Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,058cataloged exploits
35,300CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,175GitHub PoC 14,096VulnCheck XDB 8,607Nuclei 4,255Metasploit 3,474✓ verified onlyrecentpopularrisk
24,451 exploits
Exploit-DB✓ VexDay Proof
School Data Navigator - 'page' Local/Remote File Inclusion
PHP remote file inclusion vulnerability in app_and_readme/navigator/index.php in School Data Navigator allows remote att
23RISK
open ↗Exploit-DB✓ VexDay Proof
Desi Short URL Script - (Authentication Bypass) Insecure Cookie Handling
index.php in Desi Short URL Script 1.0 allows remote attackers to bypass authentication by setting the logged cookie to
23RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component com_realestatemanager 1.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in toolbar_ext.php in the RealEstateManager (com_realestatemanager) component 1.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component Akobook 2.3 - 'gbid' SQL Injection
SQL injection vulnerability in the AkoBook (com_akobook) component 2.3 for Joomla! allows remote attackers to execute ar
23RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component BookLibrary 1.5.2.4 - Remote File Inclusion
PHP remote file inclusion vulnerability in toolbar_ext.php in the BookLibrary (com_booklibrary) component 1.5.2.4 Basic
23RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component com_vehiclemanager 1.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in toolbar_ext.php in the VehicleManager (com_vehiclemanager) component 1.0 Basi
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5.0.1 - Cached Content Cross Domain Information Disclosure
Microsoft Internet Explorer 5.01 SP4; 6 SP1; 6 and 7 for Windows XP SP2 and SP3; 6 and 7 for Server 2003 SP2; 7 for Vist
28RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component com_media_library 1.5.3 - Remote File Inclusion
PHP remote file inclusion vulnerability in toolbar_ext.php in the MediaLibrary (com_media_library) component 1.5.3 Basic
23RISK
open ↗Exploit-DB✓ VexDay Proof
mrcgiguy the ticket system 2.0 PHP - Multiple Vulnerabilities
SQL injection vulnerability in admin.php in MRCGIGUY The Ticket System 2.0 allows remote attackers to execute arbitrary
23RISK
open ↗Exploit-DB✓ VexDay Proof
Winds3D Viewer 3 - 'GetURL()' Arbitrary File Download
Insecure method vulnerability in Awingsoft Awakening Winds3D Viewer plugin 3.5.0.0, 3.0.0.5, and possibly other versions
23RISK
open ↗Exploit-DB✓ VexDay Proof
Interlogy Profile Manager Basic - Insecure Cookie Handling
Multiple SQL injection vulnerabilities in cgi/admin.cgi in Interlogy Profile Manager Basic allow remote attackers to exe
23RISK
open ↗Exploit-DB✓ VexDay Proof
MySQL 5.0.75 - 'sql_parse.cc' Multiple Format String Vulnerabilities
Multiple format string vulnerabilities in the dispatch_command function in libmysqld/sql_parse.cc in mysqld in MySQL 4.0
28RISK
open ↗Exploit-DB✓ VexDay Proof
Computer Associates SiteMinder - '%00' Cross-Site Scripting Protection Security Bypass
CA SiteMinder allows remote attackers to bypass cross-site scripting (XSS) protections for J2EE applications via a reque
23RISK
open ↗Exploit-DB✓ VexDay Proof
Computer Associates SiteMinder - Unicode Cross-Site Scripting Protection Security Bypass
CA SiteMinder allows remote attackers to bypass cross-site scripting (XSS) protections for J2EE applications via a reque
23RISK
open ↗Exploit-DB✓ VexDay Proof
Avax Vector 1.3 - 'avPreview.ocx' ActiveX Control Buffer Overflow
Buffer overflow in the Avax Vector ActiveX control in avPreview.ocx in AVAX-software Avax Vector ActiveX 1.3 allows remo
23RISK
open ↗Exploit-DB✓ VexDay Proof
ClanSphere 2009 - 'text' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in the search module in ClanSphere 2009.0 and 2009.0.2 allows remo
23RISK
open ↗Exploit-DB✓ VexDay Proof
Horde 3.1 - 'Passwd' Module Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in passwd/main.php in the Passwd module before 3.1.1 for Horde allows remote at
23RISK
open ↗Exploit-DB✓ VexDay Proof
PeaZIP 2.6.1 - Compressed Filename Command Injection
PeaZIP 2.6.1, 2.5.1, and earlier on Windows allows user-assisted remote attackers to execute arbitrary commands via a .z
50RISK
open ↗Exploit-DB✓ VexDay Proof
Online Armor < 3.5.0.12 - 'OAmon.sys' Local Privilege Escalation
The OAmon.sys kernel driver 3.1.0.0 and earlier in Tall Emu Online Armor Personal Firewall AV+ before 3.5.0.12, and Pers
23RISK
open ↗Exploit-DB✓ VexDay Proof
Google Chrome 0.3.154 - 'JavaScript:' URI in 'Refresh' Header Cross-Site Scripting
Google Chrome 1.0.154.48 and earlier does not block javascript: URIs in Refresh headers in HTTP responses, which allows
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 6 - 'JavaScript:' URI in 'Refresh' Header Cross-Site Scripting
Microsoft Internet Explorer 6.0.2900.2180 and earlier does not block javascript: URIs in Refresh headers in HTTP respons
28RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component Omilen Photo Gallery 0.5b - Local File Inclusion
Directory traversal vulnerability in the Omilen Photo Gallery (com_omphotogallery) component Beta 0.5 for Joomla! allows
38RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component Seminar 1.28 - 'id' Blind SQL Injection
SQL injection vulnerability in the Seminar (com_seminar) component 1.28 for Joomla! allows remote attackers to execute a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple QuickTime - Image Description Atom Sign Extension (PoC)
Apple QuickTime before 7.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application
23RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! Component com_mosres - Multiple SQL Injections
Multiple SQL injection vulnerabilities in the Mambo Resident (aka Mos Res or com_mosres) component 1.0f for Mambo and Jo
23RISK
open ↗Exploit-DB✓ VexDay Proof
Sitecore CMS 6.0.0 rev. 090120 - 'default.aspx' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in login/default.aspx in Sitecore CMS before 6.0.2 Update-1 090507 allows remot
23RISK
open ↗Exploit-DB✓ VexDay Proof
Joomla! < 1.5.11 - Multiple Cross-Site Scripting / HTML Injection Vulnerabilities
Cross-site scripting (XSS) vulnerability in Joomla! 1.5.x through 1.5.10 allows remote attackers to inject arbitrary web
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apache Tomcat 6.0.18 - Form Authentication Existing/Non-Existing 'Username' Enumeration
Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when FORM authentication is used, al
60RISK
open ↗Exploit-DB✓ VexDay Proof
Movie PHP Script 2.0 - 'init.php?anticode' Code Execution
Eval injection vulnerability in system/services/init.php in Movie PHP Script 2.0 allows remote attackers to execute arbi
23RISK
open ↗Exploit-DB✓ VexDay Proof
My Mini Bill - 'orderid' SQL Injection
SQL injection vulnerability in my_orders.php in MyMiniBill allows remote authenticated users to execute arbitrary SQL co
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.