Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,449cataloged exploits
35,552CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,367GitHub PoC 14,225VulnCheck XDB 8,649Nuclei 4,283Metasploit 3,474✓ verified onlyrecentpopularrisk
24,451 exploits
Exploit-DB✓ VexDay Proof
CA BrightStor ARCserve - 'msgeng.exe' Remote Heap Overflow (1)
Multiple buffer overflows in LGSERVER.EXE in CA BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.1
60RISK
open ↗Exploit-DB✓ VexDay Proof
SpoonLabs Vivvo Article Management CMS 3.40 - 'Show_Webfeed.php' SQL Injection
SQL injection vulnerability in rss/show_webfeed.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) 3.40 al
23RISK
open ↗Exploit-DB✓ VexDay Proof
Telestream Flip4Mac - 'WMV' File Remote Memory Corruption
Telestream Flip4Mac Windows Media Components for Quicktime 2.1.0.33 allows remote attackers to execute arbitrary code vi
23RISK
open ↗Exploit-DB✓ VexDay Proof
AdMentor - Admin Login SQL Injection
Multiple SQL injection vulnerabilities in the administrative login page (admin/login.asp) in ASPCode.net AdMentor allow
23RISK
open ↗Exploit-DB✓ VexDay Proof
MDPro 1.0.76 - 'index.php' SQL Injection
SQL injection vulnerability in index.php in MAXdev MDPro 1.0.76 allows remote attackers to execute arbitrary SQL command
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple Installer Package 2.1.5 - Filename Format String
Format string vulnerability in Apple Installer 2.1.5 on Mac OS X 10.4.8 allows user-assisted remote attackers to execute
28RISK
open ↗Exploit-DB✓ VexDay Proof
PHP Membership Manager 1.5 - 'admin.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in admin.php in Interactive-Scripts.Com PHP Membership Manager 1.5 allows remot
23RISK
open ↗Exploit-DB✓ VexDay Proof
FD Script 1.3.x - 'FName' Information Disclosure
download.php in FD Script 1.3.2 and earlier allows remote attackers to read source of files under the web document root
23RISK
open ↗Exploit-DB✓ VexDay Proof
FD Script 1.3.2 - 'download.php' Remote File Disclosure
download.php in FD Script 1.3.2 and earlier allows remote attackers to read source of files under the web document root
23RISK
open ↗Exploit-DB✓ VexDay Proof
Yahoo! Messenger 8.0 - Notification Message HTML Injection
Multiple cross-site scripting (XSS) vulnerabilities in the Contact Details functionality in Yahoo! Messenger 8.1.0.209 a
23RISK
open ↗Exploit-DB✓ VexDay Proof
Citrix Metaframe Presentation Server Print Provider - Buffer Overflow (PoC)
Stack-based buffer overflow in the print provider library (cpprov.dll) in Citrix Presentation Server 4.0, MetaFrame Pres
28RISK
open ↗Exploit-DB✓ VexDay Proof
PHP 5.2 - FOpen 'Safe_mode' Restriction Bypass
The fopen function in PHP 5.2.0 does not properly handle invalid URI handlers, which allows context-dependent attackers
23RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Excel - Malformed Palette Record Denial of Service (PoC) (MS07-002)
Heap-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows user-as
35RISK
open ↗Exploit-DB✓ VexDay Proof
Microsoft Word 2000 - Malformed Function Code Execution
Unspecified vulnerability in Microsoft Word allows user-assisted remote attackers to execute arbitrary code on Word 2000
35RISK
open ↗Exploit-DB✓ VexDay Proof
Aztek Forum 4.0 - Multiple Vulnerabilities
SQL injection vulnerability in forum/load.php in Aztek Forum 4.00 allows remote attackers to execute arbitrary SQL comma
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX 10.4.x - Software Update Format String
Format string vulnerability in Apple Software Update 2.0.5 on Mac OS X 10.4.8 allows remote attackers to cause a denial
28RISK
open ↗Exploit-DB✓ VexDay Proof
WordPress Core 1.x/2.0.x - Pingback SourceURI Denial of Service / Information Disclosure
WordPress allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service ca
23RISK
open ↗Exploit-DB✓ VexDay Proof
GTK2 GDKPixBufLoader - Remote Denial of Service
The GdkPixbufLoader function in GIMP ToolKit (GTK+) in GTK 2 (gtk2) before 2.4.13 allows context-dependent attackers to
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX 10.4.8 - 'UserNotificationCenter' Local Privilege Escalation
The CFUserNotificationSendRequest function in UserNotificationCenter.app in Apple Mac OS X 10.4.8, when used in combinat
23RISK
open ↗Exploit-DB✓ VexDay Proof
Vote-Pro 4.0 - 'poll_frame.php?poll_id' Remote Code Execution
Multiple eval injection vulnerabilities in Vote! Pro 4.0, and possibly earlier, allow remote attackers to execute arbitr
23RISK
open ↗Exploit-DB✓ VexDay Proof
Oracle 10g - SYS.KUPW$WORKER.MAIN PL / SQL Injection
Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 have unknown impact and attack vectors, aka Oracle Vuln
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX 10.4.8 - QuickDraw GetSrcBits32ARGB Remote Memory Corruption
The _GetSrcBits32ARGB function in Apple QuickDraw, as used by Quicktime 7.1.3 and other applications on Mac OS X 10.4.8
23RISK
open ↗Exploit-DB✓ VexDay Proof
Oracle 10g - SYS.KUPV$FT.ATTACH_JOB PL / SQL Injection
Multiple SQL injection vulnerabilities in Oracle 10g Release 1 before CPU Jan 2006 allow remote attackers to execute arb
23RISK
open ↗Exploit-DB✓ VexDay Proof
Upload Service 1.0 - 'top.php?maindir' Remote File Inclusion
PHP remote file inclusion vulnerability in upload/top.php in Upload-Service 1.0, when register_globals is enabled, allow
23RISK
open ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX 10.4.x Kernel - 'shared_region_map_file_np()' Memory Corruption
The shared_region_map_file_np function in Apple Mac OS X 10.4.8 and earlier kernel allows local users to cause a denial
23RISK
open ↗Exploit-DB✓ VexDay Proof
Sun Microsystems Java - '.GIF' File Parsing Memory Corruption
Buffer overflow in Sun JDK and Java Runtime Environment (JRE) 5.0 Update 9 and earlier, SDK and JRE 1.4.2_12 and earlier
28RISK
open ↗Exploit-DB✓ VexDay Proof
3Com TFTP Service (3CTftpSvc) 2.0.1 - Remote Buffer Overflow (Metasploit)
Multiple stack-based buffer overflows in 3Com 3CTftpSvc 2.0.1, and possibly earlier, allow remote attackers to cause a d
60RISK
open ↗Exploit-DB✓ VexDay Proof
Apple iChat 3.1.6 441 - 'aim://' URL Handler Format String (PoC)
Format string vulnerability in Apple iChat 3.1.6 allows remote attackers to cause a denial of service (null pointer dere
28RISK
open ↗Exploit-DB✓ VexDay Proof
SMF 1.1 - 'index.php' HTML Injection
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Simple Machines Forum (SMF) 1.1 RC3 allow remote aut
23RISK
open ↗Exploit-DB✓ VexDay Proof
MySpeach 2.1b - 'up.php' Remote File Inclusion
PHP remote file inclusion vulnerability in up.php in Sky GUNNING MySpeach 3.0.6 and earlier allows remote attackers to e
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.