Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,299cataloged exploits
35,469CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,301GitHub PoC 14,138VulnCheck XDB 8,646Nuclei 4,289Metasploit 3,474✓ verified onlyrecentpopularrisk
24,451 exploits
Exploit-DB✓ VexDay Proof
Google Android Web Browser - '.GIF' File Heap Buffer Overflow
Heap-based buffer overflow in the GIF library in the WebKit framework for Google Android SDK m3-rc37a and earlier allows
23RISK
open ↗Exploit-DB✓ VexDay Proof
Google Android Web Browser - '.BMP' File Integer Overflow
Integer overflow in the BMP::readFromStream method in the libsgl.so library in Google Android SDK m3-rc37a and earlier,
23RISK
open ↗Exploit-DB✓ VexDay Proof
TorrentTrader 1.08 - 'msg' HTML Injection
Cross-site scripting (XSS) vulnerability in account-inbox.php in TorrentTrader Classic 1.08 allows remote attackers to i
23RISK
open ↗Exploit-DB✓ VexDay Proof
MiniWebsvr 0.0.9a - Remote Directory Traversal
Directory traversal vulnerability in Nickolas Grigoriadis Mini Web server (MiniWebsvr) 0.0.6 allows remote attackers to
23RISK
open ↗Exploit-DB✓ VexDay Proof
KC Wiki 1.0 - '/minimal/wiki.php?page' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in KCWiki 1.0 allow remote attackers to execute arbitrary PHP code vi
23RISK
open ↗Exploit-DB✓ VexDay Proof
Borland VisiBroker Smart Agent 08.00.00.C1.03 - Multiple Remote Vulnerabilities
Integer overflow in osagent.exe in Borland VisiBroker Smart Agent 08.00.00.C1.03 and earlier allows remote attackers to
28RISK
open ↗Exploit-DB✓ VexDay Proof
KC Wiki 1.0 - '/simplest/wiki.php?page' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in KCWiki 1.0 allow remote attackers to execute arbitrary PHP code vi
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHP-Nuke Johannes Hass 'Gaestebuch 2.2 Module - 'id' SQL Injection
SQL injection vulnerability in the Johannes Hass gaestebuch 2.2 module for PHP-Nuke allows remote attackers to execute a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Simple PHP Scripts Gallery 0.x - 'index.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in Simple PHP Scripts gallery 0.1, 0.3, and 0.4 allows remote atta
23RISK
open ↗Exploit-DB✓ VexDay Proof
Centreon 1.4.2.3 - 'index.php' Local File Inclusion
Directory traversal vulnerability in include/doc/index.php in Centreon 1.4.2.3 and earlier allows remote attackers to re
23RISK
open ↗Exploit-DB✓ VexDay Proof
NetOffice Dwins 1.3 - Authentication Bypass / Arbitrary File Upload
includes/library.php in netOffice Dwins 1.3 p2 compares the demoSession variable to the 'true' string literal instead of
28RISK
open ↗Exploit-DB✓ VexDay Proof
PHPMyTourney 2 - '/tourney/index.php' Remote File Inclusion
PHP remote file inclusion vulnerability in tourney/index.php in phpMyTourney 2 allows remote attackers to execute arbitr
23RISK
open ↗Exploit-DB✓ VexDay Proof
Juniper Networks Secure Access 2000 Web - Root Full Path Disclosure
Juniper Networks Secure Access 2000 5.5 R1 (build 11711) allows remote attackers to obtain sensitive information via a d
23RISK
open ↗Exploit-DB✓ VexDay Proof
XRms 1.99.2 - CRM 'msg' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in admin/users/self.php in XRMS CRM allows remote attackers to inject arbitrary
23RISK
open ↗Exploit-DB✓ VexDay Proof
Flicks Software AuthentiX 6.3b1 - 'Username' Multiple Cross-Site Scripting Vulnerabilities
Cross-site scripting (XSS) vulnerability in editUser.asp in AuthentiX 6.3b1 Trial allows remote attackers to inject arbi
23RISK
open ↗Exploit-DB✓ VexDay Proof
Juniper Networks Secure Access 2000 - 'rdremediate.cgi' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in dana-na/auth/rdremediate.cgi in Juniper Networks Secure Access 2000 5.5 R1 b
23RISK
open ↗Exploit-DB✓ VexDay Proof
Trend Micro OfficeScan - Buffer Overflow (Denial of Service) (PoC)
Stack-based buffer overflow in Trend Micro OfficeScan Corporate Edition 8.0 Patch 2 build 1189 and earlier, and 7.3 Patc
50RISK
open ↗Exploit-DB✓ VexDay Proof
Ghostscript 8.0.1/8.15 - 'zseticcspace()' Remote Buffer Overflow
Stack-based buffer overflow in the zseticcspace function in zicc.c in Ghostscript 8.61 and earlier allows remote attacke
28RISK
open ↗Exploit-DB✓ VexDay Proof
Nortel UNIStim IP Phone - Remote Ping Denial of Service
Nortel Networks UNIStim IP Phone 0604DAS allows remote attackers to cause a denial of service (crash) via a long ping pa
23RISK
open ↗Exploit-DB✓ VexDay Proof
Surgemail and WebMail 3.0 - 'Page' Remote Format String
Format string vulnerability in webmail.exe in NetWin SurgeMail 38k4 and earlier and beta 39a, and WebMail 3.1s and earli
23RISK
open ↗Exploit-DB✓ VexDay Proof
Softbiz Jokes and Funny Pictures Script - 'sbcat_id' SQL Injection
SQL injection vulnerability in index.php in Softbiz Jokes & Funny Pics Script allows remote attackers to execute arbitra
23RISK
open ↗Exploit-DB✓ VexDay Proof
Surgemail 3.0 - Real CGI executables Remote Buffer Overflow
Stack-based buffer overflow in the _lib_spawn_user_getpid function in (1) swatch.exe and (2) surgemail.exe in NetWin Sur
23RISK
open ↗Exploit-DB✓ VexDay Proof
MiniNuke 2.1 - 'uid' SQL Injection
SQL injection vulnerability in members.asp in Mini-NUKE Freehost 2.3 allows remote attackers to execute arbitrary SQL co
23RISK
open ↗Exploit-DB✓ VexDay Proof
Alkacon OpenCMS 7.0.3 - 'tree_files.jsp' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the file tree navigation function in system/workplace/views/explorer/tree_fi
23RISK
open ↗Exploit-DB✓ VexDay Proof
Packeteer PacketShaper and PolicyCenter 8.2.2 - 'FILELIST' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the file listing function in the web management interface in Packeteer Packe
23RISK
open ↗Exploit-DB✓ VexDay Proof
Galore Simple Shop 3.1 - 'section' SQL Injection
SQL injection vulnerability in the Simple Shop Galore (com_simpleshop) component for Joomla! allows remote attackers to
23RISK
open ↗Exploit-DB✓ VexDay Proof
SurgeFTP 2.3a2 - 'Content-Length' Null Pointer Denial of Service
The administration web interface in NetWin SurgeFTP 2.3a2 and earlier allows remote attackers to cause a denial of servi
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHP-Nuke Recipe Module 1.3 - 'recipeid' SQL Injection
SQL injection vulnerability in index.php in the Recipes module 1.3, 1.4, and possibly other versions for PHP-Nuke allows
23RISK
open ↗Exploit-DB✓ VexDay Proof
phpQLAdmin 2.2.7 - Multiple Remote File Inclusions
The write_array_file function in utils/include.pl in GForge 4.5.14 updates configuration files by truncating them to zer
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHP-Nuke Downloads Module - 'sid' SQL Injection
SQL injection vulnerability in the Downloads module in Php-Nuke 6.x through 7.2 allows remote attackers to execute arbit
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.