Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,401cataloged exploits
35,511CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,332GitHub PoC 14,209VulnCheck XDB 8,646Nuclei 4,289Metasploit 3,474✓ verified onlyrecentpopularrisk
24,451 exploits
Exploit-DB✓ VexDay Proof
LeadTools Raster OCR Document Object Library - Memory Corruption
Buffer overflow in a certain ActiveX control in LEAD Technologies LEADTOOLS Raster OCR Document Object Library (ltrdc14e
23RISK
open ↗Exploit-DB✓ VexDay Proof
Zenturi ProgramChecker - ActiveX File Download/Overwrite
A certain ActiveX control in sasatl.dll in Zenturi ProgramChecker allows remote attackers to download arbitrary files to
23RISK
open ↗Exploit-DB✓ VexDay Proof
LeadTools Raster ISIS Object 'LTRIS14e.DLL 14.5.0.44' - Remote Buffer Overflow (PoC)
Heap-based buffer overflow in a certain ActiveX control in LEADTOOLS LEAD Raster ISIS Object (LTRIS14e.DLL) 14.5.0.44 al
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX < 2007-005 - 'vpnd' Local Privilege Escalation
Format string vulnerability in the VPN daemon (vpnd) in Apple Mac OS X 10.3.9 and 10.4.9 allows local users to execute a
23RISK
open ↗Exploit-DB✓ VexDay Proof
UebiMiau 2.7.10 - '/demo/pop3/error.php?selected_theme' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Uebimiau Webmail allow remote attackers to inject arbitrary web s
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX 10.4.9 - VPND Local Format String
Format string vulnerability in the VPN daemon (vpnd) in Apple Mac OS X 10.3.9 and 10.4.9 allows local users to execute a
23RISK
open ↗Exploit-DB✓ VexDay Proof
UebiMiau 2.7.10 - '/demo/pop3/error.php' Multiple Full Path Disclosures
Uebimiau Webmail allows remote attackers to obtain sensitive information via a request to demo/pop3/error.php with an in
23RISK
open ↗Exploit-DB✓ VexDay Proof
British TeleCommunications Consumer Webhelper 2.0.0.7 - Multiple Buffer Overflow Vulnerabilities
Multiple buffer overflows in the British Telecommunications Consumer webhelper ActiveX control before 2.0.0.8 in btwebco
23RISK
open ↗Exploit-DB✓ VexDay Proof
CPCommerce 1.1 - 'manufacturer.php' SQL Injection
SQL injection vulnerability in manufacturer.php in cpCommerce before 1.1.0 allows remote attackers to execute arbitrary
23RISK
open ↗Exploit-DB✓ VexDay Proof
DGNews 1.5.1/2.1 - 'news.php' SQL Injection
SQL injection vulnerability in news.php in DGNews 2.1 allows remote attackers to execute arbitrary SQL commands via the
23RISK
open ↗Exploit-DB✓ VexDay Proof
DGNews 2.1 - 'NewsID' SQL Injection
SQL injection vulnerability in news.php in DGNews 2.1 allows remote attackers to execute arbitrary SQL commands via the
23RISK
open ↗Exploit-DB✓ VexDay Proof
UltraISO 8.6.2.2011 - '.cue/'.bin' Local Buffer Overflow (2)
Stack-based buffer overflow in UltraISO 8.6.2.2011 and earlier allows user-assisted remote attackers to execute arbitrar
50RISK
open ↗Exploit-DB✓ VexDay Proof
Mutt 1.4.2 - Mutt_Gecos_Name Function Local Buffer Overflow
Buffer overflow in Mutt 1.4.2 might allow local users to execute arbitrary code via "&" characters in the GECOS field, w
23RISK
open ↗Exploit-DB✓ VexDay Proof
DGNews 2.1 - 'footer.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in footer.php in DGNews 2.1 allows remote attackers to inject arbitrary web scr
23RISK
open ↗Exploit-DB✓ VexDay Proof
UltraISO 8.6.2.2011 - '.cue/'.bin' Local Buffer Overflow (1)
Stack-based buffer overflow in UltraISO 8.6.2.2011 and earlier allows user-assisted remote attackers to execute arbitrar
50RISK
open ↗Exploit-DB✓ VexDay Proof
Apache 2.0.58 mod_rewrite (Windows 2003) - Remote Overflow
Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and o
60RISK
open ↗Exploit-DB✓ VexDay Proof
BoastMachine 3.1 - 'index.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in BoastMachine allows remote attackers to inject arbitrary web sc
23RISK
open ↗Exploit-DB✓ VexDay Proof
GNUTurk - 'Mods.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in mods.php in GTP GNUTurk Portal System 3G allows remote attackers to inject a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX 10.4.8 - pppd Plugin Loading Privilege Escalation
The PPP daemon (pppd) in Apple Mac OS X 10.4.8 checks ownership of the stdin file descriptor to determine if the invoker
23RISK
open ↗Exploit-DB✓ VexDay Proof
Ruby on Rails 1.2.3 To_JSON - Script Injection
Cross-site scripting (XSS) vulnerability in the to_json (ActiveRecord::Base#to_json) function in Ruby on Rails before ed
23RISK
open ↗Exploit-DB✓ VexDay Proof
Pligg CMS 9.5 - Reset Forgotten Password Security Bypass
login.php in Pligg CMS 9.5 uses a guessable confirmation code when resetting a forgotten password, which allows remote a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Dart Communications PowerTCP - ZIP Compression Remote Buffer Overflow
Buffer overflow in the Dart Communications PowerTCP ZIP Compression ActiveX control in DartZip.dll 1.8.5.3, when Interne
23RISK
open ↗Exploit-DB✓ VexDay Proof
phpPgAdmin 4.1.1 - 'Redirect.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in phpPgAdmin 3.5 to 4.1.1, and possibly 4.1.2, allows remote attackers to inje
43RISK
open ↗Exploit-DB✓ VexDay Proof
Dart Communications PowerTCP - Service Control Remote Buffer Overflow
Buffer overflow in the Dart Communications PowerTCP ZIP Compression ActiveX control in DartZip.dll 1.8.5.3, when Interne
23RISK
open ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.x - VFat Compat IOCTLS Local Denial of Service
The VFAT compat ioctls in the Linux kernel before 2.6.21.2, when run on a 64-bit system, allow local users to corrupt a
23RISK
open ↗Exploit-DB✓ VexDay Proof
ASP-Nuke 2.0.7 - 'news.asp' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in news.asp in ASP-Nuke 2.0.7 allows remote attackers to inject arbitrary web s
23RISK
open ↗Exploit-DB✓ VexDay Proof
LeadTools Raster Dialog File Object - ActiveX Remote Buffer Overflow (PoC)
Buffer overflow in a certain ActiveX control in LTRDF14e.DLL 14.5.0.44 in LeadTools Raster Dialog File Object allows rem
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Office 2000 (OUACTRL.OCX 1.0.1.9) - Remote Denial of Service
Buffer overflow in the HelpPopup method in the Microsoft Office 2000 Controllo UA di Microsoft Office ActiveX control (O
28RISK
open ↗Exploit-DB✓ VexDay Proof
phpPgAdmin 4.1.1 - 'SQLEDIT.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in sqledit.php in phpPgAdmin 4.1.1 allows remote attackers to inject arbitrary
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple Safari 2.0.4 - Cross-Domain Browser Location Information Disclosure
Cross-domain vulnerability in Apple Safari 2.0.4 allows remote attackers to access restricted information from other dom
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.