Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,302cataloged exploits
35,469CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,301GitHub PoC 14,141VulnCheck XDB 8,646Nuclei 4,289Metasploit 3,474✓ verified onlyrecentpopularrisk
24,451 exploits
Exploit-DB✓ VexDay Proof
8E6 R3000 Internet Filter 2.0.5.33 - URI SecURIty Bypass
8e6 R3000 Internet Filter 2.0.05.33, and other versions before 2.0.11, allows remote attackers to bypass intended restri
23RISK
open ↗Exploit-DB✓ VexDay Proof
2WIRE Routers - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in /xslt in 2wire 1701HG, 1800HW, and 2071 Gateway routers, with 3.17.5,
23RISK
open ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Peter's Math Anti-Spam 0.1.6 - Audio CAPTCHA Security Bypass
Peter's Math Anti-Spam Spinoff plugin for WordPress generates audio CAPTCHA clips by concatenating static audio files wi
23RISK
open ↗Exploit-DB✓ VexDay Proof
Article Dashboard - '/admin/login.php' Multiple SQL Injections
SQL injection vulnerability in admin/login.php in Article Dashboard allows remote attackers to execute arbitrary SQL com
23RISK
open ↗Exploit-DB✓ VexDay Proof
Fortinet Fortigate - CRLF Characters URL Filtering Bypass
Fortinet FortiGuard Fortinet FortiGate-1000 3.00 build 040075,070111 allows remote attackers to bypass URL filtering via
23RISK
open ↗Exploit-DB✓ VexDay Proof
F5 BIG-IP 9.4.3 - 'SearchString' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in the Search function in the web management interface in F5 BIG-IP
23RISK
open ↗Exploit-DB✓ VexDay Proof
pMachine Pro 2.4.1 - Multiple Cross-Site Scripting Vulnerabilities
Cross-site scripting (XSS) vulnerability in pm/language/spanish/preferences.php in PMachine Pro 2.4.1 allows remote atta
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHP Running Management 1.0.2 - 'index.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in PHP Running Management (phpRunMan) before 1.0.3 allows remote a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple Safari 2.0.4 - KHTML WebKit Remote Denial of Service
KHTML WebKit as used in Apple Safari 2.x allows remote attackers to cause a denial of service (browser crash) via a craf
23RISK
open ↗Exploit-DB✓ VexDay Proof
Moodle 1.8.3 - 'install.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in install.php for Moodle 1.8.3, and possibly other versions before 1.8.4, allo
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Visual InterDev 6.0 SP6 - '.sln' Local Buffer Overflow
Buffer overflow in Microsoft Visual InterDev 6.0 (SP6) allows user-assisted attackers to execute arbitrary code via a St
28RISK
open ↗Exploit-DB✓ VexDay Proof
Qvod Player 2.1.5 - 'QvodInsert.dll' ActiveX Control Remote Buffer Overflow
Heap-based buffer overflow in QvodInsert.QvodCtrl.1 ActiveX control (QvodInsert.dll) in QVOD Player before 2.1.5 build 0
23RISK
open ↗Exploit-DB✓ VexDay Proof
Members Area System 1.7 - 'view_func.php' Remote File Inclusion
PHP remote file inclusion vulnerability in view_func.php in Member Area System (MAS) 1.7 and possibly others allows remo
23RISK
open ↗Exploit-DB✓ VexDay Proof
SunOS 5.10 - Remote ICMP Kernel Crash
Unspecified vulnerability in Sun Solaris 10 before 20070130 allows remote attackers to cause a denial of service (system
23RISK
open ↗Exploit-DB✓ VexDay Proof
ID-Commerce 2.0 - 'liste.php' SQL Injection
SQL injection vulnerability in liste.php in ID-Commerce 2.0 and earlier allows remote attackers to execute arbitrary SQL
23RISK
open ↗Exploit-DB✓ VexDay Proof
Oracle Database 10 g - XML DB xdb.xdb_pitrig_pkg Package PITRIG_TRUNCATE Function Overflow
Unspecified vulnerability in the XML DB component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 has unkn
28RISK
open ↗Exploit-DB✓ VexDay Proof
Sun Java System Identity Manager 6.0/7.0/7.1 - '/idm/login.jsp' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Sun Java System Identity Manager 6.0/7.0/7.1 - '/idm/account/findForSelect.jsp?resultsForm' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Sun Java System Identity Manager 6.0/7.0/7.1 - '/idm/user/main.jsp?activeControl' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.
23RISK
open ↗Exploit-DB✓ VexDay Proof
Sun Java System Identity Manager 6.0/7.0/7.1 - '/idm/help/index.jsp?helpUrl' Remote Frame Injection
/idm/help/index.jsp in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allows remote attackers to inj
23RISK
open ↗Exploit-DB✓ VexDay Proof
Xine-Lib 1.1.9 - 'rmff_dump_cont()' Remote Heap Buffer Overflow (PoC)
Heap-based buffer overflow in the rmff_dump_cont function in input/libreal/rmff.c in xine-lib 1.1.9 and earlier allows r
28RISK
open ↗Exploit-DB✓ VexDay Proof
Omegasoft Insel 7 - Authentication Bypass / User Enumeration
OMEGA (aka Omegasoft) INterneSErvicesLosungen (INSEL) 7 supports authentication with a cookie that lacks a shared secret
23RISK
open ↗Exploit-DB✓ VexDay Proof
Xtacacsd 4.1.2 - 'report()' Remote Buffer Overflow (Metasploit)
Buffer overflow in the report function in xtacacsd 4.1.2 and earlier allows remote attackers to execute arbitrary code v
43RISK
open ↗Exploit-DB✓ VexDay Proof
IceWarp Mail Server 9.1.1 - '/admin/index.html' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in admin/index.html in Merak IceWarp Mail Server allows remote attackers to inj
23RISK
open ↗Exploit-DB✓ VexDay Proof
SysHotel On Line System - 'index.php' Local File Inclusion
Absolute path traversal vulnerability in index.php in Sys-Hotel on Line System allows remote attackers to read arbitrary
23RISK
open ↗Exploit-DB
Creative Ensoniq PCI ES1371 WDM Driver 5.1.3612 - Local Privilege Escalation
CreativeLabs es1371mp.sys 5.1.3612.0 WDM audio driver, as used in Ensoniq PCI 1371 sound cards and when running on Windo
23RISK
open ↗Exploit-DB✓ VexDay Proof
eTicket 1.5.5.2 - 'view.php?s' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in view.php in eTicket 1.5.5.2 allows remote attackers to inject arbitrary web
23RISK
open ↗Exploit-DB✓ VexDay Proof
eTicket 1.5.5.2 - 'search.php' Multiple SQL Injections
Multiple SQL injection vulnerabilities in eTicket 1.5.5.2 allow remote authenticated users to execute arbitrary SQL comm
23RISK
open ↗Exploit-DB✓ VexDay Proof
eTicket 1.5.5.2 - 'admin.php' Multiple SQL Injections
Multiple SQL injection vulnerabilities in eTicket 1.5.5.2 allow remote authenticated users to execute arbitrary SQL comm
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.