Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,460Referência 22,910GitHub PoC 14,997VulnCheck XDB 8,843Nuclei 4,358Metasploit 3,489✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
MonGoose 2.4 (Windows) - WebServer Directory Traversal
Directory traversal vulnerability in Mongoose 2.4 allows remote attackers to read arbitrary files via a .. (dot dot) in
23RISK
open ↗Referência✓ VexDay Proof
XZero Community Classifieds 4.95.11 - Remote File Inclusion
PHP remote file inclusion vulnerability in config.inc.php in XZero Community Classifieds 4.95.11 and earlier allows remo
23RISK
open ↗Referência✓ VexDay Proof
DaZPHP 0.1 - 'prefixdir' Local File Inclusion
Directory traversal vulnerability in makepost.php in DaZPHPNews 0.1-1, when register_globals is enabled and magic_quotes
23RISK
open ↗Referência✓ VexDay Proof
VanGogh Web CMS 0.9 - 'article_ID' SQL Injection
SQL injection vulnerability in get_article.php in VanGogh Web CMS 0.9 allows remote attackers to execute arbitrary SQL c
23RISK
open ↗Referência✓ VexDay Proof
groone glinks 2.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in includes/header.php in Groone GLinks 2.1 allows remote attackers to execute a
23RISK
open ↗Referência✓ VexDay Proof
jetAudio 7.x - '.m3u' Local Overwrite (SEH)
Stack-based buffer overflow in COWON America jetAudio Basic 7.0.3 allows user-assisted remote attackers to execute arbit
23RISK
open ↗Referência✓ VexDay Proof
MyBloggie 2.1.6 - Multiple SQL Injections
Cross-site request forgery (CSRF) vulnerability in admin.php in myWebland myBloggie 2.1.6 allows remote attackers to per
23RISK
open ↗Referência✓ VexDay Proof
OCE 3121/3122 Printer - 'parser.exe' Denial of Service
parser.exe in Océ (OCE) 3121/3122 Printer allows remote attackers to cause a denial of service (crash or reboot) via a l
23RISK
open ↗Referência✓ VexDay Proof
Simple Customer 1.3 - Arbitrary Change Admin Password
profile.php in Simple Customer 1.3 does not require administrative authentication, which allows remote attackers to chan
23RISK
open ↗Referência✓ VexDay Proof
Okul Otomasyon Portal 2.0 - SQL Injection
SQL injection vulnerability in default.asp in Okul Otomasyon Portal 2.0 allows remote attackers to execute arbitrary SQL
23RISK
open ↗Referência✓ VexDay Proof
MiniBB 2.2 - Cross-Site Scripting / SQL Injection / Full Path Disclosure
miniBB 2.2, and possibly earlier, when register_globals is enabled, allows remote attackers to obtain the full path via
23RISK
open ↗Referência✓ VexDay Proof
XPOZE Pro 3.06 - 'uid' SQL Injection
SQL injection vulnerability in user.html in Xpoze Pro 3.06 (aka Xpoze Pro CMS 2008) allows remote attackers to execute a
23RISK
open ↗Referência✓ VexDay Proof
PHP-Nuke NukeAI Module 3b - 'util.php' Remote File Inclusion
Direct static code injection vulnerability in util.php in the NukeAI 0.0.3 Beta module for PHP-Nuke, aka Program E is an
23RISK
open ↗Referência✓ VexDay Proof
Liberum Help Desk 0.97.3 - SQL Injection / File Disclosure
Doug Luxem Liberum Help Desk 0.97.3 stores db/helpdesk2000.mdb under the web root with insufficient access control, whic
23RISK
open ↗Referência✓ VexDay Proof
P-News 1.16/1.17 - 'user.dat' Remote Password Disclosure
P-News 1.16 and 1.17 store sensitive information under the web root with insufficient access control, which allows remot
23RISK
open ↗Referência✓ VexDay Proof
ColdFusion Scripts Red_Reservations - Database Disclosure
The Red_Reservations script for ColdFusion stores sensitive information under the web root with insufficient access cont
23RISK
open ↗Referência✓ VexDay Proof
Ocean12 FAQ Manager Pro - Database Disclosure
Ocean12 FAQ Manager Pro stores sensitive data under the web root with insufficient access control, which allows remote a
23RISK
open ↗Referência✓ VexDay Proof
PHPmotion 2.0 - 'update_profile.php' Arbitrary File Upload
SQL injection vulnerability in play.php in PHPmotion 2.0 and earlier allows remote attackers to execute arbitrary SQL co
23RISK
open ↗Referência✓ VexDay Proof
cf shopkart 5.2.2 - SQL Injection / File Disclosure
CF Shopkart 5.2.2 stores cfshopkart52.mdb under the web root with insufficient access control, which allows remote attac
23RISK
open ↗Referência✓ VexDay Proof
U&M Software JustBookIt 1.0 - Authentication Bypass
U&M Software JustBookIt 1.0 does not require administrative authentication for all scripts in the admin/ directory, whic
23RISK
open ↗Referência✓ VexDay Proof
Advanced Guestbook 2.4.0 - 'phpBB' File Inclusion
PHP remote file inclusion vulnerability in admin/addentry.php in phpBB Advanced Guestbook 2.4.0 and earlier, when regist
23RISK
open ↗Referência✓ VexDay Proof
XOOPS Module Lykos Reviews 1.00 - 'index.php' SQL Injection
SQL injection vulnerability in index.php in the Lykos Reviews (lykos_reviews) 1.00 module for Xoops allows remote attack
23RISK
open ↗Referência✓ VexDay Proof
Zomplog 3.8 - 'mp3playlist.php' SQL Injection
SQL injection vulnerability in plugins/mp3playlist/mp3playlist.php in Zomplog 3.8 and earlier allows remote attackers to
23RISK
open ↗Referência✓ VexDay Proof
LimeSurvey 1.52 - 'language.php' Remote File Inclusion
PHP remote file inclusion vulnerability in classes/core/language.php in LimeSurvey 1.5.2 and earlier allows remote attac
23RISK
open ↗Referência✓ VexDay Proof
awzMB 4.2 Beta 1 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in awzMB 4.2 beta 1 and earlier allow remote attackers to execute arb
28RISK
open ↗Referência✓ VexDay Proof
xNews 1.3 - 'xNews.php' SQL Injection
SQL injection vulnerability in xNews.php in xNews 1.3 allows remote attackers to execute arbitrary SQL commands via the
23RISK
open ↗Referência✓ VexDay Proof
X-ice News System 1.0 - 'devami.asp?id' SQL Injection
SQL injection vulnerability in devami.asp in X-Ice News System 1.0 allows remote attackers to execute arbitrary SQL comm
23RISK
open ↗Referência✓ VexDay Proof
ImperialBB 2.3.5 - Arbitrary File Upload
Unrestricted file upload vulnerability in ImperialBB 2.3.5 and earlier allows remote authenticated users to upload and e
23RISK
open ↗Referência✓ VexDay Proof
XOOPS Module Friendfinder 3.3 - 'view.php?id' SQL Injection
SQL injection vulnerability in view.php in the Friendfinder 3.3 and earlier module for Xoops allows remote attackers to
23RISK
open ↗Referência✓ VexDay Proof
BBPortalS 2.0 - Blind SQL Injection
SQL injection vulnerability in tnews.php in BBsProcesS BBPortalS 1.5.10 through 2.0 allows remote attackers to execute a
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.