Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,460Referência 22,910GitHub PoC 14,997VulnCheck XDB 8,843Nuclei 4,358Metasploit 3,489✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
Multi-Threaded TFTP 1.1 - GET Denial of Service
Heap-based buffer overflow in FutureSoft TFTP Server Multithreaded (MT) 1.1 allows remote attackers to cause a denial of
23RISK
open ↗Referência✓ VexDay Proof
The Walking Club - Authentication Bypass
SQL injection vulnerability in login.aspx in WarHound Walking Club allows remote attackers to execute arbitrary SQL comm
23RISK
open ↗Referência✓ VexDay Proof
TotalCalendar 2.30 - 'inc' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in TotalCalendar 2.30 and earlier allows remote attackers to execut
23RISK
open ↗Referência✓ VexDay Proof
MP3 TrackMaker 1.5 - '.mp3' Local Heap Overflow (PoC)
Heap-based buffer overflow in Heathco Software MP3 TrackMaker 1.5 allows remote attackers to cause a denial of service (
23RISK
open ↗Referência✓ VexDay Proof
TLS - Renegotiation
The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS
70RISK
open ↗Referência✓ VexDay Proof
OpenGoo 1.1 - Local File Inclusion
Directory traversal vulnerability in upgrade/index.php in OpenGoo 1.1, when register_globals is enabled and magic_quotes
23RISK
open ↗Referência✓ VexDay Proof
PHP 5.2.3 Win32std - 'win_shell_execute' Safe Mode / disable_functions Bypass
The win32std extension in PHP 5.2.3 does not follow safe_mode and disable_functions restrictions, which allows remote at
23RISK
open ↗Referência✓ VexDay Proof
MW6 Barcode - ActiveX 'Barcode.dll' Remote Heap Overflow (PoC)
Heap-based buffer overflow in MW6 Technologies Barcode ActiveX control (Barcode.MW6Barcode.1, Barcode.dll) 3.0.0.1 allow
23RISK
open ↗Referência✓ VexDay Proof
FlexCell Grid Control 5.6.9 - Remote File Overwrite
Multiple insecure method vulnerabilities in the FlexCell.Grid ActiveX control (FlexCell.ocx) in FlexCell Grid Control 5.
23RISK
open ↗Referência✓ VexDay Proof
SunOS Release 5.11 snv_101b - Remote IPv6 Crash
The kernel in Sun Solaris 10 and 11 snv_101b, and OpenSolaris before snv_108, allows remote attackers to cause a denial
23RISK
open ↗Referência✓ VexDay Proof
WordPress Plugin fGallery 2.4.1 - 'fimrss.php' SQL Injection
SQL injection vulnerability in fim_rss.php in the fGallery 2.4.1 plugin for WordPress allows remote attackers to execute
23RISK
open ↗Referência✓ VexDay Proof
BibCiter 1.4 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in BibCiter 1.4 allow remote attackers to execute arbitrary SQL commands via the
23RISK
open ↗Referência✓ VexDay Proof
Hospital Management System 4.0 - Persistent Cross-Site Scripting
PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple Persistent XSS vulnerabilities.
38RISK
open ↗Referência✓ VexDay Proof
HP Digital Imaging 'hpqvwocx.dll 2.1.0.556' - 'SaveToFile()' File Write
Absolute path traversal vulnerability in a certain ActiveX control in hpqvwocx.dll 2.1.0.556 in Hewlett-Packard (HP) Dig
23RISK
open ↗Referência✓ VexDay Proof
CMS MAXSITE 1.10 - 'category' SQL Injection
SQL injection vulnerability in index.php in MAXSITE 1.10 and earlier allows remote attackers to execute arbitrary SQL co
23RISK
open ↗Referência✓ VexDay Proof
MetaForum 0.513 Beta - Arbitrary File Upload
Unrestricted file upload vulnerability in usercp.php in MetaForum 0.513 Beta restricts file types based on the MIME type
23RISK
open ↗Referência✓ VexDay Proof
Yahoo! Music Jukebox 2.2 - 'AddImage()' ActiveX Remote Buffer Overflow (PoC)
Stack-based buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! Music Jukebox 2.2.2.056 allows
23RISK
open ↗Referência✓ VexDay Proof
Free Bible Search PHP Script - SQL Injection
SQL injection vulnerability in readbible.php in Free Bible Search PHP Script 1.0 allows remote attackers to execute arbi
23RISK
open ↗Referência✓ VexDay Proof
Hex Workshop 5.1.4 - Color Mapping File Local Buffer Overflow (PoC)
Buffer overflow in BreakPoint Software Hex Workshop 5.1.4 allows user-assisted attackers to cause a denial of service an
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component com_pccookbook - 'recipe_id' Blind SQL Injection
SQL injection vulnerability in the PcCookBook (com_pccookbook) component for Joomla! allows remote attackers to execute
23RISK
open ↗Referência✓ VexDay Proof
Aigaion 1.3.3 - 'topic topic_id' SQL Injection
SQL injection vulnerability in pagetopic.php in Aigaion 1.3.3 and earlier allows remote attackers to execute arbitrary S
23RISK
open ↗Referência✓ VexDay Proof
verlihub 0.9.8d-RC2 - Remote Command Execution
The cTrigger::DoIt function in src/ctrigger.cpp in the trigger mechanism in the daemon in Verlihub 0.9.8d-RC2 and earlie
23RISK
open ↗Referência✓ VexDay Proof
JBC Explorer 7.20 RC 1 - Remote Code Execution
Direct static code injection vulnerability in dirsys/modules/config/post.php in JBC Explorer 7.20 RC1 and earlier allows
23RISK
open ↗Referência✓ VexDay Proof
ESPG (Enhanced Simple PHP Gallery) 1.72 - File Disclosure
Directory traversal vulnerability in gallery/comment.php in Enhanced Simple PHP Gallery (ESPG) 1.72 allows remote attack
23RISK
open ↗Referência✓ VexDay Proof
blogit! - SQL Injection / File Disclosure / Cross-Site Scripting
SQL injection vulnerability in index.asp in Katy Whitton BlogIt! allows remote attackers to execute arbitrary SQL comman
23RISK
open ↗Referência✓ VexDay Proof
Quate CMS 0.3.4 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Quate CMS 0.3.4 allow remote attackers to inject arbitrary web sc
23RISK
open ↗Referência✓ VexDay Proof
CoreHTTP 0.5.3alpha - HTTPd Remote Buffer Overflow
Multiple buffer overflows in the HttpSprockMake function in http.c in Frank Yaul corehttp 0.5.3alpha allow remote attack
23RISK
open ↗Referência✓ VexDay Proof
Simple Machines Forum (SMF) 1.1.6 - Local File Inclusion / Code Execution
Directory traversal vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 all
23RISK
open ↗Referência✓ VexDay Proof
ZeusCMS 0.3 - Blind SQL Injection
Absolute path traversal vulnerability in ZeusCMS 0.3 and earlier might allow remote attackers to list arbitrary director
23RISK
open ↗Referência✓ VexDay Proof
blogit! - SQL Injection / File Disclosure / Cross-Site Scripting
Katy Whitton BlogIt! stores sensitive information under the web root with insufficient access control, which allows remo
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.