Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,351cataloged exploits
35,509CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,332GitHub PoC 14,159VulnCheck XDB 8,646Nuclei 4,289Metasploit 3,474✓ verified onlyrecentpopularrisk
24,451 exploits
Exploit-DB✓ VexDay Proof
Pay Roll Time Sheet and Punch Card Application With Web UI - 'login.asp' SQL Injection
SQL injection vulnerability in login.asp in CodeWidgets Pay Roll - Time Sheet and Punch Card Application With Web Interf
23RISK
open ↗Exploit-DB✓ VexDay Proof
Real Estate Listing Website Application Template Login Dialog - SQL Injection
SQL injection vulnerability in the login script in Real Estate listing website application template, when logging in as
23RISK
open ↗Exploit-DB✓ VexDay Proof
Berthanas Ziyaretci Defteri 2.0 - 'Yonetici.asp' SQL Injection
Multiple SQL injection vulnerabilities in yonetici.asp in Berthanas Ziyaretci Defteri 2.0 allow remote attackers to exec
23RISK
open ↗Exploit-DB✓ VexDay Proof
Online Store Application Template - 'Sign_In.aspx' SQL Injection
SQL injection vulnerability in sign_in.aspx in WebStore (Online Store Application Template) allows remote attackers to e
23RISK
open ↗Exploit-DB✓ VexDay Proof
Fail2ban 0.8 - Remote Denial of Service
fail2ban 0.8 and earlier does not properly parse sshd log files, which allows remote attackers to add arbitrary hosts to
23RISK
open ↗Exploit-DB✓ VexDay Proof
phpCoupon - Remote Payment Bypass
user.php in the Billing Control Panel in phpCoupon allows remote authenticated users to obtain Premium Member status, an
23RISK
open ↗Exploit-DB✓ VexDay Proof
IBM AIX 5.3 SP6 - FTP 'gets()' Local Privilege Escalation
Buffer overflow in the ftp client in IBM AIX 5.3 SP6 and 5.2.0 allows local users to execute arbitrary code via unspecif
23RISK
open ↗Exploit-DB✓ VexDay Proof
IBM AIX 5.3 SP6 - Capture Terminal Sequence Privilege Escalation
Stack-based buffer overflow in capture in IBM AIX 5.3 SP6 and 5.2.0 allows remote attackers to execute arbitrary code vi
23RISK
open ↗Exploit-DB✓ VexDay Proof
Bandersnatch 0.4 - Multiple Input Validation Vulnerabilities
Multiple SQL injection vulnerabilities in Bandersnatch 0.4 allow remote attackers to execute arbitrary SQL commands via
23RISK
open ↗Exploit-DB✓ VexDay Proof
Nessus Vulnerability Scanner 3.0.6 - ActiveX Command Execution
Directory traversal vulnerability in a certain ActiveX control in Nessus Vulnerability Scanner 3.0.6 allows remote attac
23RISK
open ↗Exploit-DB✓ VexDay Proof
IBM AIX 5.3 SP6 - 'pioout' Arbitrary Library Loading Privilege Escalation
pioout in IBM AIX 5.3 SP6 allows local users to execute arbitrary code by specifying a malicious library with the -R (Pa
23RISK
open ↗Exploit-DB✓ VexDay Proof
Nessus Vulnerability Scanner 3.0.6 - ActiveX Command Execution
The SCANCTRL.ScanCtrlCtrl.1 ActiveX control in scan.dll in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to
23RISK
open ↗Exploit-DB✓ VexDay Proof
Metyus Forum Portal 1.0 - 'Philboard_Forum.asp' SQL Injection
SQL injection vulnerability in philboard_forum.asp in Metyus Forum Portal 1.0 allows remote attackers to execute arbitra
23RISK
open ↗Exploit-DB✓ VexDay Proof
BSM Store Dependent Forums 1.02 - 'Username' SQL Injection
SQL injection vulnerability in BSM Store Dependent Forums 1.02 allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗Exploit-DB✓ VexDay Proof
WordPress Plugin WP-FeedStats 2.1 - HTML Injection
Multiple cross-site scripting (XSS) vulnerabilities in the WP-FeedStats before 2.4 plugin for WordPress allow remote att
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Explorer - '.png' Image Local Denial of Service
Microsoft Windows Explorer (explorer.exe) allows user-assisted remote attackers to cause a denial of service (CPU consum
28RISK
open ↗Exploit-DB✓ VexDay Proof
IPSwitch IMail Server 2006 9.10 - Subscribe Remote Overflow
Multiple buffer overflows in Ipswitch IMail Server 2006 before 2006.21 (1) allow remote attackers to execute arbitrary c
28RISK
open ↗Exploit-DB✓ VexDay Proof
Nukedit 4.9.x - 'login.asp' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in utilities/login.asp in nukedit 4.9.7 and earlier allows remote attackers to
23RISK
open ↗Exploit-DB✓ VexDay Proof
T1lib - 'intT1_Env_GetCompletePath' Buffer Overflow (PoC)
Buffer overflow in the intT1_EnvGetCompletePath function in lib/t1lib/t1env.c in t1lib 5.1.1 allows context-dependent at
28RISK
open ↗Exploit-DB✓ VexDay Proof
IBM AIX 5.2/5.3 - Capture Command Local Stack Buffer Overflow
Stack-based buffer overflow in capture in IBM AIX 5.3 SP6 and 5.2.0 allows remote attackers to execute arbitrary code vi
23RISK
open ↗Exploit-DB✓ VexDay Proof
Vikingboard 0.1.2 - 'forum.php' Information Disclosure
Vikingboard 0.1.2 allows remote attackers to obtain sensitive information via the debug parameter to (1) forum.php, (2)
23RISK
open ↗Exploit-DB✓ VexDay Proof
iFoto 1.0 - 'index.php' Directory Traversal
Directory traversal vulnerability in index.php in iFoto 1.0.1 and earlier allows remote attackers to list arbitrary dire
23RISK
open ↗Exploit-DB✓ VexDay Proof
W1L3D4 philboard 0.3 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in W1L3D4_aramasonuc.asp in W1L3D4 Philboard 0.3 allows remote attackers to inj
23RISK
open ↗Exploit-DB✓ VexDay Proof
Multiple Browsers - URI Handlers Command Injection
Mozilla Firefox before 2.0.0.6, Thunderbird before 1.5.0.13 and 2.x before 2.0.0.6, and SeaMonkey before 1.1.4 allow rem
23RISK
open ↗Exploit-DB✓ VexDay Proof
Vikingboard 0.1.2 - 'cp.php' Information Disclosure
Vikingboard 0.1.2 allows remote attackers to obtain sensitive information via the debug parameter to (1) forum.php, (2)
23RISK
open ↗Exploit-DB✓ VexDay Proof
Vikingboard 0.1.2 - 'topic.php' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Vikingboard 0.1.2 allow remote attackers to inject arbitrary web
23RISK
open ↗Exploit-DB✓ VexDay Proof
Vikingboard 0.1.2 - 'user.php' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Vikingboard 0.1.2 allow remote attackers to inject arbitrary web
23RISK
open ↗Exploit-DB✓ VexDay Proof
Vikingboard 0.1.2 - 'post.php' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Vikingboard 0.1.2 allow remote attackers to inject arbitrary web
23RISK
open ↗Exploit-DB✓ VexDay Proof
IPSwitch IMail Server 2006 - SEARCH Remote Stack Overflow
Multiple buffer overflows in the IMAP service (imapd32.exe) in Ipswitch IMail Server 2006 before 2006.21 allow remote au
60RISK
open ↗Exploit-DB✓ VexDay Proof
Vikingboard 0.1.2 - 'cp.php' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Vikingboard 0.1.2 allow remote attackers to inject arbitrary web
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.