddr()' Remote Denial of Service
The RPC subsystem in Sun Solaris 9 allows remote attackers to cause a denial of service (daemon crash) via a crafted req
28RISK
open ↗Referência✓ VexDay Proof
Citadel SMTP 7.10 - Remote Overflow
Buffer overflow in Citadel SMTP server 7.10 and earlier allows remote attackers to execute arbitrary code via a long RCP
28RISK
open ↗Referência✓ VexDay Proof
WordPress MU < 1.3.2 - 'active_plugins' Code Execution
wp-admin/options.php in WordPress MU before 1.3.2, and WordPress 2.3.2 and earlier, does not properly validate requests
28RISK
open ↗Referência✓ VexDay Proof
CF_Calendar - 'calendarevent.cfm' SQL Injection
SQL injection vulnerability in calendarevent.cfm in CF_Calendar allows remote attackers to execute arbitrary SQL command
23RISK
open ↗Referência✓ VexDay Proof
CF_Auction - Blind SQL Injection
SQL injection vulnerability in forummessages.cfm in CFMSource CF_Auction allows remote attackers to execute arbitrary SQ
23RISK
open ↗Referência✓ VexDay Proof
Hannon Hill Cascade Server - (Authenticated) Command Execution
Hannon Hill Cascade Server 5.7 and other versions allows remote authenticated users to execute arbitrary programs or Jav
28RISK
open ↗Referência✓ VexDay Proof
Microsoft Word 2007 - Multiple Vulnerabilities
Multiple unspecified vulnerabilities in Microsoft Word 2007 allow remote attackers to cause a denial of service (CPU con
28RISK
open ↗Referência✓ VexDay Proof
EDraw Office Viewer Component - Denial of Service
Buffer overflow in a certain ActiveX control in the EDraw Office Viewer Component (edrawofficeviewer.ocx) 4.0.5.20, and
28RISK
open ↗Referência✓ VexDay Proof
Joomla! Component Ynews 1.0.0 - 'id' SQL Injection
SQL injection vulnerability in index.php in the Ynews (com_ynews) 1.0.0 component for Joomla! allows remote attackers to
23RISK
open ↗Referência✓ VexDay Proof
AspWebCalendar 2008 - Arbitrary File Upload
Unrestricted file upload vulnerability in calendar_admin.asp in Full Revolution aspWebCalendar 2008 allows remote attack
28RISK
open ↗Referência✓ VexDay Proof
Pixaria Gallery 1.x - 'class.Smarty.php' Remote File Inclusion
PHP remote file inclusion vulnerability in resources/includes/class.Smarty.php in Pixaria Gallery before 1.4.3 allows re
28RISK
open ↗Referência✓ VexDay Proof
ProQuiz 1.0 - Authentication Bypass
SQL injection vulnerability in index.php in ProQuiz 1.0 allows remote attackers to execute arbitrary SQL commands via th
23RISK
open ↗Referência✓ VexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote attackers to obtain login access via a request to hosting/a
28RISK
open ↗Referência✓ VexDay Proof
Butterfly ORGanizer 2.0.1 - 'id' SQL Injection
SQL injection vulnerability in view.php in Butterfly Organizer 2.0.0 and 2.0.1 allows remote attackers to execute arbitr
23RISK
open ↗Referência✓ VexDay Proof
Backup Exec System Recovery Manager 7.0.1 - Arbitrary File Upload
Unrestricted file upload vulnerability in the FileUpload class running on the Symantec LiveState Apache Tomcat server, a
28RISK
open ↗Referência✓ VexDay Proof
Pre Job Board - Authentication Bypass
SQL injection vulnerability in Employee/login.asp in Pre ASP Job Board allows remote attackers to execute arbitrary SQL
23RISK
open ↗Referência✓ VexDay Proof
MyTopix 1.3.0 - SQL Injection
SQL injection vulnerability in index.php in MyTopix 1.3.0 and earlier allows remote authenticated users to execute arbit
23RISK
open ↗Referência✓ VexDay Proof
Simple Customer 1.2 - Authentication Bypass
SQL injection vulnerability in login.php in Simple Customer 1.2 allows remote attackers to execute arbitrary SQL command
23RISK
open ↗Referência✓ VexDay Proof
Apple QuickTime 7.5.5 / iTunes 8.0 - Remote Off-by-One Crash
Buffer overflow in Apple QuickTime 7.5.5 and iTunes 8.0 allows remote attackers to cause a denial of service (browser cr
28RISK
open ↗Referência✓ VexDay Proof
RSS Simple News - SQL Injection
SQL injection vulnerability in news.php in RSS Simple News (RSSSN), when magic_quotes_gpc is disabled, allows remote att
23RISK
open ↗Referência✓ VexDay Proof
Extract Website - 'Filename' File Disclosure
Directory traversal vulnerability in download.php in eMetrix Extract Website allows remote attackers to read arbitrary f
23RISK
open ↗Referência✓ VexDay Proof
MailBee WebMail Pro 4.1 - Remote File Disclosure
Directory traversal vulnerability in download_view_attachment.aspx in AfterLogic MailBee WebMail Pro 4.1 for ASP.NET all
28RISK
open ↗Referência✓ VexDay Proof
Online Keyword Research Tool - 'download.php' File Disclosure
Directory traversal vulnerability in download.php in eMetrix Online Keyword Research Tool allows remote attackers to rea
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component ProDesk 1.0/1.2 - Local File Inclusion
Directory traversal vulnerability in the Pro Desk Support Center (com_pro_desk) component 1.0 and 1.2 for Joomla! allows
43RISK
open ↗Referência✓ VexDay Proof
Corel Paint Shop Pro Photo 11.20 - '.clp' Local Buffer Overflow
Buffer overflow in igcore15d.dll 15.1.2.0 and 15.2.0.0 for AccuSoft ImageGear, as used in Corel Paint Shop Pro Photo 11.
28RISK
open ↗Referência✓ VexDay Proof
Text Lines Rearrange Script - 'Filename' File Disclosure
Directory traversal vulnerability in download.php in Text Lines Rearrange Script 1.0, when register_globals is enabled,
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component com_noticias 1.0 - SQL Injection
SQL injection vulnerability in index.php in the Noticias (com_noticias) 1.0 component for Joomla! allows remote attacker
23RISK
open ↗Referência✓ VexDay Proof
SolarCMS 0.53.8 - 'Forum' Remote Cookies Disclosure
SQL injection vulnerability in Forum.php in SolarCMS 0.53.8 and 1.0 allows remote attackers to execute arbitrary SQL com
23RISK
open ↗Referência✓ VexDay Proof
A-Blog 2.0 - Cross-Site Scripting / SQL Injection
SQL injection vulnerability in blog.php in A-Blog 2 allows remote attackers to execute arbitrary SQL commands via the id
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.