Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,201cataloged exploits
36,413CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,464Referência 23,022GitHub PoC 15,017VulnCheck XDB 8,846Nuclei 4,361Metasploit 3,491✓ verified onlyrecentpopularrisk
24,695 exploits
Exploit-DB✓ VexDay Proof
OpenEMR 4.1.1 - 'ofc_upload_image.php' Arbitrary File Upload
Multiple cross-site scripting (XSS) vulnerabilities in iTop (aka IT Operations Portal) 1.1.181 and 1.2.0-RC-282 allow re
23RISK
open ↗Exploit-DB✓ VexDay Proof
OpenEMR 4.1.1 - 'ofc_upload_image.php' Arbitrary File Upload
Unrestricted file upload vulnerability in ofc_upload_image.php in Open Flash Chart v2 Beta 1 through v2 Lug Wyrm Charmer
60RISK
open ↗Exploit-DB✓ VexDay Proof
Novell Groupwise Client - 'gwcls1.dll' ActiveX Remote Code Execution (Metasploit)
An ActiveX control in gwcls1.dll in the client in Novell GroupWise 8.0 before 8.0.3 HP2 and 2012 before SP1 HP1 allows r
50RISK
open ↗Exploit-DB✓ VexDay Proof
VMware OVF Tools - Format String (Metasploit) (2)
Format string vulnerability in VMware OVF Tool 2.1 on Windows, as used in VMware Workstation 8.x before 8.0.5, VMware Pl
50RISK
open ↗Exploit-DB✓ VexDay Proof
Linksys E1500/E2500 - Multiple Vulnerabilities
Cisco Linksys E4200 1.0.05 Build 7 routers contain a Local File Include Vulnerability which could allow remote attackers
28RISK
open ↗Exploit-DB✓ VexDay Proof
Schneider Electric Accutech Manager - Heap Overflow (PoC)
Heap-based buffer overflow in RFManagerService.exe in Schneider Electric Accutech Manager 2.00.1 and earlier allows remo
28RISK
open ↗Exploit-DB✓ VexDay Proof
CubeCart 5.2.0 - 'cubecart.class.php' PHP Object Injection
The Cubecart::_basket method in classes/cubecart.class.php in CubeCart 5.0.0 through 5.2.0 allows remote attackers to un
23RISK
open ↗Exploit-DB✓ VexDay Proof
Cool PDF Reader 3.0.2.256 - Buffer Overflow
Stack-based buffer overflow in the reader in CoolPDF 3.0.2.256 allows remote attackers to execute arbitrary code via a P
43RISK
open ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Wysija Newsletters - Multiple SQL Injections
Multiple SQL injection vulnerabilities in the Wysija Newsletters plugin before 2.2.1 for WordPress allow remote authenti
23RISK
open ↗Exploit-DB✓ VexDay Proof
WordPress Plugin CommentLuv - '_ajax_nonce' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the CommentLuv plugin before 2.92.4 for WordPress allows remote attackers to
23RISK
open ↗Exploit-DB✓ VexDay Proof
VMware OVF Tools - Format String (Metasploit) (1)
Format string vulnerability in VMware OVF Tool 2.1 on Windows, as used in VMware Workstation 8.x before 8.0.5, VMware Pl
50RISK
open ↗Exploit-DB✓ VexDay Proof
Portable UPnP SDK - 'unique_service_name()' Remote Code Execution (Metasploit)
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable
35RISK
open ↗Exploit-DB✓ VexDay Proof
Portable UPnP SDK - 'unique_service_name()' Remote Code Execution (Metasploit)
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable
35RISK
open ↗Exploit-DB✓ VexDay Proof
Portable UPnP SDK - 'unique_service_name()' Remote Code Execution (Metasploit)
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable
35RISK
open ↗Exploit-DB✓ VexDay Proof
Portable UPnP SDK - 'unique_service_name()' Remote Code Execution (Metasploit)
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable
60RISK
open ↗Exploit-DB✓ VexDay Proof
Opera SVG - Use-After-Free
Opera before 12.13 allows remote attackers to execute arbitrary code via crafted clipPaths in an SVG document.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Portable UPnP SDK - 'unique_service_name()' Remote Code Execution (Metasploit)
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable
35RISK
open ↗Exploit-DB✓ VexDay Proof
Cisco Unity Express - Multiple Vulnerabilities
Multiple cross-site request forgery (CSRF) vulnerabilities on the Cisco Unity Express with software before 8.0 allow rem
23RISK
open ↗Exploit-DB✓ VexDay Proof
Portable UPnP SDK - 'unique_service_name()' Remote Code Execution (Metasploit)
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable
35RISK
open ↗Exploit-DB✓ VexDay Proof
Portable UPnP SDK - 'unique_service_name()' Remote Code Execution (Metasploit)
Samsung Kies Air 2.1.207051 and 2.1.210161 relies on the IP address for authentication, which allows remote man-in-the-m
23RISK
open ↗Exploit-DB✓ VexDay Proof
Portable UPnP SDK - 'unique_service_name()' Remote Code Execution (Metasploit)
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable
60RISK
open ↗Exploit-DB✓ VexDay Proof
Cisco Unity Express - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unity Express before 8.0 allow remote attackers to inject a
28RISK
open ↗Exploit-DB✓ VexDay Proof
Portable UPnP SDK - 'unique_service_name()' Remote Code Execution (Metasploit)
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable
35RISK
open ↗Exploit-DB✓ VexDay Proof
CADA 3S CoDeSys Gateway Server - Directory Traversal (Metasploit)
Directory traversal vulnerability in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitr
50RISK
open ↗Exploit-DB✓ VexDay Proof
DataLife Engine - 'preview.php' PHP Code Injection (Metasploit)
DataLife Engine (DLE) 9.7 allows remote attackers to execute arbitrary PHP code via the catlist[] parameter to engine/pr
50RISK
open ↗Exploit-DB✓ VexDay Proof
DataLife Engine - 'preview.php' PHP Code Injection (Metasploit)
Session fixation vulnerability in DataLife Engine (DLE) 9.7 and earlier allows remote attackers to hijack web sessions v
23RISK
open ↗Exploit-DB✓ VexDay Proof
Firebird - Relational Database CNCT Group Number Buffer Overflow (Metasploit)
Stack-based buffer overflow in Firebird 2.1.3 through 2.1.5 before 18514, and 2.5.1 through 2.5.3 before 26623, on Windo
50RISK
open ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Audio Player - 'playerID' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in assets/player.swf in the Audio Player plugin before 2.0.4.6 for Wordpress al
23RISK
open ↗Exploit-DB✓ VexDay Proof
Novell Groupwise Client 8.0 - Multiple Remote Code Execution Vulnerabilities
The client in Novell GroupWise 8.0 before 8.0.3 HP2 and 2012 before SP1 HP1 allows remote attackers to execute arbitrary
28RISK
open ↗Exploit-DB✓ VexDay Proof
Ruby on Rails - JSON Processor YAML Deserialization Code Execution (Metasploit)
lib/active_support/json/backends/yaml.rb in Ruby on Rails 2.3.x before 2.3.16 and 3.0.x before 3.0.20 does not properly
60RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.