Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,401cataloged exploits
35,511CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,332GitHub PoC 14,209VulnCheck XDB 8,646Nuclei 4,289Metasploit 3,474✓ verified onlyrecentpopularrisk
22,301 exploits
Referência✓ VexDay Proof
Fastpublish CMS 1.6.9 - config[fsBase] Remote File Inclusion
PHP remote file inclusion vulnerability in Fastpublish CMS 1.6.9.d allows remote attackers to include arbitrary files vi
28RISK
open ↗Referência✓ VexDay Proof
Informium 0.12.0 - 'common-menu.php' Remote File Inclusion
PHP remote file inclusion vulnerability in common-menu.php in Cameron McKay Informium 0.12.0 allows remote attackers to
23RISK
open ↗Referência✓ VexDay Proof
Redaxo 3.2 - 'INCLUDE_PATH' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Redaxo 3.0 allow remote attackers to execute arbitrary PHP code vi
23RISK
open ↗Referência✓ VexDay Proof
Wikiwig 4.1 - 'wk_lang.php' Remote File Inclusion
PHP remote file inclusion vulnerability in _wk/wk_lang.php in Wikiwig 4.1 and earlier allows remote attackers to execute
23RISK
open ↗Referência
CVE-2026-23760
SmarterTools SmarterMail < Build 9511 Authentication Bypass via Password Reset API
100RISK
open ↗Referência
CVE-2023-6553
Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
85RISK
open ↗Referência
glibc 2.38 - Buffer Overflow
Glibc: buffer overflow in ld.so leading to privilege escalation
100RISK
open ↗Referência✓ VexDay Proof
Linux Kernel 2.6.x - 'sys_timer_create()' Local Denial of Service
The sys_timer_create function in posix-timers.c for Linux kernel 2.6.x allows local users to cause a denial of service (
23RISK
open ↗Referência
CVE-2019-10068
An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions
100RISK
open ↗Referência
CVE-2026-7228
SourceCodester Pizzafy Ecommerce System ajax.php get_cart_count sql injection
33RISK
open ↗Referência✓ VexDay Proof
PHPWind 5.0.1 - 'AdminUser' Blind SQL Injection
SQL injection vulnerability in admin.php in PHPWind 5.0.1 and earlier allows remote attackers to execute arbitrary SQL c
23RISK
open ↗Referência
CVE-2012-1125
Unrestricted file upload vulnerability in uploadify/scripts/uploadify.php in the Kish Guest Posting plugin before 1.2 fo
28RISK
open ↗Referência✓ VexDay Proof
Power Phlogger 2.0.9 - 'config.inc.php3' File Inclusion
PHP remote file inclusion vulnerability in config.inc.php3 in Power Phlogger 2.0.9 and earlier allows remote attackers t
23RISK
open ↗Referência✓ VexDay Proof
FreePBX 2.1.3 - 'upgrade.php' Remote File Inclusion
PHP remote file inclusion vulnerability in upgrade.php in Coalescent Systems freePBX 2.1.3 allows remote attackers to ex
23RISK
open ↗Referência
CVE-2020-17530
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISK
open ↗Referência✓ VexDay Proof
PHP-Stats 0.1.9.1b - 'ip' SQL Injection
Multiple SQL injection vulnerabilities in php-stats.recphp.php in PHP-Stats 0.1.9.1b and earlier allow remote attackers
23RISK
open ↗Referência✓ VexDay Proof
PHP-Stats 0.1.9.1b - 'PC-REMOTE-ADDR' SQL Injection
Multiple SQL injection vulnerabilities in php-stats.recphp.php in PHP-Stats 0.1.9.1b and earlier allow remote attackers
23RISK
open ↗Referência
CVE-2020-24186
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allo
85RISK
open ↗Referência
CVE-2020-24186
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allo
85RISK
open ↗Referência✓ VexDay Proof
phpBP RC3 (2.204) - SQL Injection / Remote Code Execution
SQL injection vulnerability in phpBP RC3 (2.204) and earlier allows remote attackers to execute arbitrary SQL commands v
23RISK
open ↗Referência✓ VexDay Proof
BrowseDialog Class 'ccrpbds6.dll' Internet Explorer 7 - Denial of Service
A certain ActiveX control in the Common Controls Replacement Project (CCRP) CCRP BrowseDialog Server (ccrpbds6.dll) allo
23RISK
open ↗Referência
CVE-2016-5674
__debugging_center_utils___.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.7.5 through 3.0.0, and NETGEAR Rea
60RISK
open ↗Referência
CVE-2018-1111
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in
78RISK
open ↗Referência
CVE-2018-1111
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in
78RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.