Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,533cataloged exploits
35,607CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,407GitHub PoC 14,247VulnCheck XDB 8,663Nuclei 4,287Metasploit 3,474✓ verified onlyrecentpopularrisk
24,455 exploits
Exploit-DB✓ VexDay Proof
AckerTodo 4.0 - 'index.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in Rob Hensley AckerTodo 4.0 allows remote attackers to inject arb
23RISK
open ↗Exploit-DB✓ VexDay Proof
BinGo News 3.01 - 'bnrep' Remote File Inclusion
PHP remote file inclusion vulnerability in bp_news.php in BinGo News (BP News) 3.01 and earlier allows remote attackers
23RISK
open ↗Exploit-DB✓ VexDay Proof
Uni-vert PHPLeague 0.82 - 'Joueurs.php' SQL Injection
SQL injection vulnerability in consult/joueurs.php in Uni-Vert PhpLeague 0.82 and earlier allows remote attackers to exe
23RISK
open ↗Exploit-DB✓ VexDay Proof
AnnonceV News Script 1.1 - 'page' Remote File Inclusion
PHP remote file inclusion vulnerability in annonce.php in AnnonceV (aka annoncesV) 1.1 allows remote attackers to execut
23RISK
open ↗Exploit-DB✓ VexDay Proof
Zix Forum 1.12 - 'RepId' SQL Injection (1)
SQL injection vulnerability in ReplyNew.asp in ZIXForum 1.12 allows remote attackers to execute arbitrary SQL commands v
23RISK
open ↗Exploit-DB✓ VexDay Proof
DSocks 1.3 - 'Name' Buffer Overflow (PoC)
Buffer overflow in the _tor_resolve function in dsocks.c in dsocks before 1.4 allows remote attackers to execute arbitra
23RISK
open ↗Exploit-DB✓ VexDay Proof
SoftBB 0.1 - 'Page' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in SoftBB 0.1 and earlier allows remote attackers to inject arbitr
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHP-Proxima 6.0 - 'BB_Smilies.php' Local File Inclusion
Direct static code injection vulnerability in admin/save_opt.php in SoftBB 0.1, and possibly earlier, allows remote auth
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHP-Nuke MyHeadlines 4.3.1 Module - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the MyHeadlines before 4.3.2 module for PHP-Nuke allows remote attackers to
23RISK
open ↗Exploit-DB✓ VexDay Proof
Easy Address Book Web Server 1.2 - Remote Format String
Format string vulnerability in Easy Address Book Web Server 1.2 allows remote attackers to cause a denial of service (cr
23RISK
open ↗Exploit-DB✓ VexDay Proof
Yappa-ng 2.3.1 - 'admin_modules' Remote File Inclusion
PHP remote file inclusion vulnerability in Yappa-NG before 2.3.2 allows remote attackers to execute arbitrary PHP code v
23RISK
open ↗Exploit-DB✓ VexDay Proof
Annuaire 1Two 2.2 - SQL Injection
SQL injection vulnerability in index.php in Annuaire 1Two 2.2 allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗Exploit-DB✓ VexDay Proof
Autentificator 2.01 - 'Aut_Verifica.Inc.php' SQL Injection
SQL injection vulnerability in aut_verifica.inc.php in Autentificator 2.01 allows remote attackers to execute arbitrary
23RISK
open ↗Exploit-DB✓ VexDay Proof
PowerZip 7.06.38950 - 'Filename Handling' Local Buffer Overflow
Stack-based buffer overflow in Trident Software PowerZip 7.06 Build 3895 on Windows 2000 allows remote attackers to exec
23RISK
open ↗Exploit-DB✓ VexDay Proof
MyBace Light - 'login_check.php' Remote File
PHP remote file inclusion in MyBace Light Skrip, when register_globals is enabled, allows remote attackers to execute ar
23RISK
open ↗Exploit-DB✓ VexDay Proof
VBZoom 1.11 - 'profile.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in VBZooM allows remote attackers to inject arbitrary web script o
23RISK
open ↗Exploit-DB✓ VexDay Proof
Internet Security Systems 3.6 BlackICE - Local Denial of Service
RapDrv.sys in BlackICE PC Protection 3.6.cpn, cpj, cpiE, and possibly 3.6 and earlier, allows local users to cause a den
23RISK
open ↗Exploit-DB✓ VexDay Proof
YACS CMS 6.6.1 - context[path_to_root] Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Yet Another Community System (YACS) CMS 6.6.1 allow remote attacke
23RISK
open ↗Exploit-DB✓ VexDay Proof
EZContents 2.0.3 - 'search.php?GLOBALS[language_home]' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Visual Shapers ezContents 2.0.3 allow remote attackers to execute
23RISK
open ↗Exploit-DB✓ VexDay Proof
VisualShapers EZContents 2.0.3 - 'Headeruserdata.php' SQL Injection
SQL injection vulnerability in headeruserdata.php in Visual Shapers ezContents 2.0.3 allows remote attackers to execute
23RISK
open ↗Exploit-DB✓ VexDay Proof
EZContents 2.0.3 - 'showguestbook.php?GLOBALS[admin_home]' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Visual Shapers ezContents 2.0.3 allow remote attackers to execute
23RISK
open ↗Exploit-DB✓ VexDay Proof
EZContents 2.0 - 'gallery_summary.php?GLOBALS[admin_home]' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Visual Shapers ezContents 2.0.3 allow remote attackers to execute
23RISK
open ↗Exploit-DB✓ VexDay Proof
EZContents 2.0.3 - 'calendar.php?GLOBALS[language_home]' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Visual Shapers ezContents 2.0.3 allow remote attackers to execute
23RISK
open ↗Exploit-DB✓ VexDay Proof
EZContents 2.0.3 - 'event_list.php?GLOBALS[admin_home]' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Visual Shapers ezContents 2.0.3 allow remote attackers to execute
23RISK
open ↗Exploit-DB✓ VexDay Proof
EZContents 2.0.3 - 'review_summary.php?GLOBALS[admin_home]' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Visual Shapers ezContents 2.0.3 allow remote attackers to execute
23RISK
open ↗Exploit-DB✓ VexDay Proof
phpAtm 1.21 - 'include_location' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in PHP Advanced Transfer Manager (phpATM) 1.20 allow remote attackers
23RISK
open ↗Exploit-DB✓ VexDay Proof
IwebNegar 1.1 - 'comments.php' SQL Injection
SQL injection vulnerability in comments.php in IwebNegar 1.1 allows remote attackers to execute arbitrary SQL commands v
23RISK
open ↗Exploit-DB✓ VexDay Proof
Alstrasoft Template Seller - 'Config[Template_Path]' Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in AlstraSoft Template Seller, and possibly AltraSoft Template Seller
23RISK
open ↗Exploit-DB✓ VexDay Proof
VisualShapers EZContents 2.0.3 - 'Loginreq2.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in loginreq2.php in Visual Shapers ezContents 2.0.3 allows remote attackers to
23RISK
open ↗Exploit-DB✓ VexDay Proof
Digiappz Freekot 1.01 - ASP SQL Injection
Multiple SQL injection vulnerabilities in login_verif.asp in Digiappz Freekot 1.01 allow remote attackers to execute arb
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.