Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,401cataloged exploits
35,511CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,332GitHub PoC 14,209VulnCheck XDB 8,646Nuclei 4,289Metasploit 3,474✓ verified onlyrecentpopularrisk
24,451 exploits
Exploit-DB✓ VexDay Proof
Microsoft Office 2000 (OUACTRL.OCX 1.0.1.9) - Remote Denial of Service
Buffer overflow in the HelpPopup method in the Microsoft Office 2000 Controllo UA di Microsoft Office ActiveX control (O
28RISK
open ↗Exploit-DB✓ VexDay Proof
Apple Safari 2.0.4 - Cross-Domain Browser Location Information Disclosure
Cross-domain vulnerability in Apple Safari 2.0.4 allows remote attackers to access restricted information from other dom
23RISK
open ↗Exploit-DB✓ VexDay Proof
WYYS 1.0 - 'index.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in Web Icerik Yonetim Sistemi (WIYS) 1.0 allows remote attackers t
23RISK
open ↗Exploit-DB✓ VexDay Proof
LeadTools ISIS Control - 'ltisi14E.ocx 14.5.0.44' Remote Denial of Service
Heap-based buffer overflow in LEAD Technologies LEADTOOLS ISIS ActiveX Control (ltisi14E.ocx) 14.5.0.44 and earlier allo
23RISK
open ↗Exploit-DB✓ VexDay Proof
Jetbox CMS 2.1 - Login Variable Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in Jetbox CMS 2.1 allows remote attackers to inject arbitrary web
23RISK
open ↗Exploit-DB✓ VexDay Proof
KSign KSignSWAT 2.0.3.3 - ActiveX Control Remote Buffer Overflow
Multiple stack-based buffer overflows in the KSign KSignSWAT ActiveX Control (AxKSignSWAT.dll) 2.0.3.3 allow remote atta
23RISK
open ↗Exploit-DB✓ VexDay Proof
ABC Excel Parser Pro 4.0 - 'Parser_Path' Remote File Inclusion
PHP remote file inclusion vulnerability in sample/xls2mysql in ABC Excel Parser Pro 4.0 allows remote attackers to execu
23RISK
open ↗Exploit-DB✓ VexDay Proof
rdiffweb 0.3.5 - Directory Traversal
Directory traversal vulnerability in rdw_helpers.py in rdiffWeb before 0.3.5.1 allows remote attackers to read arbitrary
23RISK
open ↗Exploit-DB✓ VexDay Proof
GaliX 2.0 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in index.php in GaliX 2.0 allow remote attackers to inject arbitrary
23RISK
open ↗Exploit-DB✓ VexDay Proof
Ol BookMarks Manager 0.7.4 - SQL Injection
SQL injection vulnerability in index.php in ol'bookmarks manager 0.7.5 allows remote attackers to execute arbitrary SQL
23RISK
open ↗Exploit-DB✓ VexDay Proof
Ol BookMarks Manager 0.7.4 - 'root' Remote File Inclusion
Multiple SQL injection vulnerabilities in search.php in WoltLab Burning Board (wBB) Lite 1.0.2 pl3e allow remote attacke
23RISK
open ↗Exploit-DB✓ VexDay Proof
Ol BookMarks Manager 0.7.4 - 'root' Remote File Inclusion
SQL injection vulnerability in index.php in ol'bookmarks manager 0.7.5 allows remote attackers to execute arbitrary SQL
23RISK
open ↗Exploit-DB✓ VexDay Proof
WordPress Core 2.1.3 - 'admin-ajax.php' SQL Injection Blind Fishing
SQL injection vulnerability in wp-admin/admin-ajax.php in WordPress before 2.2 allows remote attackers to execute arbitr
23RISK
open ↗Exploit-DB✓ VexDay Proof
Ol BookMarks Manager 0.7.4 - SQL Injection
Multiple PHP remote file inclusion vulnerabilities in ol'bookmarks 0.7.4 allow remote attackers to execute arbitrary PHP
28RISK
open ↗Exploit-DB✓ VexDay Proof
Jetbox CMS 2.1 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in index.php in Jetbox CMS 2.1 allow remote attackers to execute arbitrary SQL co
23RISK
open ↗Exploit-DB✓ VexDay Proof
Ol BookMarks Manager 0.7.4 - 'root' Remote File Inclusion
SQL injection vulnerability in read/index.php in ol'bookmarks 0.7.4 allows remote attackers to execute arbitrary SQL com
23RISK
open ↗Exploit-DB✓ VexDay Proof
Pegasus ImagN - ActiveX Control Remote Buffer Overflow
Multiple stack-based buffer overflows in the Pegasus ImagN' ActiveX control (IMW32O40.OCX) 4.00.041 allow remote attacke
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apache Tomcat 6.0.10 - Documentation Sample Application Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in the appdev/sample/web/hello.jsp example application in Tomcat 4.0
35RISK
open ↗Exploit-DB✓ VexDay Proof
Rational Software Hidden Administrator 1.7 - Authentication Bypass
Unspecified vulnerability in Rational Soft Hidden Administrator 1.7 and earlier allows remote attackers to bypass authen
23RISK
open ↗Exploit-DB✓ VexDay Proof
ClientExec 3.0 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in index.php in ClientExec (CE) 3.0 beta2, and possibly other versio
23RISK
open ↗Exploit-DB✓ VexDay Proof
LeadTools JPEG 2000 - COM Object Remote Stack Overflow
Stack-based buffer overflow in the LEAD Technologies LeadTools JPEG 2000 LEADJ2K.LEADJ2K.140 ActiveX control (LTJ2K14.oc
23RISK
open ↗Exploit-DB✓ VexDay Proof
PsychoStats 2.3 - 'Server.php' Full Path Disclosure
PsychoStats 3.0.6b and earlier allows remote attackers to obtain sensitive information via a request for server.php with
23RISK
open ↗Exploit-DB✓ VexDay Proof
LeadTools MultiMedia 15 - 'Ltmm15.dll' ActiveX Control Stack Buffer Overflow
Buffer overflow in the UnlockSupport function in the LockModules subsystem in a certain ActiveX control in ltmm15.dll in
23RISK
open ↗Exploit-DB✓ VexDay Proof
WordPress Theme Redoable 1.2 - 'header.php?s' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Redoable 1.2 allow remote attackers to inject arbitrary web scrip
23RISK
open ↗Exploit-DB✓ VexDay Proof
PrecisionID Barcode ActiveX 1.9 - Remote Denial of Service
Stack-based buffer overflow in the PrecisionID Barcode 1.9 ActiveX control in PrecisionID_Barcode.dll allows remote atta
23RISK
open ↗Exploit-DB✓ VexDay Proof
Sun Java JDK 1.x - Multiple Vulnerabilities
Integer overflow in the embedded ICC profile image parser in Sun Java Development Kit (JDK) before 1.5.0_11-b03 and 1.6.
28RISK
open ↗Exploit-DB✓ VexDay Proof
vBulletin 3.6.6 - 'calendar.php' HTML Injection
Cross-site scripting (XSS) vulnerability in calendar.php in Jelsoft vBulletin before 3.6.6 allows remote attackers to in
23RISK
open ↗Exploit-DB✓ VexDay Proof
Computer Associates BrightStor ARCserve Backup 11.5 - mediasvr caloggerd Denial of Service
Multiple unspecified vulnerabilities in (1) mediasvr and (2) caloggerd in CA BrightStor ARCServe BackUp v9.01 through R1
23RISK
open ↗Exploit-DB✓ VexDay Proof
Jetbox CMS 2.1 Email - 'FormMail.php' Input Validation
formmail.php in Jetbox CMS 2.1 allows remote attackers to send arbitrary e-mails (spam) via modified recipient, _SETTING
23RISK
open ↗Exploit-DB✓ VexDay Proof
Jetbox CMS 2.1 - view/supplynews Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Jetbox CMS allow remote attackers to inject arbitrary web script
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.