Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,460Referência 22,910GitHub PoC 14,997VulnCheck XDB 8,843Nuclei 4,358Metasploit 3,489✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
RhinoSoft Serv-U FTP Server 7.3 - (Authenticated) 'stou con:1' Denial of Service
Serv-U 7.0.0.1 through 7.3, including 7.2.0.1, allows remote authenticated users to cause a denial of service (CPU consu
28RISK
open ↗Referência✓ VexDay Proof
jPORTAL 2 - 'humor.php' SQL Injection
SQL injection vulnerability in humor.php in jPORTAL 2 allows remote attackers to execute arbitrary SQL commands via the
23RISK
open ↗Referência✓ VexDay Proof
Winamp 5.34 - '.mp4' Code Execution
libmp4v2.dll in Winamp 5.02 through 5.34 allows user-assisted remote attackers to execute arbitrary code via a certain .
28RISK
open ↗Referência✓ VexDay Proof
Oceandir 2.9 - 'show_vote.php' SQL Injection
SQL injection vulnerability in show_vote.php in Oceandir 2.9 and earlier allows remote attackers to execute arbitrary SQ
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component pcchess 0.8 - SQL Injection
SQL injection vulnerability in index.php in the Prince Clan Chess Club (com_pcchess) 0.8 and earlier component for Jooml
23RISK
open ↗Referência✓ VexDay Proof
Diesel Pay Script - 'area' SQL Injection
SQL injection vulnerability in index.php in Diesel Pay allows remote attackers to execute arbitrary SQL commands via the
23RISK
open ↗Referência✓ VexDay Proof
Plaincart 1.1.2 - 'p' SQL Injection
SQL injection vulnerability in index.php in PlainCart 1.1.2 allows remote attackers to execute arbitrary SQL commands vi
23RISK
open ↗Referência✓ VexDay Proof
Sun Board 1.00.00 alpha - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Sun Board 1.00.00 Alpha allow remote attackers to execute arbitrar
45RISK
open ↗Referência✓ VexDay Proof
easyLink 1.1.0 - 'detail.php' SQL Injection
SQL injection vulnerability in detail.php in MountainGrafix easyLink 1.1.0 allows remote attackers to execute arbitrary
23RISK
open ↗Referência✓ VexDay Proof
Mumbo Jumbo Media OP4 - Blind SQL Injection
SQL injection vulnerability in Mumbo Jumbo Media OP4 allows remote attackers to execute arbitrary SQL commands via the i
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component versioning 1.0.2 - 'id' SQL Injection
SQL injection vulnerability in the Versioning component (com_versioning) 1.0.2 in Joomla! and Mambo allows remote attack
23RISK
open ↗Referência✓ VexDay Proof
Microsoft Internet Explorer 6 / Provideo Camimage - 'ISSCamControl.dll 1.0.1.5' Remote Buffer Overflow
Buffer overflow in the Provideo Camimage ActiveX control in ISSCamControl.dll 1.0.1.5, when Internet Explorer 6 is used
35RISK
open ↗Referência✓ VexDay Proof
Joomla! Component Flash Tree Gallery 1.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in admin.treeg.php in the Flash Tree Gallery (com_treeg) component 1.0 for Jooml
28RISK
open ↗Referência✓ VexDay Proof
Joomla! Component VirtueMart Google Base 1.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in admin.googlebase.php in the Ecom Solutions VirtueMart Google Base (aka com_go
28RISK
open ↗Referência✓ VexDay Proof
Mole Group Taxi Calc Dist Script - Authentication Bypass
SQL injection vulnerability in login.php in Mole Group Taxi Map Script (aka Taxi Calc Dist Script) allows remote attacke
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component com_galeria - SQL Injection
SQL injection vulnerability in index.php in the com_galeria component for Joomla! allows remote attackers to execute arb
23RISK
open ↗Referência✓ VexDay Proof
XOOPS Module myTopics - 'articleId' SQL Injection
SQL injection vulnerability in print.php in the myTopics module for XOOPS allows remote attackers to execute arbitrary S
23RISK
open ↗Referência✓ VexDay Proof
SoftComplex PHP Image Gallery 1.0 - Authentication Bypass
SQL injection vulnerability in index.php in SoftComplex PHP Image Gallery 1.0 allows remote attackers to execute arbitra
23RISK
open ↗Referência✓ VexDay Proof
FLABER 1.1 RC1 - Remote Command Execution
function/update_xml.php in FLABER 1.1 and earlier allows remote attackers to overwrite arbitrary files by specifying the
23RISK
open ↗Referência✓ VexDay Proof
Easy News Content Management - Database Disclosure
Easy Content Management Publishing stores sensitive information under the web root with insufficient access control, whi
23RISK
open ↗Referência✓ VexDay Proof
ASP User Engine .NET - Remote Database Disclosure
ASP User Engine.NET stores sensitive information under the web root with insufficient access control, which allows remot
23RISK
open ↗Referência✓ VexDay Proof
Pro Chat Rooms 3.0.2 - Cross-Site Scripting / Cross-Site Request Forgery
Directory traversal vulnerability in Pro Chat Rooms 3.0.2 allows remote authenticated users to select an arbitrary local
23RISK
open ↗Referência✓ VexDay Proof
Openfire Server 3.6.0a - Authentication Bypass / SQL Injection / Cross-Site Scripting
Directory traversal vulnerability in the AuthCheck filter in the Admin Console in Openfire 3.6.0a and earlier allows rem
60RISK
open ↗Referência✓ VexDay Proof
Openfire Server 3.6.0a - Authentication Bypass / SQL Injection / Cross-Site Scripting
Open redirect vulnerability in login.jsp in Openfire 3.6.0a and earlier allows remote attackers to redirect users to arb
23RISK
open ↗Referência✓ VexDay Proof
NCTAudioEditor2 ActiveX DLL 'NCTWMAFile2.dll 2.6.2.157' - File Write
The NCTAudioEditor2 ActiveX control in NCTWMAFile2.dll 2.6.2.157, as distributed in NCTAudioEditor and NCTAudioStudio 2.
23RISK
open ↗Referência✓ VexDay Proof
Andy's PHP KnowledgeBase 0.92.9 - Arbitrary File Upload
Unrestricted file upload vulnerability in saa.php in Andy's PHP Knowledgebase (aphpkb) 0.92.9 allows remote attackers to
23RISK
open ↗Referência✓ VexDay Proof
b1gbb 2.24.0 - 'footer.inc.php?tfooter' Remote File Inclusion
PHP remote file inclusion vulnerability in footer.inc.php in B1G b1gBB 2.24 allows remote attackers to execute arbitrary
45RISK
open ↗Referência✓ VexDay Proof
VidiScript (Avatar) - Arbitrary File Upload
Unrestricted file upload vulnerability in the profile feature in VidiScript allows registered remote authenticated users
23RISK
open ↗Referência✓ VexDay Proof
Really Simple PHP and Ajax (RSPA) 2007-03-23 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Really Simple PHP and Ajax (RSPA) 2007-03-23 and earlier allow rem
23RISK
open ↗Referência✓ VexDay Proof
OpenInvoice 0.9 - Arbitrary Change User Password
auth.php in openInvoice 0.90 beta and earlier allows remote attackers to bypass authentication and gain privileges by se
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.