Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,607cataloged exploits
34,986CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,899GitHub PoC 13,974VulnCheck XDB 8,571Nuclei 4,248Metasploit 3,472✓ verified onlyrecentpopularrisk
24,443 exploits
Exploit-DB
Limny 2.0 - Cross-Site Request Forgery (Change Email and Password)
Multiple cross-site request forgery (CSRF) vulnerabilities in Limny 2.0 allow remote attackers to (1) hijack the authent
23RISK
open ↗Exploit-DB✓ VexDay Proof
Pogodny CMS - SQL Injection
SQL injection vulnerability in index.php in KR MEDIA Pogodny CMS allows remote attackers to execute arbitrary SQL comman
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apache mod_rewrite - LDAP protocol Buffer Overflow (Metasploit)
Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and o
60RISK
open ↗Exploit-DB✓ VexDay Proof
Alt-N WebAdmin - USER Buffer Overflow (Metasploit)
Buffer overflow in WebAdmin.exe for WebAdmin allows remote attackers to execute arbitrary code via an HTTP request to We
50RISK
open ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Copperleaf Photolog 0.16 - SQL Injection
SQL injection vulnerability in cplphoto.php in the Copperleaf Photolog plugin 0.16, and possibly earlier, for WordPress
23RISK
open ↗Exploit-DB✓ VexDay Proof
Katalog Stron Hurricane 1.3.5 - Remote File Inclusion / SQL Injection
PHP remote file inclusion vulnerability in includes/moderation.php in Katalog Stron Hurricane 1.3.5, and possibly earlie
23RISK
open ↗Exploit-DB✓ VexDay Proof
Katalog Stron Hurricane 1.3.5 - Remote File Inclusion / SQL Injection
SQL injection vulnerability in index.php in Katalog Stron Hurricane 1.3.5, and possibly earlier, allows remote attackers
23RISK
open ↗Exploit-DB
Joomla! Component Jw_allVideos - Arbitrary File Download
Directory traversal vulnerability in includes/download.php in the JoomlaWorks AllVideos (Jw_allVideos) plugin 3.0 throug
43RISK
open ↗Exploit-DB✓ VexDay Proof
JTL-Shop 2 - 'druckansicht.php' SQL Injection
SQL injection vulnerability in druckansicht.php in JTL-Shop 2 allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗Exploit-DB✓ VexDay Proof
Sambar Server 6 - Search Results Buffer Overflow (Metasploit)
Stack-based buffer overflow in results.stm for Sambar Server before the 6.0 production release allows remote attackers t
60RISK
open ↗Exploit-DB✓ VexDay Proof
WordPress Core 2.9 - Failure to Restrict URL Access
WordPress 2.9 before 2.9.2 allows remote authenticated users to read trash posts from other authors via a direct request
23RISK
open ↗Exploit-DB✓ VexDay Proof
statcountex 3.1 - Multiple Vulnerabilities
StatCounteX 3.0 and 3.1 allows remote attackers to obtain sensitive information and edit configuration scripts via a dir
23RISK
open ↗Exploit-DB✓ VexDay Proof
ZeusCMS 0.2 - Database Backup Dump / Local File Inclusion
Directory traversal vulnerability in index.php in ZeusCMS 0.2 allows remote attackers to include and execute arbitrary l
23RISK
open ↗Exploit-DB✓ VexDay Proof
ZeusCMS 0.2 - Database Backup Dump / Local File Inclusion
ZeusCMS 0.2 stores sensitive information under the web root with insufficient access control, which allows remote attack
23RISK
open ↗Exploit-DB✓ VexDay Proof
statcountex 3.1 - Multiple Vulnerabilities
StatCounteX 3.1 stores sensitive information under the web root with insufficient access control, which allows remote at
23RISK
open ↗Exploit-DB✓ VexDay Proof
WSN Guest 1.02 - 'orderlinks' SQL Injection
SQL injection vulnerability in index.php in WSN Guest 1.02 allows remote attackers to execute arbitrary SQL commands via
23RISK
open ↗Exploit-DB✓ VexDay Proof
Basic-CMS - 'nav_id' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in pages/index.php in BASIC-CMS allows remote attackers to inject arbitrary web
23RISK
open ↗Exploit-DB
Hyleos ChemView 1.9.5.1 - ActiveX Control Buffer Overflow (Metasploit)
Multiple stack-based buffer overflows in the HyleosChemView.HLChemView ActiveX control (HyleosChemView.ocx) in Hyleos Ch
50RISK
open ↗Exploit-DB✓ VexDay Proof
Vacation Rental Script - SQL Injection
SQL injection vulnerability in index.php in CommodityRentals Vacation Rental Software allows remote attackers to execute
23RISK
open ↗Exploit-DB✓ VexDay Proof
Wireshark - LWRES Dissector getaddrsbyname_request Buffer Overflow (Metasploit)
Multiple buffer overflows in the LWRES dissector in Wireshark 0.9.15 through 1.0.10 and 1.2.0 through 1.2.5 allow remote
60RISK
open ↗Exploit-DB✓ VexDay Proof
Video Games Rentals Script - SQL Injection
SQL injection vulnerability in index.php in CommodityRentals Video Games Rentals allows remote attackers to execute arbi
23RISK
open ↗Exploit-DB✓ VexDay Proof
Books/eBooks Rental Software - SQL Injection
SQL injection vulnerability in index.php in CommodityRentals Books/eBooks Rentals Script allows remote attackers to exec
23RISK
open ↗Exploit-DB✓ VexDay Proof
Cisco Collaboration Server 5 - Cross-Site Scripting / Source Code Disclosure
Cisco Collaboration Server (CCS) 5 allows remote attackers to read the source code of JHTML files via URL encoded charac
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHP 5.3.1 - 'session_save_path() Safe_mode()' Restriction Bypass Exploiot
session.c in the session extension in PHP before 5.2.13, and 5.3.1, does not properly interpret ; (semicolon) characters
23RISK
open ↗Exploit-DB
J.A.G (Just Another Guestbook) 1.14 - Database Disclosure
JAG (Just Another Guestbook) 1.14 stores sensitive information under the web root with insufficient access control, whic
23RISK
open ↗Exploit-DB✓ VexDay Proof
Cisco Collaboration Server 5 - Cross-Site Scripting / Source Code Disclosure
Cross-site scripting (XSS) vulnerability in webline/html/admin/wcs/LoginPage.jhtml in Cisco Collaboration Server (CCS) 5
23RISK
open ↗Exploit-DB✓ VexDay Proof
Trade Manager Script - SQL Injection
SQL injection vulnerability in products.php in CommodityRentals Trade Manager Script allows remote attackers to execute
23RISK
open ↗Exploit-DB✓ VexDay Proof
CD Rentals Script - SQL Injection
SQL injection vulnerability in index.php in CommodityRentals CD Rental Software allows remote attackers to execute arbit
23RISK
open ↗Exploit-DB
Omnidocs - SQL Injection
SQL injection vulnerability in ForceChangePassword.jsp in Newgen Software OmniDocs allows remote attackers to execute ar
23RISK
open ↗Exploit-DB✓ VexDay Proof
RSA - SecurID Cross-Site Scripting
Incomplete blacklist vulnerability in IISWebAgentIF.dll in the WebID RSA Authentication Agent 5.3, and possibly earlier,
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.