Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,210cataloged exploits
36,420CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,464Referência 23,022GitHub PoC 15,026VulnCheck XDB 8,846Nuclei 4,361Metasploit 3,491✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
XOOPS Module WF-Snippets 1.02 (c) - Blind SQL Injection
SQL injection vulnerability in index.php in the WF-Snippets 1.02 and earlier module for XOOPS allows remote attackers to
23RISK
open ↗Referência✓ VexDay Proof
eReservations - Authentication Bypass
Multiple SQL injection vulnerabilities in default.asp in Enthrallweb eReservations allow remote attackers to execute arb
23RISK
open ↗Referência✓ VexDay Proof
QuickEStore 8.2 - 'insertorder.cfm' SQL Injection
SQL injection vulnerability in insertorder.cfm in QuickEStore 8.2 and earlier allows remote attackers to execute arbitra
23RISK
open ↗Referência✓ VexDay Proof
Arcadwy Arcade Script - (Authentication Bypass) Insecure Cookie Handling
SQL injection vulnerability in Arcadwy Arcade Script allows remote attackers to execute arbitrary SQL commands via the u
23RISK
open ↗Referência✓ VexDay Proof
PHP Real Estate - 'fullnews.php?id' SQL Injection
SQL injection vulnerability in fullnews.php in PHP Real Estate Classifieds allows remote attackers to execute arbitrary
23RISK
open ↗Referência✓ VexDay Proof
Limbo CMS 1.0.4.2 - 'Cuid' cookie Blind SQL Injection
SQL injection vulnerability in class_auth.php in Limbo CMS 1.0.4.2, and possibly earlier versions, allows remote attacke
23RISK
open ↗Referência✓ VexDay Proof
YouTube blog 0.1 - Remote File Inclusion / SQL Injection / Cross-Site Scripting
SQL injection vulnerability in todos.php in C. Desseno YouTube Blog (ytb) 0.1 allows remote attackers to execute arbitra
23RISK
open ↗Referência✓ VexDay Proof
Quick and Dirty Blog (qdblog) 0.4 - SQL Injection / Local File Inclusion
Multiple SQL injection vulnerabilities in authenticate.php in Quick and Dirty Blog (QDBlog) 0.4, and possibly earlier, a
23RISK
open ↗Referência✓ VexDay Proof
Fuzzylime Forum 1.0 - 'low.php?topic' SQL Injection
SQL injection vulnerability in low.php in Fuzzylime Forum 1.0 allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗Referência✓ VexDay Proof
Vastal I-Tech Freelance Zone - 'coder_id' SQL Injection
SQL injection vulnerability in view_cresume.php in Vastal I-Tech Freelance Zone allows remote attackers to execute arbit
23RISK
open ↗Referência✓ VexDay Proof
Netartmedia Blog System - SQL Injection
SQL injection vulnerability in image.php in NetArt Media Blog System 1.5 allows remote attackers to execute arbitrary SQ
23RISK
open ↗Referência✓ VexDay Proof
SFS EZ Career - SQL Injection
SQL injection vulnerability in content.php in Scripts For Sites (SFS) EZ Career allows remote attackers to execute arbit
23RISK
open ↗Referência✓ VexDay Proof
DigiLeave 1.2 - 'book_id' Blind SQL Injection
SQL injection vulnerability in info_book.asp in DigiLeave 1.2 and earlier allows remote attackers to execute arbitrary S
23RISK
open ↗Referência✓ VexDay Proof
Woltlab Burning Board 1.0.2/2.3.6 - 'search.php' SQL Injection (1)
SQL injection vulnerability in search.php in Woltlab Burning Board (wBB) 1.0.2 and earlier, and 2.3.6 and earlier in the
23RISK
open ↗Referência✓ VexDay Proof
Crea-Book 1.0 - Admin Access Bypass / Database Disclosure / Code Execution
Multiple SQL injection vulnerabilities in admin/admin.php in Crea-Book 1.0 and earlier allow remote attackers to execute
23RISK
open ↗Referência✓ VexDay Proof
BluSky CMS - 'news_id' SQL Injection
SQL injection vulnerability in index.php in BluSky CMS allows remote attackers to execute arbitrary SQL commands via the
23RISK
open ↗Referência✓ VexDay Proof
ZEELYRICS 2.0 - 'bannerclick.php' SQL Injection
SQL injection vulnerability in bannerclick.php in ZEELYRICS 2.0 allows remote attackers to execute arbitrary SQL command
23RISK
open ↗Referência✓ VexDay Proof
XOOPS module Articles 1.02 - 'print.php?id' SQL Injection
SQL injection vulnerability in print.php in the Articles 1.02 and earlier module for Xoops allows remote attackers to ex
23RISK
open ↗Referência✓ VexDay Proof
phpFullAnnu (PFA) 6.0 - SQL Injection
SQL injection vulnerability in index.php in phpFullAnnu (PFA) 6.0 allows remote attackers to execute arbitrary SQL comma
23RISK
open ↗Referência✓ VexDay Proof
JobSite Professional 2.0 - 'file.php' SQL Injection
SQL injection vulnerability in file.php in JobSite Professional 2.0 allows remote attackers to execute arbitrary SQL com
23RISK
open ↗Referência✓ VexDay Proof
Content Injector 1.53 - 'index.php' SQL Injection
SQL injection vulnerability in index.php in Content Injector 1.53 allows remote attackers to execute arbitrary SQL comma
23RISK
open ↗Referência✓ VexDay Proof
Autodealers CMS AutOnline - 'id' SQL Injection
SQL injection vulnerability in index.php in Zanfi Autodealers CMS AutOnline allows remote attackers to execute arbitrary
23RISK
open ↗Referência✓ VexDay Proof
LocazoList 2.01a beta5 - 'subcatID' SQL Injection
SQL injection vulnerability in main.asp in LocazoList 2.01a beta5 and earlier allows remote attackers to execute arbitra
23RISK
open ↗Referência✓ VexDay Proof
ThWboard 3.0b2.84-php5 - SQL Injection / Code Execution
SQL injection vulnerability in inc/header.inc.php in ThWboard 3.0b2.84-php5 and earlier allows remote attackers to execu
23RISK
open ↗Referência✓ VexDay Proof
WebPortal CMS 0.7.4 - 'download.php' SQL Injection
SQL injection vulnerability in download.php in WebPortal CMS 0.7.4 and earlier allows remote attackers to execute arbitr
23RISK
open ↗Referência✓ VexDay Proof
LightRO CMS 1.0 - 'index.php?projectid' SQL Injection
SQL injection vulnerability in projects.php in LightRO CMS 1.0 allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗Referência✓ VexDay Proof
Injader CMS 2.1.1 - 'id' SQL Injection
SQL injection vulnerability in feeds.php in Injader before 2.1.2 allows remote attackers to execute arbitrary SQL comman
23RISK
open ↗Referência✓ VexDay Proof
XOOPS Module debaser 0.92 - 'genre.php' Blind SQL Injection
SQL injection vulnerability in genre.php in the debaser 0.92 and earlier module for Xoops allows remote attackers to exe
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component live chat - SQL Injection / Open Proxy
Multiple SQL injection vulnerabilities in the Live Chat (com_livechat) component 1.0 for Joomla! allow remote attackers
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component Phil-a-Form 1.2.0.0 - SQL Injection
SQL injection vulnerability in index.php in the Phil-a-Form (com_philaform) 1.2.0.0 and earlier component for Joomla! al
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.