Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,647cataloged exploits
34,986CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,899GitHub PoC 14,014VulnCheck XDB 8,571Nuclei 4,248Metasploit 3,472✓ verified onlyrecentpopularrisk
24,443 exploits
Exploit-DB✓ VexDay Proof
Joomla! Component com_gcalendar 1.1.2 - 'gcid' SQL Injection
SQL injection vulnerability in the Google Calendar GCalendar (com_gcalendar) component 1.1.2, 2.1.4, and possibly earlie
23RISK
open ↗Exploit-DB✓ VexDay Proof
phpBazar-2.1.1fix - Remote Administration-Panel
phpBazar 2.1.1fix and earlier does not require administrative authentication for admin/admin.php, which allows remote at
23RISK
open ↗Exploit-DB✓ VexDay Proof
TYPSoft FTP Server 1.10 - APPE DELE Denial of Service
TYPSoft FTP Server 1.10 allows remote authenticated users to cause a denial of service (crash) by sending an APPE (appen
23RISK
open ↗Exploit-DB✓ VexDay Proof
pointcomma 3.8b2 - Remote File Inclusion
PHP remote file inclusion vulnerability in includes/classes/pctemplate.php in PointComma 3.8b2 and earlier allows remote
23RISK
open ↗Exploit-DB✓ VexDay Proof
Quick.Cart 3.4 / Quick.CMS 2.4 - Cross-Site Request Forgery
Multiple cross-site request forgery (CSRF) vulnerabilities in Quick.Cart 3.4 allow remote attackers to hijack the authen
23RISK
open ↗Exploit-DB✓ VexDay Proof
outreach project tool 1.2.6 - Remote File Inclusion
PHP remote file inclusion vulnerability in forums/Forum_Include/index.php in Outreach Project Tool (OPT) 1.2.7 and earli
23RISK
open ↗Exploit-DB✓ VexDay Proof
XM Easy Personal FTP Server 5.8.0 - Remote Denial of Service
XM Easy Personal FTP Server 5.8.0 allows remote authenticated users to cause a denial of service (crash) by uploading or
23RISK
open ↗Exploit-DB✓ VexDay Proof
NukeHall 0.3 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in NukeHall 0.3 and earlier allow remote attackers to execute arbitra
23RISK
open ↗Exploit-DB✓ VexDay Proof
phptraverse 0.8.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in assets/plugins/mp3_id/mp3_id.php in PHP Traverser 0.8.0 allows remote attacke
23RISK
open ↗Exploit-DB✓ VexDay Proof
klinza Professional CMS 5.0.1 - 'menulast.php' Local File Inclusion
Directory traversal vulnerability in funzioni/lib/menulast.php in klinza professional cms 5.0.1 and earlier allows remot
23RISK
open ↗Exploit-DB✓ VexDay Proof
Python < 2.5.2 Imageop Module - 'imageop.crop()' Buffer Overflow
Multiple integer overflows in imageop.c in the imageop module in Python 1.5.2 through 2.5.1 allow context-dependent atta
28RISK
open ↗Exploit-DB✓ VexDay Proof
kr-web 1.1b2 - Remote File Inclusion
PHP remote file inclusion vulnerability in adm/krgourl.php in KR-Web 1.1b2 and earlier allows remote attackers to execut
50RISK
open ↗Exploit-DB✓ VexDay Proof
XM Easy Personal FTP Server 5.8.0 - Remote Denial of Service
Dxmsoft XM Easy Personal FTP Server 5.8.0 allows remote authenticated users to cause a denial of service (daemon outage)
23RISK
open ↗Exploit-DB✓ VexDay Proof
Quick.Cart 3.4 / Quick.CMS 2.4 - Delete Function Cross-Site Request Forgery
Multiple cross-site request forgery (CSRF) vulnerabilities in Quick.Cart 3.4 allow remote attackers to hijack the authen
23RISK
open ↗Exploit-DB✓ VexDay Proof
MySQL 6.0.9 - SELECT Statement WHERE Clause Sub-query Denial of Service
mysqld in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41 does not (1) properly handle errors during execution of cert
28RISK
open ↗Exploit-DB✓ VexDay Proof
Autodesk SoftImage Scene TOC - Arbitrary Command Execution
Autodesk Softimage 7.x and Softimage XSI 6.x allow remote attackers to execute arbitrary JavaScript code via a scene pac
23RISK
open ↗Exploit-DB✓ VexDay Proof
Autodesk SoftImage 7.0 Scene - '.TOC' File Remote Code Execution
Autodesk Softimage 7.x and Softimage XSI 6.x allow remote attackers to execute arbitrary JavaScript code via a scene pac
23RISK
open ↗Exploit-DB✓ VexDay Proof
MySQL 6.0.9 - 'GeomFromWKB()' Function First Argument Geometry Value Handling Denial of Service
mysqld in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41 does not (1) properly handle errors during execution of cert
28RISK
open ↗Exploit-DB✓ VexDay Proof
Autodesk Maya Script - Nodes Arbitrary Command Execution
Autodesk Maya 8.0, 8.5, 2008, 2009, and 2010 and Alias Wavefront Maya 6.5 and 7.0 allow remote attackers to execute arbi
23RISK
open ↗Exploit-DB✓ VexDay Proof
Cisco VPN Client - Integer Overflow Denial of Service
The StartServiceCtrlDispatcher function in the cvpnd service (cvpnd.exe) in Cisco VPN client for Windows before 5.0.06.0
23RISK
open ↗Exploit-DB✓ VexDay Proof
Cacti 0.8.x - 'graph.php' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.7e allow remote attackers to inject arbitrary web scrip
23RISK
open ↗Exploit-DB✓ VexDay Proof
AIMP2 Audio Converter 2.53 build 330 - Playlist '.pls' Unicode Buffer Overflow
Stack-based buffer overflow in AIMP2 Audio Converter 2.53 (build 330) and earlier allows remote attackers to cause a den
28RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component Com_Joomclip - 'cat' SQL Injection
SQL injection vulnerability in the JoomClip (com_joomclip) component for Joomla! allows remote attackers to execute arbi
23RISK
open ↗Exploit-DB✓ VexDay Proof
TEKUVA - Password Reminder Authentication Bypass
TUKEVA Password Reminder before 1.0.0.4 uses a hard-coded password for rem.accdb, which allows local users to discover c
23RISK
open ↗Exploit-DB✓ VexDay Proof
Betsy CMS versions 3.5 - Local File Inclusion
Directory traversal vulnerability in admin/popup.php in Betsy CMS 3.5 allows remote attackers to include and execute arb
23RISK
open ↗Exploit-DB✓ VexDay Proof
Opera Web Browser 10.01 - 'dtoa()' Remote Code Execution
Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation
28RISK
open ↗Exploit-DB✓ VexDay Proof
KDE 4.3.3 - KDELibs 'dtoa()' Remote Code Execution
Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation
28RISK
open ↗Exploit-DB✓ VexDay Proof
KDE KDELibs 4.3.3 - Remote Array Overrun
Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation
28RISK
open ↗Exploit-DB✓ VexDay Proof
Opera 10.01 - Remote Array Overrun
Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation
28RISK
open ↗Exploit-DB✓ VexDay Proof
SeaMonkey 1.1.8 - Remote Array Overrun
Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation
28RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.