Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,620cataloged exploits
35,647CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,429GitHub PoC 14,270VulnCheck XDB 8,693Nuclei 4,299Metasploit 3,474✓ verified onlyrecentpopularrisk
22,429 exploits
Referência✓ VexDay Proof
cmreams CMS 1.3.1.1 beta2 - Local File Inclusion / Cross-Site Scripting
Directory traversal vulnerability in load_language.php in CMReams CMS 1.3.1.1 Beta 2, when register_globals is enabled,
23RISK
open ↗Referência✓ VexDay Proof
phpDMCA 1.0.0 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in phpDMCA 1.0.0 allow remote attackers to execute arbitrary PHP code
23RISK
open ↗Referência✓ VexDay Proof
FOG Forum 0.8.1 - Multiple Local File Inclusions
Multiple directory traversal vulnerabilities in index.php in FOG Forum 0.8.1 allow remote attackers to include and execu
23RISK
open ↗Referência✓ VexDay Proof
PHPortal 1.2 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in sablonlar/gunaysoft/gunaysoft.php in PHPortal 1.2 Beta allow remot
23RISK
open ↗Referência✓ VexDay Proof
Efestech Shop 2.0 - 'cat_id' SQL Injection
SQL injection vulnerability in default.asp in EfesTECH Shop 2.0 allows remote attackers to execute arbitrary SQL command
23RISK
open ↗Referência✓ VexDay Proof
PHP-Agenda 2.2.4 - 'index.php' Local File Inclusion
Directory traversal vulnerability in index.php in Simple PHP Agenda 2.2.4 and earlier allows remote attackers to include
23RISK
open ↗Referência
CVE-2026-13539
Wavlink WL-NU516U1-A POST Parameter wireless.cgi sub_407504 stack-based overflow
41RISK
open ↗Referência
CVE-2026-13538
Wavlink WL-NU516U1-A POST Parameter wireless.cgi sub_401D68 command injection
33RISK
open ↗Referência
CVE-2026-13534
CherryHQ cherry-studio CherryIN Preload API MemoryService.ts sha256 authorization
28RISK
open ↗Referência✓ VexDay Proof
Joomla! Component Brightcode Weblinks - 'catid' SQL Injection
SQL injection vulnerability in Brightcode Weblinks (com_brightweblinks) component for Joomla! allows remote attackers to
23RISK
open ↗Referência✓ VexDay Proof
Kasseler CMS 1.3.0 - Local File Inclusion / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the Files module in Kasseler CMS 1.3.0 and 1.3.1 Lite allows remote attacker
23RISK
open ↗Referência✓ VexDay Proof
PHPmotion 2.0 - 'update_profile.php' Arbitrary File Upload
Unrestricted file upload vulnerability in update_profile.php in PHPmotion 2.0 and earlier allows remote authenticated us
23RISK
open ↗Referência✓ VexDay Proof
Mole Group Real Estate Script 1.1 - SQL Injection
SQL injection vulnerability in index.php in Mole Group Real Estate Script 1.1 and earlier allows remote attackers to exe
23RISK
open ↗Referência✓ VexDay Proof
Mole Group Hotel Script 1.0 - SQL Injection
SQL injection vulnerability in index.php in Mole Group Hotel Script 1.0 allows remote attackers to execute arbitrary SQL
23RISK
open ↗Referência✓ VexDay Proof
Mole Group Last Minute Script 4.0 - SQL Injection
SQL injection vulnerability in index.php in Mole Group Lastminute Script 4.0 allows remote attackers to execute arbitrar
23RISK
open ↗Referência✓ VexDay Proof
Pivot 1.40.5 - Dreamwind 'load_template()' Credentials Disclosure
Directory traversal vulnerability in search.php in Pivot 1.40.5 allows remote attackers to read arbitrary files via a ..
23RISK
open ↗Referência✓ VexDay Proof
Catviz 0.4.0 beta1 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in index.php in Catviz 0.4 beta 1 allow remote attackers to execute arbitrary SQL
23RISK
open ↗Referência
CVE-2026-56789
RTKLIB 2.4.3 - Heap Buffer Overflow and Stack Read via Oversized RINEX Epoch Satellite Count
41RISK
open ↗Referência
CVE-2026-56787
RTKLIB 2.4.3 - Off-by-One Out-of-Bounds Read in decode_ssr3 via RTCM3 SSR Message
33RISK
open ↗Referência
CVE-2026-8379
Frontend File Manager Plugin <= 23.6 - Unauthenticated Arbitrary File Download
41RISK
open ↗Referência
CVE-2026-7842
Infility Global < 2.15.20 - Editor+ SQL Injection via orderby Parameter
33RISK
open ↗Referência
CVE-2026-12814
Comfast CF-WR631AX V3 API Endpoint mbox-config system os command injection
33RISK
open ↗Referência✓ VexDay Proof
pSys 0.7.0 Alpha - 'chatbox.php' SQL Injection
SQL injection vulnerability in chatbox.php in pSys 0.7.0 Alpha, when magic_quotes_gpc is disabled, allows remote attacke
23RISK
open ↗Referência✓ VexDay Proof
AShop Deluxe 4.x - 'catalogue.php' SQL Injection
SQL injection vulnerability in catalogue.php in AShop Deluxe 4.x allows remote attackers to execute arbitrary SQL comman
23RISK
open ↗Referência✓ VexDay Proof
SmartPPC Pay Per Click Script - 'idDirectory' Blind SQL Injection (2)
SQL injection vulnerability in directory.php in SmartPPC and SmartPPC Pro allows remote attackers to execute arbitrary S
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.