Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,108cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,464Referência 22,936GitHub PoC 15,010VulnCheck XDB 8,846Nuclei 4,361Metasploit 3,491✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
XOOPS Module WF-Links 1.03 - 'cid' SQL Injection
SQL injection vulnerability in viewcat.php in the WF-Links (wflinks) 1.03 and earlier module for XOOPS allows remote att
23RISK
open ↗Referência✓ VexDay Proof
TinyIdentD 2.2 - Remote Buffer Overflow
Stack-based buffer overflow in TinyIdentD 2.2 and earlier allows remote attackers to execute arbitrary code via a long s
50RISK
open ↗Referência✓ VexDay Proof
PHP-Nuke Module splattforum 4.0 RC1 - Local File Inclusion
Directory traversal vulnerability in bbcode_ref.php in the Giorgio Ciranni Splatt Forum 4.0 RC1 module for PHP-Nuke allo
23RISK
open ↗Referência✓ VexDay Proof
PHPGlossar 0.8 - 'format_menue' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in PHPGlossar 0.8 allow remote attackers to execute arbitrary PHP cod
23RISK
open ↗Referência✓ VexDay Proof
CA BrightStor Backup 11.5.2.0 - 'caloggderd.exe' Denial of Service
(1) caloggerd.exe (camt70.dll) and (2) mediasvr.exe (catirpc.dll and rwxdr.dll) in CA BrightStor Backup 11.5.2.0 SP2 all
28RISK
open ↗Referência✓ VexDay Proof
CA BrightStor Backup 11.5.2.0 - 'Mediasvr.exe' Denial of Service
(1) caloggerd.exe (camt70.dll) and (2) mediasvr.exe (catirpc.dll and rwxdr.dll) in CA BrightStor Backup 11.5.2.0 SP2 all
28RISK
open ↗Referência✓ VexDay Proof
Battle.net Clan Script for PHP 1.5.1 - SQL Injection
SQL injection vulnerability in login.php in Ryan Haudenschilt Battle.net Clan Script for PHP 1.5.1 and earlier allows re
23RISK
open ↗Referência✓ VexDay Proof
InoutMailingListManager 3.1 - Remote Command Execution
Multiple SQL injection vulnerabilities in InoutMailingListManager 3.1 and earlier allow remote attackers to execute arbi
23RISK
open ↗Referência✓ VexDay Proof
pl-PHP Beta 0.9 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in login.php in pL-PHP beta 0.9 allow remote attackers to execute arbitrary SQL c
23RISK
open ↗Referência✓ VexDay Proof
Mambo Component com_yanc 1.4 Beta - 'id' SQL Injection
SQL injection vulnerability in the Yet another Newsletter Component (aka YaNC or com_yanc) component before 1.5 beta 3 f
23RISK
open ↗Referência✓ VexDay Proof
GeekLog 2.x - 'ImageImageMagick.php' Remote File Inclusion
PHP remote file inclusion vulnerability in ImageImageMagick.php in Geeklog 2.x allows remote attackers to execute arbitr
35RISK
open ↗Referência✓ VexDay Proof
Vizayn Urun Tanitim Sistemi 0.2 - 'tr' SQL Injection
SQL injection vulnerability in default.asp in Vizayn Urun Tanitim Sitesi 0.2 allows remote attackers to execute arbitrar
23RISK
open ↗Referência✓ VexDay Proof
Ol BookMarks Manager 0.7.4 - 'root' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in ol'bookmarks 0.7.4 allow remote attackers to execute arbitrary PHP
28RISK
open ↗Referência✓ VexDay Proof
LeadTools Raster Variant - 'LTRVR14e.dll' Remote File Overwrite
A certain ActiveX control in LeadTools Raster Variant Object Library (LTRVR14e.dll) 14.5.0.44 allows remote attackers to
23RISK
open ↗Referência✓ VexDay Proof
Virtual CD 9.0.0.2 - 'vc9api.DLL' Remote Shell Commands Execution
The VCDAPILibApi ActiveX control in vc9api.DLL 9.0.0.57 in Virtual CD 9.0.0.2 allows remote attackers to execute arbitra
23RISK
open ↗Referência✓ VexDay Proof
BtiTracker 1.4.1 - Become Admin SQL Injection
Multiple SQL injection vulnerabilities in account_change.php in BtiTracker 1.4.1 and earlier allow remote attackers to e
23RISK
open ↗Referência✓ VexDay Proof
Microsoft Internet Explorer 6 / Ademco co. ltd. ATNBaseLoader100 Module - Remote Buffer Overflow
Buffer overflow in the BaseRunner ActiveX control in the Ademco ATNBaseLoader100 Module (ATNBaseLoader100.dll) 5.4.0.6,
35RISK
open ↗Referência✓ VexDay Proof
FlaP 1.0b - 'pachtofile' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in FlaP 1.0b (1.0 Beta) allow remote attackers to execute arbitrary P
23RISK
open ↗Referência✓ VexDay Proof
vBulletin vBGSiteMap 2.41 - 'root' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in the creator in vBulletin Google Yahoo Site Map (vBGSiteMap) 2.41 f
23RISK
open ↗Referência✓ VexDay Proof
OpenBASE 0.6a - 'root_prefix' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in OpenBASE Alpha 0.6 allow remote attackers to execute arbitrary PHP
23RISK
open ↗Referência✓ VexDay Proof
DESlock+ < 3.2.6 - 'DLMFDISK.sy's Local kernel Ring0 SYSTEM
DLMFDISK.sys 1.2.0.27 in DESlock+ 3.2.6 and earlier allows local users to gain privileges via a certain DLKFDISK_IOCTL r
23RISK
open ↗Referência✓ VexDay Proof
DESlock+ < 3.2.6 - 'LIST' Local Kernel Memory Leak
Memory leak in DLMFENC.sys 1.0.0.26 in DESlock+ 3.2.6 and earlier allows local users to cause a denial of service (kerne
23RISK
open ↗Referência✓ VexDay Proof
Pheap 2.0 - Authentication Bypass / Remote Code Execution
Pheap 2.0 allows remote attackers to bypass authentication by setting a pheap_login cookie value to the administrator's
23RISK
open ↗Referência✓ VexDay Proof
ZYXEL ZyWALL Quagga/Zebra - 'Default Password' Remote Code Execution
ZyXEL ZyWALL 1050 has a hard-coded password for the Quagga and Zebra processes that is not changed when it is set by a u
28RISK
open ↗Referência✓ VexDay Proof
phpComasy 0.8 - 'mod_project_id' SQL Injection
SQL injection vulnerability in index.php in phpComasy 0.8 allows remote attackers to execute arbitrary SQL commands via
23RISK
open ↗Referência✓ VexDay Proof
WebSPELL 4.01.02 - 'picture.php' File Disclosure
Directory traversal vulnerability in picture.php in WebSPELL 4.01.02 and earlier, when PHP before 4.3.0 is used, allows
23RISK
open ↗Referência✓ VexDay Proof
phpMyNewsletter 0.8 (beta5) - Multiple Vulnerabilities
admin/index.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier provides access to configuration modification
23RISK
open ↗Referência✓ VexDay Proof
Ripe Website Manager (CMS) 0.8.9 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Ripe Website Manager 0.8.9 and earlier allow remote attackers to e
35RISK
open ↗Referência✓ VexDay Proof
Buddy Zone 1.5 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in Buddy Zone 1.5 and earlier allow remote attackers to execute arbitrary SQL com
23RISK
open ↗Referência✓ VexDay Proof
WebChat 0.78 - 'login.php?rid' SQL Injection
SQL injection vulnerability in login.php in WebChat 0.78 allows remote attackers to execute arbitrary SQL commands via t
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.