Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,460Referência 22,910GitHub PoC 14,997VulnCheck XDB 8,843Nuclei 4,358Metasploit 3,489✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
Hex Workshop 5.1.4 - Color Mapping File Local Buffer Overflow (PoC)
Buffer overflow in BreakPoint Software Hex Workshop 5.1.4 allows user-assisted attackers to cause a denial of service an
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component com_pccookbook - 'recipe_id' Blind SQL Injection
SQL injection vulnerability in the PcCookBook (com_pccookbook) component for Joomla! allows remote attackers to execute
23RISK
open ↗Referência✓ VexDay Proof
Aigaion 1.3.3 - 'topic topic_id' SQL Injection
SQL injection vulnerability in pagetopic.php in Aigaion 1.3.3 and earlier allows remote attackers to execute arbitrary S
23RISK
open ↗Referência✓ VexDay Proof
blogit! - SQL Injection / File Disclosure / Cross-Site Scripting
SQL injection vulnerability in index.asp in Katy Whitton BlogIt! allows remote attackers to execute arbitrary SQL comman
23RISK
open ↗Referência✓ VexDay Proof
S-Gastebuch 1.5.3 - 'gb_pfad' Remote File Inclusion
PHP remote file inclusion vulnerability in functions_inc.php in VS-Gastebuch 1.5.3 and earlier allows remote attackers t
23RISK
open ↗Referência✓ VexDay Proof
Miniweb 0.8.19 - Multiple Vulnerabilities
Heap-based buffer overflow in the _mwProcessReadSocket function in http.c in MiniWeb HTTP Server 0.8.19 allows remote at
23RISK
open ↗Referência✓ VexDay Proof
JV2 Folder Gallery 3.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in theme/include_mode/template.php in JV2 Folder Gallery 3.0.2 and earlier allow
23RISK
open ↗Referência✓ VexDay Proof
Phoenix View CMS Pre Alpha2 - SQL Injection / Local File Inclusion / Cross-Site Scripting
Multiple SQL injection vulnerabilities in Phoenix View CMS Pre Alpha2 and earlier allow remote attackers to execute arbi
23RISK
open ↗Referência✓ VexDay Proof
Merak Media Player 3.2 - '.m3u' File Local Buffer Overflow (PoC)
Stack-based buffer overflow in Merak Media Player 3.2 allows remote attackers to execute arbitrary code via a long strin
28RISK
open ↗Referência✓ VexDay Proof
wavewoo 0.1.1 - 'loading.php?path_include' Remote File Inclusion
PHP remote file inclusion vulnerability in include/loading.php in Alessandro Lulli wavewoo 0.1.1 allows remote attackers
23RISK
open ↗Referência✓ VexDay Proof
Mail Machine 3.989 - Local File Inclusion
Directory traversal vulnerability in the load function in cgi-bin/mail/mailmachine.cgi in Mail Machine 3.989 and earlier
23RISK
open ↗Referência✓ VexDay Proof
WinFTP Server 2.3.0 - 'LIST' (Authenticated) Remote Buffer Overflow
Stack-based buffer overflow in WFTPSRV.exe in WinFTP 2.3.0 allows remote authenticated users to execute arbitrary code v
23RISK
open ↗Referência✓ VexDay Proof
Snircd 1.3.4 - 'send_user_mode' Denial of Service
The send_user_mode function in s_user.c in (1) Undernet ircu 2.10.12.12 and earlier, (2) snircd 1.3.4 and earlier, and u
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component EasyBook 1.1 - 'gbid' SQL Injection
SQL injection vulnerability in the EasyBook (com_easybook) component 1.1 for Joomla! allows remote attackers to execute
23RISK
open ↗Referência✓ VexDay Proof
Microsoft Internet Explorer 7 - Clickjacking
Microsoft Internet Explorer 7 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick acti
28RISK
open ↗Referência✓ VexDay Proof
SiteXS CMS 0.1.1 - Local File Inclusion
Directory traversal vulnerability in post.php in SiteXS CMS 0.1.1 and earlier allows remote attackers to include and exe
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component ElearningForce Flash Magazine Deluxe - SQL Injection
SQL injection vulnerability in the ElearningForce Flash Magazine Deluxe (com_flashmagazinedeluxe) component for Joomla!
23RISK
open ↗Referência✓ VexDay Proof
Blog:CMS 4.1.3 - 'NP_UserSharing.php' Remote File Inclusion
PHP remote file inclusion vulnerability in admin/plugins/NP_UserSharing.php in BLOG:CMS 4.1.3 and earlier allows remote
23RISK
open ↗Referência✓ VexDay Proof
CitectSCADA ODBC Server - Remote Stack Buffer Overflow (Metasploit)
Stack-based buffer overflow in the ODBC server service in Citect CitectSCADA 6 and 7, and CitectFacilities 7, allows rem
60RISK
open ↗Referência✓ VexDay Proof
Jupiter CMS 1.1.5 - '/index.php' Local/Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in Jupiter CMS 1.1.5, when PHP 5.0.0 or later is used, allows remot
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component Com BazaarBuilder Shopping Cart 5.0 - SQL Injection
SQL injection vulnerability in the BazaarBuilder Ecommerce Shopping Cart (com_prod) 5.0 component for Joomla! allows rem
23RISK
open ↗Referência✓ VexDay Proof
OwnRS Blog 1.2 - 'autor.php' SQL Injection
SQL injection vulnerability in autor.php in OwnRS CMS 1.2 allows remote attackers to execute arbitrary SQL commands via
23RISK
open ↗Referência✓ VexDay Proof
AMX Corp. VNC ActiveX Control - 'AmxVnc.dll 1.0.13.0' Remote Buffer Overflow
Multiple buffer overflows in the AMX NetLinx VNC (AmxVnc) ActiveX control in AmxVnc.dll 1.0.13.0 allow remote attackers
28RISK
open ↗Referência✓ VexDay Proof
PHPress 0.2.0 - 'adisplay.php?lang' Local File Inclusion
PHP remote file inclusion vulnerability in adisplay.php in PhPress 0.2.0 allows remote attackers to execute arbitrary PH
23RISK
open ↗Referência✓ VexDay Proof
Community CMS 0.4 - 'id' Blind SQL Injection
SQL injection vulnerability in index.php in Community CMS 0.4 and earlier allows remote attackers to execute arbitrary S
23RISK
open ↗Referência✓ VexDay Proof
CodeBB 1.0 Beta 2 - 'phpbb_root_path' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in CodeBB 1.1b3 and earlier allow remote attackers to execute arbitra
23RISK
open ↗Referência✓ VexDay Proof
Max.Blog 1.0.6 - 'offline_auth.php' Offline Authentication Bypass
SQL injection vulnerability in offline_auth.php in Max.Blog 1.0.6 and earlier, when magic_quotes_gpc is disabled, allows
23RISK
open ↗Referência✓ VexDay Proof
YourFreeScreamer 1.0 - 'serverPath' Remote File Inclusion
PHP remote file inclusion vulnerability in templates/2blue/bodyTemplate.php in YourFreeScreamer 1.0 allows remote attack
23RISK
open ↗Referência✓ VexDay Proof
BoastMachine 3.1 - 'mail.php' id SQL Injection
SQL injection vulnerability in mail.php in boastMachine (aka bMachine) 3.1 and earlier allows remote attackers to execut
23RISK
open ↗Referência✓ VexDay Proof
DMXReady Classified Listings Manager 1.1 - SQL Injection
SQL injection vulnerability in CategoryManager/upload_image_category.asp in DMXReady Classified Listings Manager 1.1 and
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.