Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,302cataloged exploits
35,469CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,301GitHub PoC 14,141VulnCheck XDB 8,646Nuclei 4,289Metasploit 3,474✓ verified onlyrecentpopularrisk
24,451 exploits
Exploit-DB✓ VexDay Proof
BlueCat Networks Adonis 5.0.2.8 - CLI Privilege Escalation
The Command Line Interface (CLI), aka Adonis Administration Console, on the BlueCat Networks Adonis DNS/DHCP appliance 5
23RISK
open ↗Exploit-DB✓ VexDay Proof
Sun Java Runtime Environment 1.4.2 - Font Parsing Privilege Escalation
Unspecified vulnerability in the font parsing implementation in Sun JDK and JRE 5.0 Update 9 and earlier, and SDK and JR
23RISK
open ↗Exploit-DB✓ VexDay Proof
Yahoo! Messenger 8.1 - 'KDU_V32M.DLL' Remote Denial of Service
Heap-based buffer overflow in Kakadu kdu_v32m.dll in Yahoo! Messenger 8.1.0.413 allows remote attackers to cause a denia
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft XML Core Services 6.0 - SubstringData Integer Overflow
Microsoft XML Core Services (MSXML) 3.0 through 6.0 allows remote attackers to execute arbitrary code via the substringD
35RISK
open ↗Exploit-DB✓ VexDay Proof
Apache Tomcat 6.0.13 - Host Manager Servlet Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the Host Manager Servlet for Apache Tomcat 6.0.0 to 6.0.13 and 5.5.0 to 5.5.
35RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5.0.1 - Vector Markup Language 'VGX.dll' Remote Buffer Overflow
Integer underflow in the CDownloadSink class code in the Vector Markup Language (VML) component (VGX.DLL), as used in In
35RISK
open ↗Exploit-DB✓ VexDay Proof
Apache Tomcat 6.0.13 - Insecure Cookie Handling Quote Delimiter Session ID Disclosure
Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 treats single quotes
35RISK
open ↗Exploit-DB✓ VexDay Proof
Zoidcom 0.6.x - Malformed Packet Denial of Service
Zoidcom 0.6.7 and earlier allows remote attackers to cause a denial of service (application crash) via a JOIN packet (ak
23RISK
open ↗Exploit-DB✓ VexDay Proof
WordPress Core 1.0.7 - 'Pool index.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in the Pool 1.0.7 theme for WordPress allows remote attackers to i
23RISK
open ↗Exploit-DB✓ VexDay Proof
OWASP Stinger - Filter Bypass
OWASP Stinger before 2.5 allows remote attackers to bypass input validation routines by using multipart encoded requests
23RISK
open ↗Exploit-DB✓ VexDay Proof
Savant Web Server 3.1 - GET Universal Remote Overflow
Buffer overflow in Savant Web Server 3.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP G
50RISK
open ↗Exploit-DB✓ VexDay Proof
Lib2 PHP Library 0.2 - 'My_Statistics.php' Remote File Inclusion
PHP remote file inclusion vulnerability in adm/my_statistics.php in Omnistar Lib2 PHP 0.2 allows remote attackers to exe
23RISK
open ↗Exploit-DB✓ VexDay Proof
Haudenschilt Family Connections 0.8 - 'index.php' Authentication Bypass
index.php in Ryan Haudenschilt Family Connections (FCMS) before 0.9 allows remote attackers to access an arbitrary accou
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHP-Stats 0.1.9.2 - 'WhoIs.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in whois.php in Php-stats 0.1.9.2 allows remote attackers to inject arbitrary w
23RISK
open ↗Exploit-DB✓ VexDay Proof
ZYXEL ZyWALL 2 3.62 - '/Forms/General_1?sysSystemName' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Forms/General_1 in the management interface in ZyNOS firmware 3.62(WK.6) on
23RISK
open ↗Exploit-DB✓ VexDay Proof
File Uploader 1.1 - 'datei.php?config[root_ordner]' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in File Uploader 1.1 allow remote attackers to execute arbitrary PHP
23RISK
open ↗Exploit-DB✓ VexDay Proof
File Uploader 1.1 - 'index.php?config[root_ordner]' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in File Uploader 1.1 allow remote attackers to execute arbitrary PHP
23RISK
open ↗Exploit-DB✓ VexDay Proof
Mapos-Scripts.de Gastebuch 1.5 - 'index.php' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in Gaestebuch 1.5 allows remote attackers to execute arbitrary PHP
23RISK
open ↗Exploit-DB✓ VexDay Proof
Web News 1.1 - 'index.php?config[root_ordner]' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Web News 1.1 allow remote attackers to execute arbitrary PHP code
23RISK
open ↗Exploit-DB✓ VexDay Proof
Web News 1.1 - 'feed.php?config[root_ordner]' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Web News 1.1 allow remote attackers to execute arbitrary PHP code
23RISK
open ↗Exploit-DB✓ VexDay Proof
Bilder Galerie 1.0 - 'index.php' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Mapos Bilder Galerie 1.0 allow remote attackers to execute arbitra
23RISK
open ↗Exploit-DB✓ VexDay Proof
Generic Software Wrappers Toolkit 1.6.3 (GSWTK) - Race Condition Privilege Escalation
Multiple race conditions in certain system call wrappers in Generic Software Wrappers Toolkit (GSWTK) allow local users
23RISK
open ↗Exploit-DB✓ VexDay Proof
Systrace - Multiple System Call Wrappers Concurrency Vulnerabilities
Multiple race conditions in the (1) Sudo monitor mode and (2) Sysjail policies in Systrace on NetBSD and OpenBSD allow l
23RISK
open ↗Exploit-DB✓ VexDay Proof
Web News 1.1 - 'news.php?config[root_ordner]' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Web News 1.1 allow remote attackers to execute arbitrary PHP code
23RISK
open ↗Exploit-DB✓ VexDay Proof
Shoutbox 1.0 - 'Shoutbox.php' Remote File Inclusion
PHP remote file inclusion vulnerability in shoutbox.php in Shoutbox 1.0 allows remote attackers to execute arbitrary PHP
23RISK
open ↗Exploit-DB✓ VexDay Proof
Cisco IOS Next Hop Resolution Protocol (NHRP) - Denial of Service
Buffer overflow in the Next Hop Resolution Protocol (NHRP) functionality in Cisco IOS 12.0 through 12.4 allows remote at
28RISK
open ↗Exploit-DB✓ VexDay Proof
PHP 5.2.3 - 'snmpget()' object id Local Buffer Overflow (EDI)
Buffer overflow in the snmpget function in the snmp extension in PHP 5.2.3 and earlier, including PHP 4.4.6 and probably
28RISK
open ↗Exploit-DB✓ VexDay Proof
Coppermine Photo Gallery 1.3/1.4 - 'YABBSE.INC.php' Remote File Inclusion
PHP remote file inclusion vulnerability in bridge/yabbse.inc.php in Coppermine Photo Gallery (CPG) 1.3.1 allows remote a
23RISK
open ↗Exploit-DB✓ VexDay Proof
PHP mSQL (msql_connect) - Local Buffer Overflow
Buffer overflow in the mSQL extension in PHP 5.2.3 allows context-dependent attackers to execute arbitrary code via a lo
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Media Player 11 - AU Divide-by-Zero Denial of Service
Microsoft Windows Media Player 11 (wmplayer.exe) allows user-assisted remote attackers to cause a denial of service (app
28RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.