Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,231cataloged exploits
35,420CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,266GitHub PoC 14,131VulnCheck XDB 8,635Nuclei 4,274Metasploit 3,474✓ verified onlyrecentpopularrisk
24,451 exploits
Exploit-DB✓ VexDay Proof
Novell Groupwise Messenger 2.0 Client - Buffer Overflow
Multiple stack-based buffer overflows in Novell GroupWise Messenger (GWIM) Client before 2.0.3 HP1 for Windows allow rem
50RISK
open ↗Exploit-DB✓ VexDay Proof
QNX Neutrino RTOS 6.3 - 'phgrafx' Local Buffer Overflow
Stack-based buffer overflow in phgrafx in QNX Momentics (aka RTOS) 6.3.2 and earlier allows local users to gain privileg
23RISK
open ↗Exploit-DB✓ VexDay Proof
FaName 1.0 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Farsi Script (aka FaScript) FaName 1.0 allow remote attackers to
23RISK
open ↗Exploit-DB✓ VexDay Proof
RSS-aggregator 1.0 - Authentication Bypass
RSS-aggregator 1.0 does not require administrative authentication for the admin/fonctions/ directory, which allows remot
23RISK
open ↗Exploit-DB✓ VexDay Proof
Wireshark 1.0.0 - Multiple Denial of Service Vulnerabilities
The syslog dissector in Wireshark (formerly Ethereal) 1.0.0 allows remote attackers to cause a denial of service (applic
23RISK
open ↗Exploit-DB✓ VexDay Proof
OpenLDAP 2.3.41 - BER Decoding Remote Denial of Service
liblber/io.c in OpenLDAP 2.2.4 to 2.4.10 allows remote attackers to cause a denial of service (program termination) via
28RISK
open ↗Exploit-DB✓ VexDay Proof
RSS-aggregator 1.0 - 'IdTag' SQL Injection
Multiple SQL injection vulnerabilities in RSS-aggregator 1.0 allow remote attackers to execute arbitrary SQL commands vi
23RISK
open ↗Exploit-DB✓ VexDay Proof
IBM Tivoli Directory Server 6.1.x - Adding 'ibm-globalAdminGroup' Entry Denial of Service
Double free vulnerability in IBM Tivoli Directory Server (TDS) 6.1.0.0 through 6.1.0.15 allows remote authenticated admi
23RISK
open ↗Exploit-DB✓ VexDay Proof
Surgemail 39e-1 - (Authenticated) IMAP Remote Buffer Overflow (Denial of Service) (PoC)
Unspecified vulnerability in the IMAP service in NetWin SurgeMail before 3.9g2 allows remote attackers to cause a denial
23RISK
open ↗Exploit-DB✓ VexDay Proof
FaName 1.0 - 'page.php?name' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Farsi Script (aka FaScript) FaName 1.0 allow remote attackers to
23RISK
open ↗Exploit-DB✓ VexDay Proof
RSS-aggregator 1.0 - 'IdFlux' SQL Injection
Multiple SQL injection vulnerabilities in RSS-aggregator 1.0 allow remote attackers to execute arbitrary SQL commands vi
23RISK
open ↗Exploit-DB✓ VexDay Proof
S.T.A.L.K.E.R Shadow of Chernobyl 1.0006 - Multiple Remote Vulnerabilities
Stack-based buffer overflow in the IPureServer::_Recieve function in S.T.A.L.K.E.R.: Shadow of Chernobyl 1.0006 and earl
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 7/8 Beta 1 - Frame Location Cross Domain Security Bypass
Cross-domain vulnerability in Microsoft Internet Explorer 6 and 7 allows remote attackers to change the location propert
28RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 7/8 Beta 1 - Frame Location Cross Domain Security Bypass
Cross-domain vulnerability in Microsoft Internet Explorer 7 and 8 allows remote attackers to change the location propert
28RISK
open ↗Exploit-DB✓ VexDay Proof
AceFTP 3.80.3 - 'LIST' Directory Traversal
Directory traversal vulnerability in the FTP client in AceFTP Freeware 3.80.3 and AceFTP Pro 3.80.3 allows remote FTP se
23RISK
open ↗Exploit-DB✓ VexDay Proof
UUSee 2008 - UUUpgrade ActiveX Control 'Update' Method Arbitrary File Download
Insecure method vulnerability in the UUSee UUUpgrade ActiveX control (UUUpgrade.ocx 3.0.2.12) allows remote attackers to
23RISK
open ↗Exploit-DB✓ VexDay Proof
The Rat CMS - 'viewarticle2.php?id' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in The Rat CMS Pre-Alpha 2 allow remote attackers to inject arbitrar
23RISK
open ↗Exploit-DB✓ VexDay Proof
The Rat CMS - 'viewarticle2.php?id' SQL Injection
Multiple SQL injection vulnerabilities in The Rat CMS Pre-Alpha 2 allow remote attackers to execute arbitrary SQL comman
23RISK
open ↗Exploit-DB✓ VexDay Proof
The Rat CMS - 'viewarticle.php' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in The Rat CMS Pre-Alpha 2 allow remote attackers to inject arbitrar
23RISK
open ↗Exploit-DB✓ VexDay Proof
The Rat CMS - 'viewarticle.php?id' SQL Injection
Multiple SQL injection vulnerabilities in The Rat CMS Pre-Alpha 2 allow remote attackers to execute arbitrary SQL comman
23RISK
open ↗Exploit-DB✓ VexDay Proof
GNOME Rhythmbox 0.11.5 - '.Playlist' File Denial of Service
GNOME Rhythmbox 0.11.5 allows remote attackers to cause a denial of service (segmentation fault and crash) via a playlis
23RISK
open ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.9 < 2.6.25 (RHEL 4) - utrace and ptrace Local Denial of Service (1)
Race condition in the ptrace and utrace support in the Linux kernel 2.6.9 through 2.6.25, as used in Red Hat Enterprise
23RISK
open ↗Exploit-DB✓ VexDay Proof
5th street - 'dx8render.dll' Format String
Format string vulnerability in dx8render.dll in Snail Game (aka Suzhou Snail Electronic Company) 5th street (aka Hot Ste
23RISK
open ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.9 < 2.6.25 (RHEL 4) - utrace and ptrace Local Denial of Service (2)
Race condition in the ptrace and utrace support in the Linux kernel 2.6.9 through 2.6.25, as used in Red Hat Enterprise
23RISK
open ↗Exploit-DB✓ VexDay Proof
SunAge 1.8.1 - Multiple Denial of Service Vulnerabilities
Integer overflow in Vertex4 SunAge 1.08.1 and earlier allows remote attackers to cause a denial of service (crash) via a
23RISK
open ↗Exploit-DB✓ VexDay Proof
PEGames - Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in template2.php in PEGames allow remote attackers to inject arbitra
23RISK
open ↗Exploit-DB✓ VexDay Proof
World in Conflict 1.008 - Null Pointer Remote Denial of Service
World in Conflict (WIC) 1.008 and earlier allows remote attackers to cause a denial of service (access violation and cra
23RISK
open ↗Exploit-DB✓ VexDay Proof
Chipmunk Blog - 'archive.php' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Chipmunk Blog (Blogger) allow remote attackers to inject arbitrar
23RISK
open ↗Exploit-DB✓ VexDay Proof
Chipmunk Blog - 'photos.php' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Chipmunk Blog (Blogger) allow remote attackers to inject arbitrar
23RISK
open ↗Exploit-DB✓ VexDay Proof
Chipmunk Blog - 'members.php' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Chipmunk Blog (Blogger) allow remote attackers to inject arbitrar
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.