Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,620cataloged exploits
35,647CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,429GitHub PoC 14,270VulnCheck XDB 8,693Nuclei 4,299Metasploit 3,474✓ verified onlyrecentpopularrisk
24,455 exploits
Exploit-DB✓ VexDay Proof
SmartSite CMS 1.0 - 'root' Remote File Inclusion
PHP remote file inclusion vulnerability in SmartSiteCMS 1.0 and earlier, when register_globals is enabled, allows remote
23RISK
open ↗Exploit-DB✓ VexDay Proof
V3 Chat Instant Messenger - '/mail/index.php?id' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in V3 Chat allow remote attackers to inject arbitrary web script or
23RISK
open ↗Exploit-DB✓ VexDay Proof
V3 Chat Instant Messenger - 'expire.php?cust_name' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in V3 Chat allow remote attackers to inject arbitrary web script or
23RISK
open ↗Exploit-DB✓ VexDay Proof
V3 Chat Instant Messenger - 'mycontacts.php' membername Arbitrary User Buddy List Manipulation
mycontacts.php in V3 Chat allows remote authenticated users to gain privileges as other users via a modified membername
23RISK
open ↗Exploit-DB✓ VexDay Proof
GnuPG 1.4.3/1.9.x - Parse_User_ID Remote Buffer Overflow
parse-packet.c in GnuPG (gpg) 1.4.3 and 1.9.20, and earlier versions, allows remote attackers to cause a denial of servi
23RISK
open ↗Exploit-DB✓ VexDay Proof
V3 Chat Instant Messenger - 'profileview.php?membername' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in V3 Chat allow remote attackers to inject arbitrary web script or
23RISK
open ↗Exploit-DB✓ VexDay Proof
V3 Chat Instant Messenger - 'search.php' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in V3 Chat allow remote attackers to inject arbitrary web script or
23RISK
open ↗Exploit-DB✓ VexDay Proof
vCard PRO - 'create.php?card_id' SQL Injection
Multiple SQL injection vulnerabilities in Belchior Foundry vCard PRO allow remote attackers to execute arbitrary SQL com
23RISK
open ↗Exploit-DB✓ VexDay Proof
IdeaBox 1.1 - 'gorumDir' Remote File Inclusion
PHP remote file inclusion vulnerability in include.php in PHPOutsourcing IdeaBox (aka IdeBox) 1.1 allows remote attacker
23RISK
open ↗Exploit-DB✓ VexDay Proof
vCard PRO - 'gbrowse.php?cat_id' SQL Injection
Multiple SQL injection vulnerabilities in Belchior Foundry vCard PRO allow remote attackers to execute arbitrary SQL com
23RISK
open ↗Exploit-DB✓ VexDay Proof
vCard PRO - 'search.php?event_id' SQL Injection
Multiple SQL injection vulnerabilities in Belchior Foundry vCard PRO allow remote attackers to execute arbitrary SQL com
23RISK
open ↗Exploit-DB✓ VexDay Proof
Singapore 0.9.x/0.10 - 'index.php?template' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in singapore 0.10.0 and earlier allows remote attackers to inject
23RISK
open ↗Exploit-DB✓ VexDay Proof
e107 0.7.5 - 'search.php' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in e107 0.7.5 allow remote attackers to inject arbitrary web script
23RISK
open ↗Exploit-DB✓ VexDay Proof
SaphpLesson 1.1/2.0/3.0 - Multiple SQL Injections
SQL injection vulnerability in misc.php in SaphpLesson 1.1 and earlier allows remote attackers to execute arbitrary SQL
23RISK
open ↗Exploit-DB✓ VexDay Proof
vCard PRO - 'rating.php?card_id' SQL Injection
Multiple SQL injection vulnerabilities in Belchior Foundry vCard PRO allow remote attackers to execute arbitrary SQL com
23RISK
open ↗Exploit-DB✓ VexDay Proof
Singapore 0.9.x/0.10 - Multiple Traversal Arbitrary File Access
Directory traversal vulnerability in index.php in singapore 0.10.0 and earlier allows remote attackers to read arbitrary
23RISK
open ↗Exploit-DB✓ VexDay Proof
Eduha Meeting - 'index.php' Arbitrary File Upload
index.php in Eduha Meeting does not properly restrict file extensions before permitting a file upload, which allows remo
23RISK
open ↗Exploit-DB✓ VexDay Proof
Cisco CallManager 3.x/4.x - 'Web Interface 'ccmuser/logon.asp' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Cisco CallManager 3.3 before 3.3(5)SR3, 4.1 before 4.1(3)SR4, 4.2 before 4.2
28RISK
open ↗Exploit-DB✓ VexDay Proof
WeBBoA Host Script 1.1 - SQL Injection
SQL injection vulnerability in WeBBoA Hosting 1.1 allows remote attackers to execute arbitrary SQL commands via the id p
23RISK
open ↗Exploit-DB✓ VexDay Proof
Cisco CallManager 3.x/4.x - 'Web Interface 'ccmadmin/phonelist.asp?Pattern' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Cisco CallManager 3.3 before 3.3(5)SR3, 4.1 before 4.1(3)SR4, 4.2 before 4.2
28RISK
open ↗Exploit-DB✓ VexDay Proof
Indexu 5.0.1 - 'admin_template_path' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in nicecoder.com INDEXU 5.0.0 and 5.0.1 allow remote attackers to exe
23RISK
open ↗Exploit-DB✓ VexDay Proof
Indexu 5.0.1 - 'admin_template_path' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Indexu 5.0.1 allow remote attackers to execute arbitrary PHP code
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Excel - Unicode Local Overflow (PoC)
Stack-based buffer overflow in the HrShellOpenWithMonikerDisplayName function in Microsoft Hyperlink Object Library (hli
35RISK
open ↗Exploit-DB✓ VexDay Proof
Indexu 5.0.1 - 'admin_template_path' Remote File Inclusion
PHP remote file include vulnerability in application.php in nicecoder.com indexu 5.0.0 and 5.0.1 allows remote attackers
23RISK
open ↗Exploit-DB✓ VexDay Proof
RahnemaCo - 'page.php' PageID Remote File Inclusion
PHP remote file inclusion vulnerability in page.php in an unspecified RahnemaCo.com product, possibly eShop, allows remo
23RISK
open ↗Exploit-DB✓ VexDay Proof
CMS Faethon 1.3.2 - Multiple Remote File Inclusions
PHP remote file inclusion vulnerability in data/header.php in CMS Faethon 1.3.2 allows remote attackers to execute arbit
23RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! 1.0.9 - 'Weblinks' Blind SQL Injection
SQL injection vulnerability in the Weblinks (com_weblinks) component for Joomla! and Mambo 1.0.9 and earlier allows remo
23RISK
open ↗Exploit-DB✓ VexDay Proof
Mambo 4.6rc1 - Weblinks Blind SQL Injection (1)
SQL injection vulnerability in the Weblinks module (weblinks.php) in Mambo 4.6rc1 and earlier allows remote attackers to
23RISK
open ↗Exploit-DB✓ VexDay Proof
CMS Faethon 1.3.2 - 'mainpath' Remote File Inclusion
Multiple cross-site scripting (XSS) vulnerabilities in CMS Faethon 1.3.2 allow remote attackers to inject arbitrary web
23RISK
open ↗Exploit-DB✓ VexDay Proof
mcGuestbook 1.3 - 'ecrire.php?lang' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in mcGuestbook 1.3 allow remote attackers to execute arbitrary PHP co
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.