Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
75,445cataloged exploits
34,432CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,497GitHub PoC 13,627VulnCheck XDB 8,198Nuclei 4,217Metasploit 3,463✓ verified onlyrecentpopularrisk
21,497 exploits
Referência✓ VexDay Proof
Invision Power Board 2.1.4 - Register Users Denial of Service
index.php in Invision Power Board (IPB) 2.0.1, with Code Confirmation disabled, allows remote attackers to cause an unsp
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component LMO 1.0b2 - Remote File Inclusion
PHP remote file inclusion vulnerability in lmo.php in the LMO Component (com_lmo) 1.0b2 and earlier for Joomla! allows r
23RISK
open ↗Referência
CVE-2017-11398
A session hijacking via log disclosure vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 an
23RISK
open ↗Referência✓ VexDay Proof
UNAK-CMS 1.5 - 'dirroot' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in UNAK-CMS 1.5 and earlier allow remote attackers to execute arbitra
23RISK
open ↗Referência✓ VexDay Proof
CWB PRO 1.5 - 'INCLUDE_PATH' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in GraFX Company WebSite Builder (CWB) PRO 1.5 allow remote attackers
23RISK
open ↗Referência✓ VexDay Proof
XnView 1.92.1 - 'FontName' Slideshow Buffer Overflow
Stack-based buffer overflow in XnView 1.92 and 1.92.1 allows user-assisted remote attackers to execute arbitrary code vi
23RISK
open ↗Referência✓ VexDay Proof
PHPStore Real Estate - Arbitrary File Upload
Unrestricted file upload vulnerability in PHPStore Real Estate allows remote authenticated users to execute arbitrary co
23RISK
open ↗Referência
CVE-2015-3313
SQL injection vulnerability in WordPress Community Events plugin before 1.4.
23RISK
open ↗Referência
CVE-2015-3313
SQL injection vulnerability in WordPress Community Events plugin before 1.4.
23RISK
open ↗Referência
CVE-2014-8393
DLL Hijacking vulnerability in CorelDRAW X7, Corel Photo-Paint X7, Corel PaintShop Pro X7, Corel Painter 2015, and Corel
23RISK
open ↗Referência
CVE-2006-2152
PHP remote file inclusion vulnerability in admin/addentry.php in phpBB Advanced Guestbook 2.4.0 and earlier, when regist
23RISK
open ↗Referência
CVE-2017-13262
In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing length decrement operation. Th
23RISK
open ↗Referência
CVE-2017-13262
In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing length decrement operation. Th
23RISK
open ↗Referência✓ VexDay Proof
SysInfo 1.21 - 'sysinfo.cgi' Remote Command Execution
Direct static code injection vulnerability in sysinfo.cgi in sysinfo 1.21 and possibly other versions before 2.25 allows
23RISK
open ↗Referência✓ VexDay Proof
Advanced Guestbook 2.4.0 - 'phpBB' File Inclusion
PHP remote file inclusion vulnerability in admin/addentry.php in phpBB Advanced Guestbook 2.4.0 and earlier, when regist
23RISK
open ↗Referência✓ VexDay Proof
Simple Web Content Management System - SQL Injection
SQL injection vulnerability in page.php in Simple Web Content Management System allows remote attackers to execute arbit
23RISK
open ↗Referência
CVE-2018-8532
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious
28RISK
open ↗Referência
CVE-2017-14087
A Host Header Injection vulnerability in Trend Micro OfficeScan XG (12.0) may allow an attacker to spoof a particular Ho
23RISK
open ↗Referência
CVE-2017-14087
A Host Header Injection vulnerability in Trend Micro OfficeScan XG (12.0) may allow an attacker to spoof a particular Ho
23RISK
open ↗Referência
CVE-2012-0276
Multiple heap-based buffer overflows in XnView before 1.99 allow remote attackers to cause a denial of service (applicat
23RISK
open ↗Referência
CVE-2012-0276
Multiple heap-based buffer overflows in XnView before 1.99 allow remote attackers to cause a denial of service (applicat
23RISK
open ↗Referência
CVE-2010-1930
Off-by-one error in Novell iManager 2.7, 2.7.3, and 2.7.3 FTF2 allows remote attackers to cause a denial of service (dae
23RISK
open ↗Referência✓ VexDay Proof
OllyDBG 1.10 and ImpREC 1.7f - Export Name Buffer Overflow
Stack-based buffer overflow in (1) OllyDBG 1.10 and (2) ImpREC 1.7f allows user-assisted attackers to execute arbitrary
23RISK
open ↗Referência✓ VexDay Proof
Nokia N95-8 browser - 'setAttributeNode' Method Crash
The web browser in Symbian OS on the Nokia N95 cell phone allows remote attackers to cause a denial of service (crash) v
23RISK
open ↗Referência
CVE-2015-4038
The WP Membership plugin 1.2.3 for WordPress allows remote authenticated users to gain administrator privileges via an i
23RISK
open ↗Referência
FTP Server 1.32 - Denial of Service
The Olive Tree FTP Server (aka com.theolivetree.ftpserver) application through 1.32 for Android allows remote attackers
23RISK
open ↗Referência
CVE-2015-1362
Buffer overflow in the Customize 35mm tab in Two Pilots Exif Pilot 4.7.2 allows remote attackers to execute arbitrary co
23RISK
open ↗Referência
CVE-2015-1362
Buffer overflow in the Customize 35mm tab in Two Pilots Exif Pilot 4.7.2 allows remote attackers to execute arbitrary co
23RISK
open ↗Referência✓ VexDay Proof
ApowerManager 3.1.7 - Phone Manager Remote Denial of Service (PoC)
The ApowerManager application through 3.1.7 for Android allows remote attackers to cause a denial of service via many si
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.