Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,772cataloged exploits
35,760CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,523GitHub PoC 14,289VulnCheck XDB 8,710Nuclei 4,319Metasploit 3,476✓ verified onlyrecentpopularrisk
24,455 exploits
Exploit-DB✓ VexDay Proof
Ekinboard 1.0.3 - 'profile.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerabilities in Ekinboard 1.0.3 allow remote attackers to inject arbitrary web script or H
23RISK
open ↗Exploit-DB✓ VexDay Proof
Pearl Forums 2.0 - 'index.php' Multiple SQL Injections
Multiple SQL injection vulnerabilities in PEARLINGER Pearl Forums 2.4 allow remote attackers to execute arbitrary SQL co
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHPWCMS 1.2.5 -DEV - 'login.php?form_lang' Traversal Arbitrary File Access
Multiple directory traversal vulnerabilities in phpwcms 1.2.5 allow remote attackers to read arbitrary files via a .. (d
23RISK
open ↗Exploit-DB✓ VexDay Proof
Walla TeleSite 3.0 - 'ts.exe?sug' Cross-Site Scripting
Cross-site scripting vulnerability (XSS) in ts.exe (aka ts.cgi) in Walla TeleSite 3.0 and earlier allows remote attacker
23RISK
open ↗Exploit-DB✓ VexDay Proof
Walla TeleSite 3.0 - 'ts.exe?tsurl' Arbitrary Article Access
ts.exe in Walla TeleSite 3.0 and earlier allows remote attackers to access privileged information by entering the articl
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHPWCMS 1.2.5 -DEV - 'imgdir' Traversal Arbitrary File Access
Multiple directory traversal vulnerabilities in phpwcms 1.2.5 allow remote attackers to read arbitrary files via a .. (d
23RISK
open ↗Exploit-DB✓ VexDay Proof
Pearl Forums 2.0 - 'index.php' Local File Inclusion
Unspecified vulnerability in index.php in PEARLINGER Pearl Forums 2.4 allows remote attackers to include arbitrary files
23RISK
open ↗Exploit-DB✓ VexDay Proof
Walla TeleSite 3.0 - 'ts.exe?sug' SQL Injection
SQL injection vulnerability in ts.exe (aka ts.cgi) in Walla TeleSite 3.0 and earlier allows remote attackers to inject a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Walla TeleSite 3.0 - 'ts.cgi' File Existence Enumeration
ts.exe (aka ts.cgi) in Walla TeleSite 3.0 and earlier allows remote attackers to access arbitrary local files via the qu
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHPWCMS 1.2.5 -DEV - Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in act_newsletter.php in phpwcms 1.2.5 allow remote attackers to inj
23RISK
open ↗Exploit-DB✓ VexDay Proof
Alstrasoft Template Seller Pro 3.25 - Remote File Inclusion
PHP remote file inclusion vulnerability in payment_paypal.php in AlstraSoft Template Seller Pro 3.25 allows remote attac
23RISK
open ↗Exploit-DB✓ VexDay Proof
Unclassified NewsBoard 1.5.3 Patch 3 - Blind SQL Injection
SQL injection vulnerability in search.inc.php in Unclassified NewsBoard before 1.5.3 Patch 4 allows remote attackers to
23RISK
open ↗Exploit-DB✓ VexDay Proof
Codegrrl - 'Protection.php' Code Execution
PHP file inclusion vulnerability in protection.php in CodeGrrl (a) PHPCalendar 1.0, (b) PHPClique 1.0, (c) PHPCurrently
23RISK
open ↗Exploit-DB✓ VexDay Proof
Wizz Forum 1.20 - 'TopicID' SQL Injection
Multiple SQL injection vulnerabilities in Wizz Forum 1.20 allow remote attackers to execute arbitrary SQL commands via (
23RISK
open ↗Exploit-DB✓ VexDay Proof
Cyphor 0.19 - 'show.php?id' SQL Injection
SQL injection vulnerability in show.php in Cyphor 0.19 and earlier allows remote attackers to execute arbitrary SQL comm
23RISK
open ↗Exploit-DB✓ VexDay Proof
Help Center Live 1.0/1.2/2.0 - 'module.php' Local File Inclusion
PHP file inclusion vulnerability in the osTicket module in Help Center Live before 2.0.3 allows remote attackers to acce
23RISK
open ↗Exploit-DB✓ VexDay Proof
Wizz Forum - 'ForumAuthDetails.php?AuthID' SQL Injection
Multiple SQL injection vulnerabilities in Wizz Forum 1.20 allow remote attackers to execute arbitrary SQL commands via (
23RISK
open ↗Exploit-DB✓ VexDay Proof
Arki-DB 1.0 - 'catid' SQL Injection
SQL injection vulnerability in Arki-DB 1.0 and 2.0 allows remote attackers to execute arbitrary SQL commands via the cat
23RISK
open ↗Exploit-DB✓ VexDay Proof
Wizz Forum - 'forumreply.php?TopicID' SQL Injection
Multiple SQL injection vulnerabilities in Wizz Forum 1.20 allow remote attackers to execute arbitrary SQL commands via (
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHPWebThings 1.4 - 'download.php?File' SQL Injection
SQL injection vulnerability in download.php in PhpWebThings 1.4.4 allows remote attackers to execute arbitrary SQL comma
23RISK
open ↗Exploit-DB✓ VexDay Proof
XOOPS (wfdownloads) 2.05 Module - Multiple Vulnerabilities
SQL injection vulnerability in viewcat.php in XOOPS WF-Downloads module 2.05 allows remote attackers to execute arbitrar
23RISK
open ↗Exploit-DB✓ VexDay Proof
ActiveCampaign 1-2-All Broadcast Email 4.0 - Admin Control Panel 'Username' SQL Injection
SQL injection vulnerability in admin/index.php in ActiveCampaign 1-2-All Broadcast Email allows remote attackers to exec
23RISK
open ↗Exploit-DB✓ VexDay Proof
Veritas Storage Foundation 4.0 - VCSI18N_LANG Local Overflow
Buffer overflow in various ha commands of VERITAS Cluster Server for UNIX before 4.0MP2 allows local users to execute ar
23RISK
open ↗Exploit-DB✓ VexDay Proof
Snort 2.4.2 - Back Orifice Pre-Preprocessor Remote (4)
Stack-based buffer overflow in the Back Orifice (BO) preprocessor for Snort before 2.4.3 allows remote attackers to exec
60RISK
open ↗Exploit-DB✓ VexDay Proof
Snort 2.4.2 - Back Orifice Pre-Preprocessor Remote (3)
Stack-based buffer overflow in the Back Orifice (BO) preprocessor for Snort before 2.4.3 allows remote attackers to exec
60RISK
open ↗Exploit-DB✓ VexDay Proof
Sudo Perl 1.6.x - Environment Variable Handling Security Bypass
Sudo before 1.6.8 p12, when the Perl taint flag is off, does not clear the (1) PERLLIB, (2) PERL5LIB, and (3) PERL5OPT e
23RISK
open ↗Exploit-DB✓ VexDay Proof
RealNetworks RealOne Player/RealPlayer - '.RM' Local Stack Buffer Overflow
Integer overflow in RealNetworks RealPlayer 8, 10, and 10.5, RealOne Player 1 and 2, and Helix Player 10.0.0 allows remo
28RISK
open ↗Exploit-DB✓ VexDay Proof
Moodle 1.6dev - SQL Injection / Command Execution
jumpto.php in Moodle 1.5.2 allows remote attackers to redirect users to other sites via the jump parameter.
23RISK
open ↗Exploit-DB✓ VexDay Proof
SAP Web Application Server 6.x/7.0 - Error Page Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in SAP Web Application Server (WAS) 6.10 allows remote attackers to inject arbi
23RISK
open ↗Exploit-DB✓ VexDay Proof
Operator Shell (OSH) 1.7-14 - Local Privilege Escalation
Buffer overflow in the environment variable substitution code in main.c in OSH 1.7-14 allows local users to inject arbit
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.