Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,401cataloged exploits
35,511CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,332GitHub PoC 14,209VulnCheck XDB 8,646Nuclei 4,289Metasploit 3,474✓ verified onlyrecentpopularrisk
22,332 exploits
Referência✓ VexDay Proof
Fuzzylime Forum 1.0 - 'low.php?topic' SQL Injection
Cross-site scripting (XSS) vulnerability in low.php in Fuzzylime Forum 1.0 allows remote attackers to inject arbitrary w
23RISK
open ↗Referência
CVE-2017-17618
Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter.
23RISK
open ↗Referência✓ VexDay Proof
XOOPS Module horoscope 2.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in footer.php in the Horoscope 1.0 module for XOOPS allows remote attackers to e
45RISK
open ↗Referência✓ VexDay Proof
xoops module tinycontent 1.5 - Remote File Inclusion
PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the TinyContent 1.5 module for XOOPS all
35RISK
open ↗Referência
CVE-2017-17619
Laundry Booking Script 1.0 has SQL Injection via the /list city parameter.
23RISK
open ↗Referência✓ VexDay Proof
PHPMyInventory 2.8 - 'global.inc.php' Remote File Inclusion
PHP remote file inclusion vulnerability in Includes/global.inc.php in phpMyInventory 2.8 allows remote attackers to exec
23RISK
open ↗Referência✓ VexDay Proof
Microsoft Office - MSODataSourceControl COM-object Buffer Overflow (PoC)
Buffer overflow in the Microsoft Office MSODataSourceControl ActiveX object allows remote attackers to cause a denial of
35RISK
open ↗Referência
CVE-2017-17620
Lawyer Search Script 1.1 has SQL Injection via the /lawyer-list city parameter.
23RISK
open ↗Referência✓ VexDay Proof
XOOPS Module wiwimod 0.4 - Remote File Inclusion
PHP remote file inclusion vulnerability in spaw/spaw_control.class.php in the WiwiMod 0.4 module for XOOPS allows remote
28RISK
open ↗Referência✓ VexDay Proof
LiveCMS 3.4 - 'categoria.php?cid' SQL Injection
categoria.php in LiveCMS 3.4 and earlier allows remote attackers to obtain sensitive information via a ' (quote) charact
23RISK
open ↗Referência✓ VexDay Proof
LiveCMS 3.4 - 'categoria.php?cid' SQL Injection
Unrestricted file upload vulnerability in LiveCMS 3.4 and earlier allows remote attackers to upload and execute arbitrar
23RISK
open ↗Referência✓ VexDay Proof
MiniBill 1.2.5 - 'run_billing.php' Remote File Inclusion
PHP remote file inclusion vulnerability in crontab/run_billing.php in MiniBill 1.2.5 allows remote attackers to execute
35RISK
open ↗Referência
CVE-2017-17621
Multivendor Penny Auction Clone Script 1.0 has SQL Injection via the PATH_INFO to the /detail URI.
23RISK
open ↗Referência✓ VexDay Proof
Solar Empire 2.9.1.1 - Blind SQL Injection / Hash Retrieve
SQL injection vulnerability in game_listing.php in Solar Empire 2.9.1.1 and earlier allows remote attackers to execute a
23RISK
open ↗Referência✓ VexDay Proof
LAN Management System (LMS) 1.9.6 - Remote File Inclusion
PHP remote file inclusion vulnerability in lib/language.php in LAN Management System (LMS) 1.9.6 and earlier allows remo
35RISK
open ↗Referência✓ VexDay Proof
BitchX 1.1-final - 'EXEC' Remote Command Execution
hook.c in BitchX 1.1-final allows remote IRC servers to execute arbitrary commands by sending a client certain data cont
23RISK
open ↗Referência✓ VexDay Proof
Sun Board 1.00.00 alpha - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Sun Board 1.00.00 Alpha allow remote attackers to execute arbitrar
45RISK
open ↗Referência
CVE-2026-14817
Element Pack Elementor Addons < 8.7.13 - Contributor+ DOM-Based Stored XSS via uikit Data Attributes
33RISK
open ↗Referência✓ VexDay Proof
NCTAudioEditor2 ActiveX DLL 'NCTWMAFile2.dll 2.6.2.157' - File Write
The NCTAudioEditor2 ActiveX control in NCTWMAFile2.dll 2.6.2.157, as distributed in NCTAudioEditor and NCTAudioStudio 2.
23RISK
open ↗Referência✓ VexDay Proof
b1gbb 2.24.0 - 'footer.inc.php?tfooter' Remote File Inclusion
PHP remote file inclusion vulnerability in footer.inc.php in B1G b1gBB 2.24 allows remote attackers to execute arbitrary
45RISK
open ↗Referência✓ VexDay Proof
Ripe Website Manager (CMS) 0.8.9 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Ripe Website Manager 0.8.9 and earlier allow remote attackers to e
35RISK
open ↗Referência✓ VexDay Proof
Buddy Zone 1.5 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in Buddy Zone 1.5 and earlier allow remote attackers to execute arbitrary SQL com
23RISK
open ↗Referência
CVE-2007-3530
PHPDirector 0.21 and earlier stores the admin account name and password in config.php, which allows local users to gain
23RISK
open ↗Referência
CVE-2017-17622
Online Exam Test Application Script 1.6 has SQL Injection via the exams.php sort parameter.
23RISK
open ↗Referência
CVE-2026-12500
WP Travel Engine < 6.8.2 - Unauthenticated Trip Difficulty Level Option Update
41RISK
open ↗Referência
CVE-2026-11881
Fluent Forms < 6.2.6 - Contributor+ Stored XSS via Date/Time Field
33RISK
open ↗Referência
CVE-2026-11870
Hide My WP Ghost < 7.0.05 - IP Address Spoofing via Trusted Proxy Headers Leading to Protection Mechanism Bypass
33RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.